Skip to content
CAI
Software that uses CAICheck a score

flarum/framework

46.7

Weak · 19 September 2026

103.5k

lines of production code

PHP

with TypeScript, JavaScript

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is the Flarum 2.x forum software, structured as a monorepo containing the core framework and a suite of bundled extensions. It provides a modern, extensible platform for community discussions, featuring real-time updates, private messaging, and comprehensive content moderation tools like spam filtering, post approval, and user suspension. The architecture supports rich user interactions through likes, mentions, and subscriptions, while ensuring data privacy and administrative control via GDPR compliance and detailed audit logging.

How it got here

2014–2015 — Flarum 2.0 foundation and extension rewrites

47 changes.

This period established the Flarum 2.0 baseline by upgrading core dependencies to PHP 8.3 and Laravel 13, while removing legacy Ember.js frontend code in favor of a modern TypeScript and Webpack build system. It involved the comprehensive initialization and rewriting of all bundled extensions, including Tags, Mentions, Likes, and Locks, to align with the new architecture and provide updated admin interfaces and database schemas.

2017–2021 — Flarum 2.x modernization and tooling

45 changes.

This period focused on modernizing the Flarum codebase for version 2.x, characterized by rewriting the admin panel in TypeScript and establishing comprehensive developer tooling for extensions. It introduced significant new features such as the Nicknames extension, enhanced Statistics dashboards, and a redesigned Extension Manager, while simultaneously standardizing UI styling with CSS variables across multiple components. The work was heavily supported by the implementation of robust PHP and JavaScript testing infrastructures to ensure stability during this major architectural shift.

2022–2025 — Monorepo infrastructure and core extensions

38 changes.

The project restructured into a monorepo with standardized build quality gates, static analysis, and testing infrastructure. This period saw the introduction of major features including private messaging, real-time WebSocket updates, and enhanced GDPR controls, alongside significant expansion of unit and integration test coverage across core and bundled extensions.

2026 — Audit extension migration and test expansion

13 changes.

This period focused on migrating the Audit extension to Flarum 2.x, including database schema updates, admin interface styling, and comprehensive integration testing. Significant effort was also dedicated to expanding test coverage across various frontend components and extensions, such as GDPR, Likes, Lock, Embed, Tags, Statistics, and Realtime.

Features

Add server-rendered views for tag and tag-list pages

The Tags extension now includes dedicated Blade templates for rendering the individual tag page and the main tag list page on the frontend. Users will see a structured layout for the tag index featuring primary and secondary tag categories with hierarchical nesting, as well as a dedicated view for individual tags that displays the tag name, description, and a paginated list of associated discussions.

extensions/tags/views · high confidence

Add styling for the messages extension UI

This change introduces the visual design for the new messages extension by adding \admin.less\ and \forum.less\. These styles define the layout and appearance of the messages interface, including the sidebar, message list items, avatars, and composer components, ensuring a consistent look and feel across admin and forum contexts.

extensions/messages/less · high confidence

Added monorepo test runner script

A new shell script at bin/test.sh has been added to facilitate testing across the monorepo. This script iterates through a defined list of core and extension directories (including framework/core, extensions/akismet, extensions/approval, etc.) and executes the composer test command for each, providing clear console output to track progress and completion for each component.

bin · high confidence

Admin area bootstrapping and middleware stack

The framework now explicitly registers the Admin area's service provider, wiring up its dedicated route collection, middleware stack (including CSRF, session, and admin-only access checks), and error handling. It also configures the admin frontend assets (JS/CSS) and registers the admin frontend payload, ensuring the admin interface is fully bootstrapped and isolated from the forum and API areas.

framework/core · high confidence

Akismet extension admin settings and forum post controls

The Akismet extension now provides an admin configuration page where administrators can enter their Akismet API key and toggle an option to automatically delete blatant spam. On the forum side, posts flagged by Akismet display a custom 'Not Spam' button in the post controls, and the flag reason text is localized to clearly indicate Akismet involvement.

extensions/akismet/js · high confidence

Approval extension database schema and permissions initialization

The approval extension now includes migration files that initialize the database schema and default permissions. Specifically, it adds an 'is\_approved' boolean column (defaulting to true) to both the 'discussions' and 'posts' tables to track approval status. Additionally, it sets default permissions for members to start and reply to discussions without approval, and grants moderators the ability to approve posts.

extensions/approval/migrations · high confidence

Database schema for the new Messages extension

This change introduces the database migrations for the Messages extension, establishing the core data structures for private conversations. It creates the \dialogs\ table to represent conversation threads, the \dialog\_messages\ table for individual messages, and a \dialog\_user\ pivot table to track user membership and read status within each dialog. The schema also includes a permissions migration to grant the \dialog.sendMessage\ capability to members, and a comprehensive mention system via separate junction tables (\dialog\_message\_mentions\_user\, \\_post\, \\_group\, \\_tag\) to link messages to specific entities. Finally, a migration adds a \number\ column to \dialog\_messages\ to provide stable, sequential ordering of messages within each dialog.

extensions/messages/migrations · high confidence

Discussion locking extension adds API, permissions, and notifications

The lock extension now provides the core infrastructure for locking discussions, including an API resource that exposes an \isLocked\ field and a \canLock\ permission check. It introduces a \DiscussionPolicy\ that prevents non-administrators from replying to locked threads, and registers event listeners that automatically create system posts and send notifications when a discussion is locked or unlocked. Additionally, a \LockedFilter\ is added to the search driver to allow filtering discussions by their locked status, and conditional integrations are set up to broadcast these events via the realtime extension and log them in the audit extension when present.

extensions/lock · high confidence

Embed extension initial release with forum embedding support

The embed extension is introduced, allowing users to embed Flarum discussions directly into external sites via a dedicated forum route. The extension registers a frontend asset bundle for the embed context and utilizes the \resolve\ helper for content handling, ensuring compatibility with Flarum v1.0.0. Initial setup includes standard project files like \.gitattributes\ and \.gitignore\ to manage repository exports and local environment artifacts.

extensions/embed · high confidence

Emoji extension initialization and emoticon mapping

The emoji extension has been initialized with core configuration files, including a changelog, license, and build attributes. The extension now registers frontend assets for the admin and forum areas and defines a set of default emoticon-to-emoji mappings (such as ':)' to '🙂') within the text formatter. Additionally, it introduces a configurable setting allowing users to specify a custom CDN address for loading emoji assets, defaulting to the jsDelivr Twemoji CDN.

extensions/emoji · high confidence

Flarum Lock extension adds forum UI controls and admin permissions

The Flarum Lock extension now includes its frontend JavaScript implementation, enabling users to lock and unlock discussions directly from the forum interface via a new moderation button. This change introduces a visual lock badge on locked discussions, displays lock/unlock events in the post stream, and sends notifications to users when a discussion is locked. Administrators gain a new 'Lock Discussions' permission under the Moderate role, and the extension integrates with the search system via a LockedGambit to filter locked discussions. It also supports real-time stream updates for locking events when the Realtime extension is active.

extensions/lock/js · high confidence

Initial release of the Approval extension

This change introduces the Flarum Approval extension, enabling post moderation workflows. On the forum, unapproved posts and discussions are visually distinguished with badges and CSS classes, and moderators gain a new 'Approve' button in the post controls to mark content as approved. In the admin panel, new permissions are added to allow specific user groups to start discussions or reply without requiring approval, and the system ensures these permissions correctly require the base discussion and reply permissions.

extensions/approval/js · high confidence

Initial release of the English language pack extension

This entry introduces the \lang-english\ extension, which provides the core English translation strings for the Flarum forum software. The extension registers itself as a language pack via \extend.php\ and includes the necessary metadata files (such as \.gitattributes\ and \.gitignore\) to ensure a clean distribution. While the extension itself is new, the included \CHANGELOG.md\ indicates that this release (v1.2.0) primarily serves as a compatibility update for Flarum v1.0.0, consolidating translation keys that were previously scattered across other extensions into this central package.

extensions/lang-english · high confidence

Introduce Nicknames extension for alternative display names

Adds the Nicknames extension, allowing users to set and manage an alternative display name separate from their username. On the forum, users with permission can change their nickname via a new modal in the Account Settings, and administrators can edit nicknames in the user edit modal. During registration, the extension optionally prompts for a nickname and can automatically generate a random username if configured. Administrators can configure these behaviors (such as requiring uniqueness, setting length limits, or enabling random username generation) in the Flarum Basics settings, with a warning displayed if the display name driver is not set to 'nickname'.

extensions/nicknames/js · high confidence

Introduce Realtime extension as a self-hosted WebSocket alternative

The Realtime extension is added, providing a self-hosted WebSocket server that replaces third-party services like Pusher. It enables real-time forum updates, including auto-updating the index, pushing new posts, and displaying typing indicators. The extension includes a daemon (started via \php flarum realtime:serve\) that requires separate installation and configuration (e.g., via supervisor or systemd). It integrates with Flarum's notification system to show toasts for likes, replies, and flags, and provides an extender API for other extensions to register custom real-time events.

extensions/realtime · high confidence

Introduce extensible mention system with user, post, group, and tag support

The mentions extension has been rewritten to support a new, extensible mention format system. Users can now mention users, posts, groups, and tags, each with distinct syntax (e.g., @username, @"Display Name"\#123, @"Mods"\#g4, \~tag). The composer includes an autocomplete dropdown that suggests these mentionables as you type, and posts display previews when hovering over mentions. Additionally, a 'Mentioned By' list shows who has replied to a post, and a dedicated 'Mentions' tab on user profiles lists posts where they were mentioned. Admins can control whether the new display-name-based mention format is allowed and manage permissions for mentioning groups.

extensions/mentions/js · high confidence

Introduce forum-side flagging and moderation UI

This change adds the frontend components for the Flags extension, enabling users to flag posts and moderators to view and manage them. On the forum, a flag button is added to post controls, opening a modal with predefined reasons (off-topic, inappropriate, spam, other) and optional details. Moderators see a flags dropdown in the header and a dedicated /flags page listing flagged posts, with real-time badge updates via the realtime extension. The admin side registers settings for guidelines and own-post flagging, plus permissions for viewing and creating flags.

extensions/flags/js · high confidence

Introduce private messaging (dialogs) feature

Adds a new private messaging system to the forum, allowing users to send and receive direct messages. This includes a dedicated Messages page with a sidebar listing active conversations, a message stream for viewing and replying to messages, and a composer for initiating new conversations. The feature supports real-time updates via websockets for new messages and typing indicators, and includes administrative controls for permissions such as sending messages and deleting own messages.

extensions/messages/js · high confidence

Introduce the Messages extension for private dialog conversations

The new Messages extension adds private, dialog-based messaging to the forum. It introduces a dedicated /messages route and a dialog detail view, backed by new API resources for dialogs and dialog messages that support pagination, filtering (including an unread filter), and real-time updates when the realtime extension is enabled. Users can send messages, delete their own messages (subject to configurable time or reply-based limits), and mark conversations as read, with email notifications sent for new messages. The extension also integrates with the platform's search and mention systems, allowing users to search their dialogs and receive notifications for user, post, group, and tag mentions within messages.

extensions/messages · high confidence

Introduce user suspension capability with admin controls and user notifications

This change adds the frontend JavaScript for the Suspend extension, enabling moderators to suspend users from the forum. On the forum side, users with the 'user.suspend' permission see a new 'Suspend' button in user controls, which opens a modal to set a suspension duration (limited or indefinite), reason, and message. Suspended users are notified via a modal and a notification item, and their profile displays a suspension badge. The admin side registers the necessary 'user.suspend' permission and adds a search gambit to filter for suspended users.

extensions/suspend/js · high confidence

Likes extension initialization and core behavior

The likes extension is introduced, enabling users to like and unlike posts with real-time updates (when the realtime extension is active). It adds a 'likes' relationship to posts, displays the like count and a list of likers (limited to 4) in the API, and sends notifications to post authors when their posts are liked or unliked. A new setting, \flarum-likes.like\_own\_post\, allows administrators to prevent users from liking their own posts. Search filters are added to find posts liked by a specific user or posts that a specific user has liked.

extensions/likes · high confidence

Likes extension rewritten in TypeScript with new user-facing features

The Likes extension has been completely rewritten in TypeScript, introducing a 'Likes' tab on user profiles to view posts they have liked, a modal to display the full list of users who liked a specific post, and haptic feedback when liking a post on supported devices. The extension now supports real-time updates via the realtime extension, allows administrators to configure whether users can like their own posts, and adds a search gambit to filter posts by the user who liked them.

extensions/likes/js · high confidence

Markdown extension initialization and configuration

This change introduces the core structure for the Flarum Markdown extension. It adds the necessary entry points (extend.php) to register frontend assets for both the forum and admin panels, and configures the text formatter to support Litedown syntax with a custom inline spoiler implementation. A database migration is included to set the default value for the 'mdarea' setting, and supporting files like .gitattributes, .gitignore, LICENSE, and CHANGELOG are added to standardize the extension's repository and distribution.

extensions/markdown · high confidence

Markdown toolbar and keyboard shortcuts for the composer

The Markdown extension now provides a visual toolbar in the composer with buttons for common formatting (headers, bold, italic, strikethrough, quotes, code, links, images, lists, and spoilers) and supports keyboard shortcuts (e.g., Ctrl/Cmd+B for bold) to apply these styles. It also improves list editing by automatically continuing lists when pressing Enter, including proper handling of empty items to end the list.

extensions/markdown/js · high confidence

New Flarum 2.x Extension Manager admin interface

The admin area now features a redesigned Extension Manager with a dedicated Discover section to browse and filter extensions, themes, and locales via Packagist. Administrators can install and update extensions directly from the dashboard, including major core version upgrades with a dry-run option. The interface also supports configuring custom Composer repositories and authentication methods for private packages, and provides a Queue section to monitor the status and output of background package management tasks.

extensions/package-manager/js · high confidence

New PHPStan and testing infrastructure for extensions

This change introduces a new \php-packages/phpstan\ package that provides a PHPStan extension for Flarum, including stubs for Illuminate classes (such as Filesystem, Queue, and Log Context) and custom extensions for model relations and casts, enabling static analysis for extensions. It also adds the \php-packages/testing\ package, which provides a testing framework for Flarum extensions, including a TestCase for integration tests, a RepeatedQueryDetector to identify N+1 query issues, and a minimal test extension to validate the testing infrastructure.

php-packages · high confidence

New developer tooling packages for testing, TypeScript, and Webpack

Flarum now provides three official npm packages to standardize extension development: \@flarum/jest-config\ for unit and integration testing, \flarum-tsconfig\ for TypeScript configuration, and \flarum-webpack-config\ for build setup. The Jest config package includes a factory for creating JSON:API test fixtures (e.g., \makeDiscussion\, \makeUser\), custom Mithril component test matchers, and automatic resolution of Flarum core source in both monorepo and standalone extension environments. The TypeScript config package offers a standardized \tsconfig.json\ that extends Flarum's base settings and includes global typings for libraries like \dayjs\ and \jquery\. The Webpack config package provides a pre-configured build pipeline with Babel and TypeScript support, including an optional Webpack Bundle Analyzer integration.

js-packages · high confidence

New email templates for message notifications

The Messages extension now includes dedicated HTML and plain-text email templates for the 'message received' notification. Users will receive formatted emails containing the sender's display name, a direct link to the specific message dialog, and the message content, ensuring consistent notification delivery across different email clients.

extensions/messages/views · high confidence

New model classes for core and bundled extensions

The framework now includes the Eloquent model definitions for the core entities (Discussion, UserState, ApiKey) and the bundled extensions (AuditLog, Flag, ErasureRequest, Export, Dialog, DialogMessage, UserDialogState, Task, Tag, TagState, and event posts for locking, sticking, and tagging). These classes define the database schema, relationships, and basic state management for these features, establishing the data layer for the updated forum functionality.

flarum/framework · high confidence

New module registry and code-splitting infrastructure

The webpack configuration now includes a new module registry system that automatically exports core and extension modules, allowing them to be imported via \flarum.reg.get\ and \flarum.reg.asyncModuleImport\. This is supported by new Webpack plugins and loaders (\OverrideChunkLoaderFunction\, \RegisterAsyncChunksPlugin\, \autoChunkNameLoader\, \autoExportLoader\) that handle chunk registration, path normalization for Windows compatibility, and automatic export detection. The build process now uses a custom external resolution function to map \flarum/\ and \ext:\ imports to the registry, enabling more flexible and reliable code splitting and module loading across extensions.

js-packages/webpack-config · high confidence

New standalone frontend test bootstrap utilities

The jest-config package now includes dedicated bootstrap scripts (admin.js, forum.js, and common.js) to support frontend testing in standalone extensions. These files provide a standardized way to initialize the Flarum application context for both admin and forum environments, including loading core locale translations and setting up a default admin user session, ensuring tests run correctly without requiring the full application stack.

js-packages/jest-config · high confidence

New statistics dashboard and lifetime summary widget

The Statistics extension now provides a dedicated admin page for viewing detailed statistics over time, including support for custom date ranges, and adds a summary widget to the main admin dashboard that displays lifetime totals for users, discussions, and posts.

extensions/statistics/js · high confidence

Nickname extension v1.2.0: Registration prompts, security hardening, and audit logging

The Nicknames extension has been updated to version 1.2.0, introducing a prompt for users to set a nickname during registration. This release also includes significant security improvements: display names are now sanitized to prevent injection in HTML notification emails by stripping markdown/HTML link syntax characters and inserting zero-width spaces to prevent auto-linking of dotted strings. Additionally, the extension now integrates with the Flarum Audit extension to log nickname changes, and random username generation has been refined to ensure valid usernames when the randomization setting is enabled.

extensions/nicknames · high confidence

PHPStan extension now understands Eloquent model casts, dates, and relationships

The PHPStan static analysis tool now provides deeper type inference for Flarum models by analyzing \extend.php\ files. It recognizes model casts (e.g., \cast('field', 'date')\) to determine property types, identifies date attributes to return \Carbon\ objects, and resolves Eloquent relationship methods (\hasOne\, \hasMany\, etc.) to their specific relation types and return collections. This allows developers to get accurate type checking and autocompletion for dynamic model properties and relations without manual PHPDoc annotations.

php-packages/phpstan · high confidence

Realtime extension initial release with typing indicators and notification toasts

The Realtime extension is now available, introducing real-time features to the forum. Users can see ambient typing indicators on the discussion list and sidebar tags, with options to display specific usernames or just counts based on permissions. The extension also adds configurable notification toasts for new activity and allows administrators to control the automatic push interval for discussion updates and the duration of toast notifications.

extensions/realtime/resources · high confidence

Realtime extension introduces ambient typing indicators and notification toasts

The Realtime extension now provides ambient typing indicators on the discussion list and index sidebar tag list, allowing users to see who is typing in real-time. It also adds configurable notification toasts for new activity and asset updates, with settings to control their duration and visibility. Additionally, the extension includes a robust reconnection mechanism for iOS Safari to handle backgrounding and socket loss, ensuring users stay connected and receive missed events.

extensions/realtime/js · high confidence

Statistics extension adds custom date ranges and multi-database support

The Statistics extension now allows administrators to view community metrics using custom date ranges via the admin dashboard API. This update also expands database compatibility to include PostgreSQL and SQLite, in addition to the existing MySQL/MariaDB support, ensuring the extension functions correctly across different database drivers.

extensions/statistics · high confidence

Subscription extension adds follow/ignore controls and filtering

The subscriptions extension now provides forum users with the ability to follow or ignore specific discussions, indicated by badges and sidebar menu controls. A new 'Following' route and sidebar link allow users to view only the discussions they are subscribed to, with search results also filterable by subscription status. User preferences have been extended to support automatic following after replies or new topic creation, as well as a toggle to notify for all posts in a thread. Admin-side search filtering is also updated to respect these subscription states.

extensions/subscriptions/js · high confidence

Suspend extension adds user suspension, notifications, and search filtering

The \extensions/suspend\ extension introduces the ability to suspend users, automatically revoking their access by moving them to the guest group until the suspension expires. Suspended users receive both in-app alerts and email notifications upon suspension and unsuspension, and administrators can filter the user list by suspended status. The extension also exposes suspension details (reason, message, and expiration time) via the API and ensures these fields are correctly serialized as datetime strings.

extensions/suspend · high confidence

Removals

Removal of legacy Ember.js application structure

The legacy Ember.js application files have been removed from the framework core. This includes the deletion of the main application entry point, the custom JSON API adapter, and the entire set of controllers, routes, models, and components that previously handled the forum's UI logic, post streaming, and discussion management. This change eliminates the old Ember-based frontend implementation from this location.

framework/core/ember · high confidence

Architecture

Establish monorepo infrastructure and build quality gates

The repository is restructured into a monorepo, defined by a new \flarum-monorepo.json\ that maps core, extensions, and npm packages to their respective remote repositories. To support this structure, standard development configuration files are added, including \.editorconfig\ for consistent coding styles, \.gitattributes\ and \.gitignore\ for repository hygiene, and \.styleci.yml\ for PHP linting. Additionally, a \.bundlewatch.config.json\ is introduced to enforce JavaScript bundle size limits (150KB for core, 30KB for extensions) in CI, and \phpstan.neon\ is configured to run static analysis at level 6 across the core framework and bundled extensions.

(repo-wide) · high confidence

Behavioural changes

1 commit (0 fixes) modifying extensions/likes/js/dist-typings, extensions/lock/js/dist-typings

A change to existing behaviour in extensions/likes/js/dist-typings, extensions/lock/js/dist-typings — 1 commit, 25 files.

(repo-wide), extensions/embed/js/dist-typings, extensions/likes/js/dist-typings, extensions/lock/js/dist-typings · medium confidence · unverified

16 commits (1 fix) modifying extensions/flags/js/dist-typings/forum/components

A change to existing behaviour in extensions/flags/js/dist-typings/forum/components — 16 commits (1 fix), 6 files.

(repo-wide) · medium confidence · unverified

25 commits (0 fixes) modifying extensions/package-manager/js/dist-typings/components

A change to existing behaviour in extensions/package-manager/js/dist-typings/components — 25 commits, 21 files.

(repo-wide) · medium confidence · unverified

Add spam detection column to posts table

The Akismet extension now includes a database migration that adds an 'is\_spam' boolean column to the 'posts' table, defaulting to false. This structural change enables the system to track and store spam status for individual posts, supporting the extension's core functionality of identifying and managing spam content.

extensions/akismet/migrations · high confidence

Add subscription tracking column to user-discussion relationship

The database schema for the subscriptions extension is updated to include a new 'subscription' column on the 'discussion\_user' table. This column stores an enum value ('follow' or 'ignore') that allows users to explicitly manage their notification preferences for specific discussions, with the field being nullable to support existing records.

extensions/subscriptions/migrations · high confidence

Admin UI styling for the extension manager

The extension manager's admin interface now includes dedicated LESS stylesheets to structure the layout. This change introduces a multi-column settings group layout, styles for the control and queue sections, and specific formatting for buttons and forms, ensuring the extension management pages render with a consistent and organized visual structure.

extensions/package-manager/less · high confidence

Admin and forum tag UI styling consolidated into LESS files

The tag extension's styling is now organized into dedicated LESS entry points for the admin and forum areas. The admin styles import components for the Tags page, Edit Tag modal, and the reusable Select Tags setting component, while also restricting the dropdown menu height to 400px with scrolling. The forum styles import components for the Tag Cloud, Hero, Post, Tiles, and Toggle Button, and introduce CSS custom properties for colored tag buttons. Additionally, forum-specific layout adjustments include spacing for tag links in the sidebar, styling for the composer's tag change button, and responsive handling for discussion list item tags on tablet screens, featuring a horizontal scroll effect with a fade mask.

extensions/tags/less · high confidence

Admin panel rewritten in TypeScript with new extensibility and search features

The admin panel's frontend JavaScript has been converted to TypeScript, introducing stricter type safety and modern component patterns. This update brings a revamped admin navigation with built-in search, a new Announcements widget on the dashboard, and improved extensibility for admin pages and settings. The Advanced page now supports configurable search drivers and maintenance modes, while the extension management UI includes a reset settings button and better categorization.

framework/core/js · high confidence

Admin statistics page styling and chart export button positioning

The admin statistics interface now includes dedicated styling for the statistics widget, covering entity lists, labels, and change indicators, while also introducing a specific style for a chart export button positioned within the chart container. Additionally, the entry applies custom CSS overrides for Frappe Charts to control axis colors, line styles, and dataset rendering, ensuring the charts integrate visually with the admin theme.

extensions/statistics/less · high confidence

Admin tags interface styling and layout fixes

This change introduces new LESS styles for the admin tags management area to improve layout and usability. It fixes the tag selection setting component so that multiple selected tags wrap correctly within the button instead of overflowing the panel. It also corrects the positioning of the edit icon in the tags list by ensuring FontAwesome icons display inline, and adds styling for the delete button in the edit modal. Additionally, it applies max-height constraints to tag list items and adjusts footer and list padding for better visual structure.

extensions/tags/less/admin · high confidence

Akismet extension rewritten with manual API client and fail-open behavior

The Akismet extension has been rewritten to call the Akismet API manually instead of relying on an external library, which improves PHP 8 compatibility and allows sending additional parameters like \is\_test\. The extension now validates API keys before saving them to prevent silent misconfigurations, rechecks post content on edits, and implements a 'fail-open' strategy where spam checks do not block posting if the Akismet service is unreachable or misconfigured. Additionally, moderators can now configure the extension to automatically hide blatant spam posts and discussions.

extensions/akismet · high confidence

Apply CSS variables to locked discussion post styling

The forum interface now uses a CSS variable (--lock-color) to define the color of icons and text within locked discussion posts, replacing hardcoded values. This change centralizes the styling definition, allowing for easier theme customization of the locked post indicator.

extensions/lock/less · high confidence

Approval extension restructured for Flarum v1.0 with improved visibility and metadata handling

The approval extension has been updated to be compatible with Flarum v1.0, introducing a restructured architecture that improves how unapproved content is handled. New visibility scopes ensure that unapproved discussions and posts are correctly hidden from users who lack approval permissions, while still allowing authors to see their own pending content. The extension now properly updates discussion and user comment counts when posts are approved, and conditionally refreshes tag metadata (if the tags extension is enabled) to prevent stale counters. Additionally, the approval logic is integrated with the audit log extension to record approval actions, and the API now exposes \isApproved\ and \canApprove\ fields for posts.

extensions/approval · high confidence

Audit extension restructured for Flarum 2.x with queue pause/resume logging

The audit extension has been migrated to Flarum 2.x, introducing a new \audit\_log\ database table that automatically renames the legacy \kilowhat\_audit\_log\ table from previous extensions to preserve historical data. This update adds logging for queue pause and resume events, allowing administrators to track when background job processing is halted or restarted. The extension also includes a new admin interface for viewing audit logs, filtering by action, actor, and client, and supports limited visibility settings for IP addresses and specific actions.

extensions/audit · high confidence

Audit extension styles migrated to LESS

The Audit extension's styling has been converted from the previous format to a new LESS structure, introducing dedicated files for admin, forum, and shared components. This change establishes the visual presentation for the audit log interface, including specific padding adjustments for audit items, layout rules for search and filter controls, and styling for modal settings.

extensions/audit/less · high confidence

BBCode extension initializes with localized quote support and syntax highlighting fix

The BBCode extension now registers standard formatting tags (bold, italic, underline, strikethrough, URL, image, email, code, quote, list, and others) via the s9e TextFormatter library. A key behavioral change is that the 'wrote' string in quote blocks is now localized using the forum's translation system, ensuring the attribution text matches the user's language. Additionally, the code block rendering has been patched to re-run syntax highlighting (highlight.js) after post content is edited, fixing an issue where highlighted code would disappear or fail to update in live previews.

extensions/bbcode · high confidence

Database schema updates for discussion locking

The lock extension now includes database migrations that add an 'is\_locked' boolean column to the discussions table, create a database index on this column to improve query performance, and assign default moderator permissions for locking discussions.

extensions/lock/migrations · high confidence

Database schema updates for sticky discussions

The sticky extension now includes database migrations that add an 'is\_sticky' boolean column to the discussions table, assign default moderator permissions for sticky discussions, and create composite database indices on (is\_sticky, created\_at) and (is\_sticky, last\_posted\_at) to optimize query performance.

extensions/sticky/migrations · high confidence

Embed frontend rewritten for Flarum 2.x compatibility

The embed extension's frontend has been completely rewritten to support Flarum 2.x. This update redefines discussion routes to use the \/embed/:id\ path structure and adjusts the discussion page sidebar to remove the scrubber and provide a direct link back to the main forum discussion. It also introduces improved iframe handling, allowing the parent page to manage scrolling when replying within the embed and ensuring modals and the composer are correctly repositioned relative to the parent frame's scroll position. Additionally, external links within the embed are now automatically opened in new tabs and redirected to the standard \/d\ discussion URLs.

extensions/embed/js · high confidence

Emoji extension rewritten in TypeScript with custom CDN support and composer autocomplete

The emoji extension's JavaScript source has been restructured into TypeScript, introducing a new admin setting that allows administrators to configure a custom CDN URL for emoji images. On the forum side, the extension now provides an autocomplete dropdown in the composer when typing a colon, enabling users to quickly insert emojis by name. Additionally, emoji rendering in posts and previews has been updated to use the configured CDN and Twemoji for consistent image display.

extensions/emoji/js · high confidence

Emoji extension updates to Unicode 17 and cleans up legacy CDN settings

The emoji extension now supports Unicode 17, migrating stored emoji data from the legacy Emojione format to the current Twemoji standard via a new database migration that updates post content. Additionally, a cleanup migration removes any stored configuration settings that reference the old, deprecated Twitter Twemoji CDN URL, ensuring the extension uses the correct, up-to-date asset source.

extensions/emoji/migrations · high confidence

Extension Manager introduces Packagist search and granular update controls

The Extension Manager now sources available extensions directly from Packagist instead of the flarum.org API, allowing admins to discover and filter extensions by type (locale, theme) and search terms. The admin interface has been redesigned with a card-based layout for extensions and includes specific controls for performing minor updates, major updates (with a dry-run option), and global updates. Additionally, the system now checks extension compatibility against the current Flarum major version, rejecting incompatible updates, and provides detailed logging and task tracking for all composer operations.

extensions/package-manager · high confidence

Flags extension database schema and permissions updated

The Flags extension migrations have been updated to align with the current framework standards. This includes adding default permissions for members to flag posts and moderators to view flags, renaming the 'time' column to 'created\_at' and 'flags\_read\_time' to 'read\_flags\_at' for consistency, changing the 'reason\_detail' column type to text to support longer descriptions, adding database indices on 'created\_at' for performance, and establishing foreign key constraints between flags, posts, and users to ensure data integrity.

extensions/flags/migrations · high confidence

Flags extension rewritten for Flarum 2.x with JSON:API and real-time support

The Flags extension has been completely rewritten to align with Flarum 2.x architecture. It now uses the new JSON:API resource system for managing flags, replacing the previous event-subscriber model with modern extenders. Key behavioral changes include the ability for post authors to flag their own posts if the 'can\_flag\_own' setting is enabled, and the introduction of a 'read\_flags\_at' timestamp to track when users view the flags list. The extension also integrates with the new real-time API to broadcast flag events when the flarum-realtime extension is active, and provides an audit log integration for the flarum-audit extension to track flag creation and dismissal.

extensions/flags · high confidence

GDPR extension admin and forum UI rewritten in TypeScript

The JavaScript source for the GDPR extension has been migrated from plain JS to TypeScript, introducing a new build pipeline via webpack and tsconfig. This rewrite brings strict typing and modern component structures to the admin interface (including the new GDPR settings page, data type grid, and user column PII inspector) and the forum interface (including erasure request management, data export requests, and user deletion/anonymization workflows).

extensions/gdpr/js · high confidence

GDPR extension rebranded to flarum/gdpr with enhanced data controls and audit trails

The GDPR extension has been rebranded from 'blomstra-gdpr' to 'flarum/gdpr' (v2.0), requiring a database migration to update settings keys. This update introduces a comprehensive GDPR Data Overview in the admin panel, allowing administrators to inspect registered data types, PII fields, and user table columns. It adds support for PII field declarations and anonymized context support, enabling extensions to redact sensitive data in external integrations. Security is hardened with an audit trail for export downloads (tracking IP, user agent, and timestamp), single-use links, and active expiry checks. The erasure request lifecycle is now fully audited, and the system supports cancellation of erasure requests with a new 'cancelled\_at' status.

extensions/gdpr · high confidence

Improved styling for inline spoilers and toolbar

The extension now includes dedicated LESS styles for the Markdown toolbar and inline spoilers. The toolbar is displayed as an inline block, while inline spoilers are styled with a dark background and transparent text to hide content visually. Additionally, all child elements within spoilers (including links and images) are hidden or made non-interactive to prevent spoilers from being revealed through hover states or visual cues.

extensions/markdown/less · high confidence

Mentions extension database schema updates and normalization

The mentions extension's database structure has been updated to support new capabilities and improve data integrity. A new \post\_mentions\_group\ table allows posts to mention user groups in addition to individual users and other posts. The existing \post\_mentions\_post\ and \post\_mentions\_user\ tables now include a \created\_at\ timestamp column to track when mentions occurred. Additionally, the schema has been normalized: the original \mentions\_posts\ and \mentions\_users\ tables were renamed to \post\_mentions\_post\ and \post\_mentions\_user\, their generic ID columns were renamed to be specific (\mentions\_post\_id\, \mentions\_user\_id\), and proper foreign key constraints with cascade deletion were added to maintain referential integrity.

extensions/mentions/migrations · high confidence

Mentions extension rewritten for Flarum 2.x with new formatting and notification system

The mentions extension has been completely rewritten to support Flarum 2.x, introducing a new mention format that decouples usernames from mentions for greater stability. The extension now supports user, post, group, and tag mentions, with improved performance through eager loading and indexed lookups. Notification handling has been overhauled with dedicated blueprints for user, post, and group mentions, and the system now properly handles deleted users and posts by displaying appropriate fallback text. The API resources have been updated to include mention-related fields and relationships, and the search functionality now includes filters for mentioned users and posts.

extensions/mentions · high confidence

Mentions, subscriptions, and suspend notifications now use shared email components

The email templates for the Mentions, Subscriptions, and Suspend extensions have been rewritten to use the new \x-mail::html.notification\, \x-mail::plain.notification\, and \x-mail::html.information\ components. This change standardizes the structure of notification and information emails across these extensions, ensuring consistent styling and layout for both HTML and plain-text versions of group mentions, post mentions, user mentions, new subscription posts, and account suspension/unsuspension alerts.

extensions/mentions/views, extensions/subscriptions/views, extensions/suspend/views · high confidence

New CSS variables and styles for tag theming and selection

This change introduces a new set of Less styles for the tags extension, establishing a consistent visual language for tag labels, icons, and the tag selection modal. It adds CSS custom properties (like --tag-bg and --tag-color) to root and tag components, enabling easier theming and color customization. The styles define the appearance of tag labels (including colored and untagged states), icon alignment, and the layout for the tag selection modal, ensuring proper spacing and visual hierarchy across different screen sizes.

extensions/tags/less/common · high confidence

New visual design for the Tags page and tag tiles

The Tags page now features a completely new look, introducing a grid-based layout for tag tiles that adapts to mobile, tablet, and desktop viewports. Tag tiles display icons, descriptions, and the most recently posted discussion, with improved typography, contrast, and spacing. A new TagCloud component is also included for displaying tags in a centered, cloud-like format. Additionally, toggle buttons now respect light and dark theme variables for consistent styling.

extensions/tags/less/forum · high confidence

Nickname field becomes optional and permissions are configured

The Nicknames extension now allows users to leave their nickname blank, as the database migration updates the 'nickname' column in the users table to be nullable. Additionally, default permissions are set to allow members to edit their own nicknames.

extensions/nicknames/migrations · high confidence

Placeholder created for English locale directory

A .gitkeep file was added to the extensions/lang-english/locale directory to ensure the folder is tracked in version control. This structural change prepares the location for future locale-specific content but does not currently introduce any new user-facing features or behavioral changes.

extensions/lang-english/locale · low confidence

Prevent layout shift in emoji insertion and style emoji dropdown

The forum extension now reserves a fixed square box for inline emojis using an aspect-ratio property, preventing Cumulative Layout Shift (CLS) while SVGs load. Additionally, the emoji selection dropdown and composer wrapper have been styled with specific dimensions, padding, and layout rules to improve visual consistency and usability.

extensions/emoji/less · high confidence

Pusher extension restructured for Flarum 1.2 with TypeScript and custom server support

The Pusher extension has been updated to version 1.2.0, featuring a migration of the frontend codebase from JavaScript to TypeScript and a switch from jQuery to vanilla JavaScript. The extension now supports a configurable custom server hostname via the \flarum-pusher.server\_hostname\ setting, allowing users to specify a non-default Pusher host. Additionally, the internal implementation has been modernized to use the Laminas HTTP library instead of Zend, and the extension now properly exports locale files and manages build artifacts via \.gitattributes\.

extensions/pusher · high confidence

Pusher extension rewritten in TypeScript with custom server hostname support

The Pusher extension's JavaScript codebase has been converted to TypeScript, introducing stricter typing and modern build tooling via Webpack and a dedicated tsconfig. Administrators can now configure a custom \server\_hostname\ for the Pusher integration in addition to the existing app ID, key, secret, and cluster settings. On the forum, the extension uses vanilla JavaScript to manage Pusher connections, updating the discussion list with a new activity button and refreshing discussion pages in real-time, while removing the legacy jQuery dependencies.

extensions/pusher/js · high confidence

Redesigned mention styling and dropdown layout

The visual presentation of user, post, group, and tag mentions has been updated to use CSS variables for better theme integration, including specific styling for deleted mentions and colored group mentions. The mentions dropdown menu now features a constrained width and height with auto-scrolling, and includes improved preview layouts for posts and discussions. Additionally, the dropdown's maximum width is adjusted to full width on mobile devices to prevent overflow issues.

extensions/mentions/less · high confidence

Refactor likes extension database migrations and schema

The database migration logic for the likes extension has been updated to use a new helper-based format, improving maintainability. The underlying schema now enforces referential integrity by adding foreign keys on the post\_likes table that cascade deletes when associated posts or users are removed. Additionally, the table was renamed from posts\_likes to post\_likes, and a created\_at timestamp column was added to track when likes were recorded.

extensions/likes/migrations · high confidence

Sticky badge styling now uses CSS variables

The forum interface now uses CSS custom properties to manage the visual appearance of sticky indicators. The red background color for the sticky badge and the associated post icons/info is now defined via a variable, allowing for easier theme customization or consistent color application across the extension's UI elements.

extensions/sticky/less · high confidence

Sticky discussions now display excerpts and support filtering on the All Discussions page

Administrators can now enable sticky pinning on the All Discussions page and optionally restrict it to unread discussions only. Sticky discussions in the list view now display a truncated excerpt of the first post (controlled by a new admin setting), improving context without requiring users to open the thread. Additionally, a new search gambit allows filtering discussions by their sticky status.

extensions/sticky/js · high confidence

Sticky extension restructured for Flarum v1.2 with configurable pinning and optimized excerpts

The sticky extension has been updated to version 1.2, introducing new administrative controls and performance improvements. Administrators can now disable the pinning of sticky discussions to the top of the All Discussions page via the \flarum-sticky.pin\_sticky\_on\_all\_discussions\ setting, allowing stickied items to follow their natural posting time. Additionally, the API now serves discussion excerpts as lightweight text attributes rather than including full post objects, which reduces payload size and improves load times. The extension also includes structural updates to its search mutators and event listeners to align with Flarum's modern extender system.

extensions/sticky · high confidence

Subscription UI theming and styling

The subscription interface now supports distinct visual styles for light, dark, and high-contrast themes. Follow buttons and badges adapt their colors based on the active theme, with specific adjustments for high-contrast modes to ensure readability. The subscription menu dropdown has also been given a minimum width of 260px.

extensions/subscriptions/less · high confidence

Subscriptions extension restructured for Flarum 2.x with new auto-follow preferences

The subscriptions extension has been updated to align with Flarum 2.x architecture, introducing new user preferences to automatically follow discussions after creating a post or replying to one. The extension now uses the modern extender system for event listeners and API resources, and includes a new search filter to allow users to hide ignored discussions from the all-discussions page. Additionally, notification logic has been refined to ensure users only receive alerts for visible posts and to properly handle notification deletion or restoration when posts are hidden, deleted, or restored.

extensions/subscriptions · high confidence

Tags extension database schema updates and migrations

The Tags extension now includes a comprehensive set of database migrations to support evolving features and data integrity. Key changes include adding support for custom tag icons, automatic timestamps (created\_at/updated\_at), and a new 'is\_primary' flag to distinguish primary tags from secondary ones. The schema has been normalized with renamed tables (e.g., 'users\_tags' to 'tag\_user') and columns (e.g., 'read\_time' to 'marked\_as\_read\_at'), along with the addition of foreign key constraints for data consistency. Additionally, a new 'post\_mentions\_tag' table enables tracking tag references in posts, while legacy background styling columns have been removed to clean up the database structure.

extensions/tags/migrations · high confidence

Tags extension rewritten for Flarum 2.0 with new admin UI and tag selection modal

The Tags extension has been completely rewritten for Flarum 2.0, introducing a new admin interface with a dedicated Tags page for managing primary and secondary tags, including drag-and-drop reordering and configurable minimum/maximum tag limits. A reusable TagSelectionModal component now powers tag selection in both the forum discussion composer and admin settings, supporting features like bypassing tag requirements, parent tag dependencies, and CJK character width handling. The extension also adds tag-scoped permission scoping in the admin panel, lazy-loaded sortable functionality for performance, and TypeScript conversion of core components.

extensions/tags/js · high confidence

Tags extension v1.2.0: New permission, policy overhaul, and performance fixes

The Tags extension has been updated to v1.2.0, introducing a new 'bypass tag requirements' permission that allows specific users to create discussions without meeting the configured minimum tag counts. The extension's access control has been completely rewritten using a new policy structure (DiscussionPolicy, TagPolicy, GlobalPolicy) to simplify permission logic and fix regressions where 'own' abilities (like renaming or hiding a discussion) were incorrectly denied by tag restrictions. Performance has been improved by optimizing the tag count policy to use a single aggregate database query instead of multiple COUNT queries, and by deferring the policy check when no minimum tags are required. Additionally, the extension now properly disassociates child tags when a parent is deleted, fixing a data integrity issue.

extensions/tags · high confidence

Updated embed view styling for Flarum 2.x layout changes

The embed view's appearance has been updated to accommodate Flarum 2.x structural changes, specifically the introduction of the PageStructure component. The header and back navigation are now hidden to focus solely on the discussion content, and the layout has been adjusted from a two-column flex row to a single full-width column. Additionally, the discussion navigation bar is styled to float at the top without sidebar margins, and mobile dropdown menus have been repositioned to ensure correct display in the embedded context.

extensions/embed/less · high confidence

Updated user suspension database schema and permissions

The suspend extension's database migrations have been updated to refine how user suspensions are tracked. The 'suspended\_until' column on the users table was temporarily renamed to 'suspend\_until' and then restored to 'suspended\_until' to correct naming conventions. Additionally, new columns 'suspend\_reason' and 'suspend\_message' have been added to store details about the suspension, and a default 'user.suspend' permission has been assigned to moderators.

extensions/suspend/migrations · high confidence

Visual styling for flagged posts and flagging interface

The forum now applies specific CSS styles to posts that have been flagged, including a colored border, a distinct header bar with action buttons, and adjusted padding to visually separate flagged content. Additionally, the layout of the 'Flag Post' modal and the flag list header has been refined for better alignment and spacing.

extensions/flags/less · high confidence

Fixes

1 commit (1 fix) fixing extensions/flags/js/dist-typings/@types

A fix in extensions/flags/js/dist-typings/@types — 1 commit (1 fix), 1 file.

extensions/flags/js/dist-typings/@types · low confidence · unverified

Fix unapproved post styling to prevent UI interaction issues

The visual de-emphasis of unapproved posts has been corrected to avoid breaking user interface interactions. Previously, applying opacity to the entire post container created a stacking context that trapped dropdown menus and controls, making them unclickable. The new styles apply the fade effect only to specific child elements (such as the post body, header, and action buttons) while explicitly excluding the popup containers themselves, ensuring that menus and controls remain fully interactive and visible.

extensions/approval/less · high confidence

Fix view helper regression in ember.js

The framework update resolves a regression in the ember.js view helper, restoring expected behavior for view rendering and preventing potential errors in extensions or core components that rely on this helper.

framework · high confidence

Test coverage

Added integration and unit tests for the Audit extension; Added integration test infrastructure for the package manager; Added integration test setup for mentions extension; Added integration tests for Akismet key validation and spam handling; Added integration tests for GDPR audit logging; Added integration tests for GDPR console commands; Added integration tests for GDPR erasure confirmation; Added integration tests for approval audit logging and tag metadata updates; Added integration tests for extension manager API endpoints; Added integration tests for forum discussion start permissions; Added integration tests for nickname audit logging; Added integration tests for notification email injection prevention; Added integration tests for post flag visibility rules; Added integration tests for sticky discussion audit logging; Added integration tests for subscription and notification behaviors; Added integration tests for tag audit logging, slug handling, and policy performance; Added integration tests for tag default sort behavior; Added integration tests for tag visibility in the posts API; Added integration tests for tag-based discussion visibility; Added integration tests for tags authorization policies; Added integration tests for tags extension discussion API; Added integration tests for the Likes extension API; Added integration tests for the Lock extension audit log; Added integration tests for the Messages extension API; Added integration tests for the Statistics extension API; Added integration tests for the Tags API; Added integration tests for the embed extension's forum behavior; Added integration tests for the flags extension audit log; Added integration tests for the flags list API; Added integration tests for user suspension audit logging; Added placeholder files for likes extension test structure; Added test directory placeholders for statistics extension; Added test directory structure for sticky extension; Added test fixture and unit test directories; Added test fixture and unit test directories for the suspend extension; Added test fixtures for module export patterns; Added tests for PostMentionedNotification link generation; Added tests for tag route caching and default sort behavior; Added unit tests for GDPR DataProcessor and Type classes; Added unit tests for NicknameDriver sanitization; Added unit tests for TypingState clock synchronization and expiry logic; Added unit tests for extension compatibility checks; Added unit tests for the Akismet API client; Added unit tests for the Realtime extension's extender, registry, and websocket security logic; Added unit tests for the Statistics Widget's charting and custom range logic; Moved test fixtures and unit test directories to approval extension; New integration test infrastructure for Flarum; Reorganize test fixture and unit directories.

Dependencies

Flarum 2.0 dependency baseline and extension manifests

This change establishes the dependency baseline for Flarum 2.0 by introducing the root \flarum/framework\ composer package and individual \composer.json\ manifests for all bundled extensions (Akismet, Approval, Audit, BBCode, Embed, Emoji, Flags, GDPR, Likes, Lock, Mentions, Nicknames, Extension Manager, Pusher, Realtime, Statistics, Sticky, Subscriptions, Suspend, Tags, and Messages). The framework now requires PHP 8.3 and upgrades core libraries to Laravel 13 (Illuminate components), Symfony 7.4, FontAwesome 7, and s9e/text-formatter 2.x. Frontend build tooling is standardized across extensions using Webpack 5, TypeScript 4.5, and flarum-webpack-config 3.0.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 47.

Lenses

  • Code Health 85
  • Architecture 59
  • Maturity 51
  • Readiness 39
  • Security 73
  • Accessibility 47

Changes since last survey

  • 300 commits — 180 feature/other, 120 fixes

By area

  • framework/core — 176 commits
  • (root) — 30 commits
  • extensions/tags — 17 commits
  • extensions/audit — 15 commits
  • extensions/realtime — 9 commits
  • .github/workflows — 8 commits
  • extensions/statistics — 6 commits
  • extensions/sticky — 5 commits
  • extensions/mentions — 4 commits
  • extensions/messages — 4 commits
  • extensions/package-manager — 4 commits
  • extensions/approval — 3 commits
  • extensions/gdpr — 3 commits
  • js-packages/jest-config — 3 commits
  • extensions/akismet — 2 commits
  • extensions/embed — 2 commits
  • extensions/markdown — 2 commits
  • php-packages/testing — 2 commits
  • .github/ISSUE_TEMPLATE — 1 commit
  • extensions/flags — 1 commit

Notable commits

  • fix: Fix 500 error when page[limit]=0 is requested (#4775)
  • fix: Fix internal links landing on the index when installed in a subdirectory (#4976)
  • fix: Revert "[2.x] Harden the updater: authenticate it, and pause the queue while it runs (#4930)" (#4933)
  • fix: [2.x] Ask for the database version in bug reports, and note the 1.x status (#4919)
  • fix: [2.x] chore(ci): Fix PHP-version matrix, drop unused Xdebug, and modernise workflow actions (#4835)
  • fix: [2.x] chore: require the sourcemap release carrying the 8.5 deprecation fix (#4904)
  • fix: [2.x] feat: fail integration tests that run N+1 queries (and fix the first one it found) (#4871)
  • fix: [2.x] fix(a11y): Fix aria-label text key for New Discussion button (#4758)
  • fix: [2.x] fix(akismet): modernize the API client, fail open, verify keys, recheck edits (#4884)
  • fix: [2.x] fix(approval): scope the unapproved fade to text, not the whole post (#4836)
  • fix: [2.x] fix(core): bind the database transactions manager (#4800)
  • fix: [2.x] fix(core): harden avatar-from-URL fetch (#4795)
  • fix: [2.x] fix(core): notifications index 400 on invalid default include + n+1 (#4828)
  • fix: [2.x] fix(core): register default for show_language_selector setting (#4792)
  • fix: [2.x] fix(core): reject oversized-dimension images before decoding (#4794)
  • fix: [2.x] fix(core): render abandoned-extensions email body (#4804)
  • fix: [2.x] fix(gdpr): share view data for the erasure completion email (#4798)
  • fix: [2.x] fix(jest-config): make frontend testing work in standalone extensions (#4983)
  • fix: [2.x] fix(jest-config): resolve the 'flarum/...' import alias in tests (#4985)
  • fix: [2.x] fix(jest-config): transform core's source in standalone extension tests (#4984)
  • …and 280 more

Architecture

  • 0 containers · 1 bounded contexts · 0 dependency edges (baseline)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

flarum/framework was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b91ac1c2045bfcdd7c0392101fb377f616d46491 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.