The package has a clear README, MIT licensing, a small runtime dependency set, and no install-time scripts. It lacks tests, security scanning, and a security policy, while its single-day-old repository provides no maintenance history yet.
65%
Total Score
50
100
75
75
This is the first release, published less than a day ago, so there is no release cadence or track record yet; its age makes that gap understandable rather than evidence of abandonment.
There were no commits or active maintainers in the prior three months. Because the repository is only one day old, this shows no established maintenance capacity yet rather than a long-term collapse.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but the package's very recent creation makes low visibility unsurprising.
Composer is used as the build tool, but no security scanning tools were detected. For an extension handling user feedback, that is a modest project-hygiene gap.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.