The MIT license and lack of install-time scripts reduce adoption friction. Its organization-backed repository is intact, but the package offers little evidence of current support.
28%
Total Score
50
100
67
75
The latest release was published in May 2016, with no releases in the last 12 months and only four releases overall. This strongly indicates abandonment risk for a package intended to integrate with an evolving platform.
There were zero commits and zero active maintainers in the last three months. Given that the repository was last pushed nearly 10 years ago, current maintenance capacity appears absent.
The repository uses Composer for builds, but no security-scanning tools were detected. The missing scanning is a modest hygiene gap rather than the main adoption concern.
No security policy was found in the repository, leaving no documented process for reporting or handling vulnerabilities. This matters more for a real-time integration that depends on external service credentials.
The assessed version is a prerelease beta, and all recent versions are prereleases. Combined with the package's long inactivity, this suggests the integration may never have reached a maintained stable release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^0.1.0-beta.5 | — | — |
pusher/pusher-php-server Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.