The MIT license and focused one-dependency package make its contents easy to understand. No security policy or automated security scanning provides little supporting evidence for ongoing care.
10%
Total Score
0
100
40
83
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on it.
The latest release is about 5 years old; there have been no releases in the last 12 months. This strongly indicates the package is no longer maintained.
The repository had no commits or active maintainers in the last 3 months, consistent with abandonment rather than active maintenance.
The source repository is archived and was last pushed about 5 years ago, so new fixes and compatibility work should not be expected.
The repository has no security policy, leaving no documented process for reporting or handling security issues. This adds a transparency gap alongside the broader maintenance concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.