The project has organization backing, tests, a security policy, and a small runtime dependency surface. Its beta-heavy release history and concentrated recent commits leave a modest maintenance caveat.
82%
Total Score
83
100
90
100
One contributor made 6 of the 7 recent commits, so maintenance is concentrated. Organization backing and a second active contributor partly compensate for that concentration.
The assessed release is a beta and 80% of recent releases are prereleases, so the API may still change. The package has nevertheless progressed to a stable-major release line with a current release candidate.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-30913 flarum/nicknames is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.8.3. | 0.0.0 - 1.8.3 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^0.1.0-beta.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.