Clear documentation, MIT licensing, scoped dependencies, and security scanning support adoption. The repository is active and the release includes notes, while low popularity is only supporting context.
78%
Total Score
75
100
100
75
The repository is owned by an individual rather than an organization, so the single-contributor concentration represents a genuine continuity risk rather than normal organization publishing structure.
All 35 recent commits came from one contributor, so maintenance depends heavily on a single person and handoff capacity is limited.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear despite its extensive automated security tooling.
All 16 workflows were analyzed, use read-only permissions, and pin all 80 action references. A high-confidence bot-conditions finding in the Dependabot auto-merge workflow is a workflow-hygiene concern; the low-confidence cache-poisoning finding is not independently material.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.