The focused dependency set, matching repository, and MIT declaration make its contents easy to inspect. Its missing security policy and zero security-scanning tools reduce transparency, but these are secondary to its maintenance outlook.
42%
Total Score
25
100
75
50
The latest release was nearly seven years ago, with no releases in the last 12 months. This is strong evidence of an aging, likely unmaintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months, and was last pushed in January 2023. That sustained inactivity materially raises abandonment risk.
There are 13 open pull requests but no new or merged pull requests in the last month, suggesting unresolved maintenance work and limited project responsiveness.
The project uses Composer, which provides build tooling, but it reports no security-scanning tools. The missing scanning coverage is a modest transparency concern.
The repository has no security policy, reducing transparency about vulnerability reporting and maintainer response. This is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version >=0.1.0-beta.10 <0.1.0-beta.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.