The MIT license, focused dependency set, usable README, and lack of install scripts are reassuring. No security policy or automated security scanning is present, and the project has not yet demonstrated sustained support.
62%
Total Score
50
100
81
75
This is the package's first release, published less than one day ago, so there is too little history to establish a dependable release pattern. Its age makes the absence of older releases understandable but does not remove the uncertainty.
There were no commits or active maintainers in the last three months, but the repository itself was pushed less than one day ago and the package is newly released. This is limited evidence of maintenance rather than proof of abandonment.
Composer build tooling is present, but no security scanning tools were detected. For a framework extension, that leaves a meaningful repository hygiene gap.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This lowers transparency but is not severe enough to make the release unfit on its own.
Version 0.1.0 is an early non-stable-major release, which signals that APIs and behavior may still change. It is not marked as a prerelease, providing a small compensating signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.