The source repository remains active under an organization, with two recent contributors and a security policy. Its license, README, tests, and dependency footprint are clear, but the linked repository does not identify this package.
35%
Total Score
100
67
50
Packagist marks the package abandoned and names flagrow/split as a replacement, which is a substantial adoption and maintenance warning for this release.
The package has had no registry release for nearly five years, despite 15 releases overall; recent repository activity partly offsets the age but not the stale published artifact.
The repository name does not match the package name and its README does not mention this package, creating uncertainty about whether the linked source actually corresponds to this artifact.
All three workflows were analyzed with no high-confidence findings or untrusted checkout paths, but all three action references are unpinned, leaving a modest reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.