The project is small and has only one contributor, so future maintenance depends heavily on one person. Its focused package, matching repository, release notes, and clean workflow audit provide useful transparency, but all three actions are unpinned and no security policy is present.
62%
Total Score
50
100
75
67
The repository is owned by an individual user rather than an organization, so the single-maintainer concentration has no visible organizational handoff support.
This release is the package's only release, published 87 days ago, so there is too little history to establish durable maintenance or release stability.
One contributor made all two recent commits, concentrating maintenance responsibility entirely in a single person without organizational backing.
There were two commits in the last three months, showing some activity but not enough to demonstrate a strong ongoing maintenance cadence.
Composer build tooling is present, but no security-scanning tooling is reported; this is a modest transparency gap for supply-chain maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.