The package is clearly identified and small, with MIT licensing, a usable README, and release notes for this version. Its workflows are simple but use unpinned actions, and no security policy is published.
44%
Total Score
0
75
50
Only two releases exist, with the latest published in January 2024 and none during the last 12 months. This long release gap is a substantial maintenance concern for a package developers may need to keep compatible.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the repository’s last push in January 2024. This provides strong evidence of inactive maintenance.
The repository has zero stars and forks and only one watcher, indicating very limited adoption or review beyond the maintainers. Popularity is supporting evidence rather than decisive on its own, but it provides little compensating confidence here.
No security policy is present in the repository. This is a transparency and response-process gap, though it is less severe than the evidence of prolonged inactivity.
Both analyzed workflows were complete and had no detected dangerous triggers, sinks, or audit findings, but both of the two action references are unpinned. That leaves avoidable build-integrity risk without making the release unfit by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.