The package has no security policy and only one registry maintainer, leaving support and disclosure paths thin. Its README, license file, and release notes improve transparency, but there is no evidence of ongoing maintenance.
42%
Total Score
50
79
75
A license file is present in both the artifact and repository, but the manifest declares GPL-1.0-or-later while the detected file is GPL-3.0. The mismatch creates avoidable licensing uncertainty.
Only one registry account has publish access. Because the project is backed by an individual user rather than an organization, this leaves a thin publishing and continuity base.
This is the package's only release, published over 18 months ago, with no releases in the last 12 months. That strongly suggests abandonment risk, although the repository is not archived.
The repository recorded zero commits and zero active maintainers in the last 3 months. With only one release, there is little evidence of continuing maintenance.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counters provide no additional adoption or community support signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.2.0 | — | — |
flarum/flags Version * | — | — |
flarum/approval Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.