Healthy and actively developed, with solid tests, recent releases, and a non-archived organization-backed repository. The main caveats are that it is only 36 days old, nearly all recent commits come from one contributor, and repository security practices are limited.
78%
Total Score
80
100
83
80
The package is only 36 days old but has had 15 releases, with the latest published recently and a median interval of about 17 hours. This shows active iteration, although the short history limits evidence of long-term maintenance.
The top contributor made 99% of the 100 recent commits, creating a concentrated maintenance risk. The organization ownership partly compensates because maintenance can potentially be handed off, but the observed contributor base remains thin.
The repository has five new issues and one closed issue in the last month, alongside nine merged pull requests. Issue closure is slower than issue intake, but the merged work demonstrates active development.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but popularity alone is not decisive for a young package with strong recent activity.
Composer is used as a build tool, but no security scanning tools are configured. The absence of scanning is a hygiene gap rather than evidence of unsafe behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.