Security scanning is extensive, but one workflow has a high-confidence automation-condition flaw. The package is clearly licensed and documented, with recent releases, tests, and active repository work.
80%
Total Score
75
100
100
75
The repository is owned by a user rather than an organization, so the single-maintainer concentration has no visible organizational backing to offset it.
Only one contributor made all 17 recent commits, so maintenance depends heavily on a single person and has limited handoff resilience.
The repository has no security policy, leaving the reporting and response process unclear despite the presence of automated security scanning.
All 14 workflows were analyzed and references are pinned, but a high-confidence bot-condition finding affects the Dependabot automation; the low-confidence cache finding is only a hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.