Tests, release notes, a matching repository, and an active license provide useful support. Nearly two years without a release or commit, plus missing security scanning and unpinned workflow actions, leave maintenance and build hygiene concerns.
61%
Total Score
67
100
83
75
The package and repository are owned by individual accounts rather than an organization, so the single registry maintainer offers limited visible redundancy or institutional backing.
Only two releases exist, with no release in the last 12 months and the latest published nearly two years ago. This lowers confidence in ongoing maintenance, though the release history is not evidence of abandonment by itself.
There were no commits and no active maintainers during the last three months, consistent with nearly two years since the latest repository push. This is the strongest maintenance concern.
The repository has no stars and only three forks, indicating limited adoption. Popularity is supporting evidence rather than a health verdict, so this is only a mild concern.
The repository uses Composer build tooling, but no security-scanning tool was detected. That leaves a meaningful transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.8.0 | — | — |
symfony/dom-crawler Version ^5.0 || ^6.0.2 | — | — |
symfony/css-selector Version ^7.1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.