The source includes a README, changelog, release notes, and a valid license. No commits were recorded in the last three months, the registry history stopped in 2022, and the package-to-repository link is unclear.
18%
Total Score
50
58
75
Packagist marks the entire package as abandoned, with no replacement other than the same package name. This is a severe adoption risk even though the linked repository is not archived.
The latest registry release was in October 2022, and there were no releases in the last 12 months. Repository activity provides limited compensation, but the published package itself is substantially stale.
The repository recorded zero commits and zero active maintainers in the last three months. A recent repository push is not enough to demonstrate ongoing development.
The repository name does not match the registry package name, and its README does not mention the package. This leaves uncertainty about whether the linked source is the authoritative project.
The linked repository has no security policy. For a small translation package this is a modest transparency gap, but there is no provided compensating security process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.