The release includes detailed verification notes, a substantial test suite, and a matching source repository. Its short history, single publisher, absent security policy, and unpinned workflow actions leave limited evidence of long-term resilience.
70%
Total Score
50
79
50
Only one registry account has publish access. That is a thin publishing base for a user-owned project and increases continuity risk if that person becomes unavailable.
The package is only 46 days old with three releases, all within about three days; this shows activity but provides little evidence of long-term maintenance.
Composer build tooling is present, but no repository security-scanning tool was detected; the release notes report an npm audit result, which provides some compensating evidence but not ongoing repository coverage.
The repository has no security policy, leaving no documented channel or process for reporting and handling vulnerabilities.
v0.1.2 is not a stable major release, so its API and behavior may still change materially despite not being marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.8 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.