This is a clean, small Flarum extension with an MIT license, a coherent 19-file source and artifact tree, no install-time lifecycle scripts, a single runtime dependency, and a repository that is not archived and was pushed very recently. However, v0.1.1 is an extremely new release with only two releases, no tests or changelog, no security policy, no security-scanning tooling, and no demonstrated popularity or longer-term maintenance history. The repository name does not exactly match the package name, although its README explicitly documents the package, which reduces concern about repository identity. It may be reasonable to adopt for a low-risk frontend extension, but production users should expect limited maturity and verify ongoing maintenance.
68%
Total Score
75
100
72
88
A substantial README documents the extension and its behavior, but neither the artifact nor repository contains tests or a changelog. For a newly released frontend extension this is a real maturity gap, though the documentation provides useful transparency.
The repository is owned by an individual user rather than an organization, so the project has a limited visible ownership base. This is a mild continuity concern, especially combined with the package's very short history.
The package is only 0 days old with two releases, and the releases are separated by roughly 39 minutes. This shows initial activity but provides no evidence of sustained maintenance or release stability.
The repository has zero stars, forks, and watchers. This is supporting evidence of limited adoption, not a decisive health verdict for a newly published, specialized extension.
Composer build tooling is present, but no security-scanning tools are configured. Build support is positive, while the missing scanning layer is a modest transparency and assurance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.