The package includes a license, a README, and a matching repository, but its documentation is brief and it has no security policy. Its maintenance record is too old for a dependable current Flarum dependency.
32%
Total Score
0
75
50
This is the package's only release, published over 10 years ago, with no releases in the last 12 months. That strongly indicates abandonment for a dependency expected to track its host ecosystem.
The repository recorded zero commits and zero active maintainers in the last 3 months, while its last push was over 9 years ago. The long inactivity is not offset by any observed maintenance signal.
Composer is used as a build tool, supporting a reproducible package structure, but no security scanning tools are present. This is a minor hygiene gap rather than a decisive risk.
The linked repository has no security policy. This is a transparency and maintenance gap, although it is secondary to the much older release and commit history.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^0.1.0-beta.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.