The repository includes tests and a matching license, and the package has no install-time scripts. Its CI uses two unpinned actions and lacks security scanning, so maintenance quality is limited.
55%
Total Score
50
79
75
This is the package's only release, published about 2 years and 11 months ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package having stopped receiving updates. The repository is not archived, but there is no recent activity to offset the concern.
The project uses Composer for builds, but no security-scanning tools were detected. For a small extension this is a modest transparency and maintenance gap rather than evidence of unfitness.
Both workflows were analyzed successfully and contain no detected dangerous sinks or audit findings, but both use unpinned actions. This is a real build-reproducibility and supply-chain hygiene gap, though not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.