It has a clear MIT license, a small dependency surface, and release notes for this version. Recent issue and release activity are reassuring, though the project has no security policy.
68%
Total Score
67
100
88
75
One contributor made all two commits in the last three months, concentrating recent maintenance in a single person. Because the repository is user-owned rather than organization-owned, there is no shown organizational handoff cushion.
Two commits were made in the last three months, showing that the repository is not dormant. The low volume limits confidence that maintenance is robust.
Composer is used as a build tool, but no security scanning tool was detected. The missing scanning is a modest security-process gap rather than a direct dependency-health failure.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented. This is a transparency gap, but not evidence of abandonment by itself.
This is a prerelease beta despite being on a stable major version, so consumers should expect possible changes or unfinished behavior. The recent prerelease share is limited rather than dominant, which partly offsets the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0.0-rc.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.