# Flarum: a PHP forum skeleton, and what you actually get when you clone it

> The flarum/flarum repository is the skeleton application, not the engine. Here is what that means for installation, extensions, and the v2.0 release candidates now on the 2.x branch.

**flarum/flarum** — Simple forum software for building great communities.

- Repository: https://github.com/flarum/flarum
- Website: https://flarum.org
- Stars: 16,407 · Forks: 1,665
- Language: PHP
- License: MIT
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/flarum-flarum

## The repository is the skeleton, and that changes your first hour

The README states plainly that this repository only holds the Flarum skeleton application, and that most development happens in flarum/core. That single sentence explains most of the confusion a newcomer hits. Cloning flarum/flarum gives you a thin shell: composer.json, public/, storage/, site.php, extend.php, a flarum executable, and an .nginx.conf. It does not give you the discussion engine, the API, or the admin frontend. Those arrive as Composer dependencies.

The practical consequence is that you cannot read this repository to understand how Flarum works. The architecture you care about lives elsewhere. What you can read here is the deployment contract: which directories must be writable, what the web root is, and how the application is bootstrapped. If you are evaluating Flarum as a platform, this repo tells you how it is packaged, not what it does.

The audience follows from that. This is for people who already decided to run Flarum and want to know what they are deploying. It is also for anyone debugging a broken install, because the skeleton is where path and permission problems surface.

## How a PHP skeleton loads a forum: Composer, public/, and storage/

Flarum is built with PHP, and the README describes the interface as powered by Mithril, a JavaScript framework with a small footprint. That split matters for how requests flow. Static assets and the PHP entry point sit under public/, which is the directory your web server should point at. The .nginx.conf at the top level is a starting configuration for exactly that.

Application state and generated files go to storage/, which is why the skeleton ships the directory rather than creating it at runtime. The flarum executable at the repository root is the console entry point. The extend.php file is where skeleton-level extension registration happens, separate from the extensions you install as packages.

Because the skeleton is a Composer project, the dependency graph is the real source of truth about which Flarum version you get. The README points at Packagist for flarum/core, and the badges there track the stable version and total downloads. The repository's default branch is 2.x, and the most recent releases listed are v2.0.0-rc.8, v2.0.0-rc.7 and v2.0.0-rc.6, all dated August 2026. The last push to the repository was on 2026-08-27. That is a release-candidate line, not a finished stable release, and it is the honest description of where 2.x stands.

## Installing Flarum: where the README sends you

The README does not contain install commands. It says to read the installation guide at docs.flarum.org/install, and directs support questions to the documentation, the community forum, and Discord. That page, not this repository, is where the steps live.

What the repository does tell you is the shape of the result. The top-level entries are .editorconfig, .gitattributes, .gitignore, .nginx.conf, CHANGELOG.md, LICENSE, README.md, composer.json, extend.php, flarum, public/, site.php and storage/. A working installation should match that layout, which means your web server's document root belongs on public/ and storage/ needs to be writable by the PHP process. The bundled .nginx.conf is the reference for the first part if you run nginx. Getting those two wrong produces the most common first-run failures: a blank page when the root points one level too high, or write errors when storage/ is owned by the wrong user.

The flarum file at the repository root is the console entry point. Because the README gives no command list, the installation guide is the source for which commands to run against it. The same applies to extensions: the README frames extensibility as the Extension API and points at the documentation, so it does not name packages or enable steps here. After setup, the admin interface is where extensions are enabled and the forum's appearance is adjusted.

## The 2.x branch is on release candidates, and that is a real constraint

The default branch is 2.x. The three most recent releases are all v2.0.0 release candidates, the newest dated 2026-08-27. Nothing in the repository shows a v2.0.0 stable tag. If you deploy from the default branch or from a loose version constraint, you are running pre-release code, and the release notes for any given candidate are where you would look for what changed between them.

That is not a reason to avoid Flarum. It is a reason to be deliberate about your composer.json constraint. A project that pins to a stable line and a project that tracks 2.x are making different bets, and the README does not help you choose between them. It also does not document rollback, so there is no answer there to the question of how you would return to a previous version after a failed upgrade. Treat that as an open item to resolve from the installation guide before you upgrade anything in production.

The extension ecosystem compounds this. The README describes the Extension API as the way to customize and integrate Flarum, but it does not state which extensions are compatible with which core version. On a release-candidate line, that compatibility question is the one most likely to cost you an afternoon.

## Flarum vs Discourse, phpBB and NodeBB: where the approaches diverge

The comparison people ask about most is Flarum vs Discourse. The difference visible in this repository is the runtime. Flarum is PHP, and the README presents that as a deployment advantage: quick and easy to deploy, with no complex dependencies. Discourse is not PHP, so the operational shape of the two is different from the first step. If your hosting is a conventional PHP stack, Flarum fits it without a separate application server.

The frontend is the second divergence. Flarum's interface is powered by Mithril, a small JavaScript framework. That is a deliberate choice toward a light client rather than a large single-page application bundle.

Against phpBB, the difference is packaging and extension model. phpBB is long-established forum software; Flarum is a Composer project whose functionality is assembled from core plus extension packages, with the skeleton repository as the starting point. Against NodeBB, the split is PHP versus a Node.js runtime, which usually decides the question on hosting grounds before anything else.

What the README does not give you is a feature-by-feature comparison against any of these. It makes claims about simplicity, responsiveness and extensibility, and those are the project's own framing. Anyone choosing between Flarum and a competitor should weigh the runtime and extension model first, because those are the parts you cannot change later.

## Licence and the cost of keeping a Flarum forum current

Flarum is open-source software licensed under the MIT License, and the LICENSE file sits at the repository root. MIT is permissive: it allows commercial and closed-source use, and it does not impose copyleft obligations on your own code. That is a statement about the licence text, not legal advice, and the extensions you add may carry their own licences, which the README does not cover.

The maintenance cost is the more interesting number. Upgrading means changing a Composer constraint and running the console entry point, but the actual work is in the extensions, and the README gives no compatibility matrix. On the 2.x release-candidate line, each candidate is a new moving part. Budget for the possibility that an extension lags behind core and blocks an upgrade.

There is also a structural cost to the skeleton split. When something breaks, you have two repositories to reason about: this one for paths, permissions and bootstrap, and flarum/core for behaviour. The README is explicit that most development happens in core, so bug reports and security issues belong there. The security policy link in the README points at flarum/core's policy, not this repository's.

## Conclusion

Adopt Flarum if you want a PHP forum you can deploy on ordinary hosting and extend through Composer, and if you are comfortable running on 2.x release candidates or pinning to stable. Do not adopt it if you expect the repository you clone to contain the forum engine, or if you need a documented rollback path for upgrades, because the README does not describe one. Before committing, read the installation guide at docs.flarum.org/install, check which core version your Composer constraint resolves to, and confirm your host meets the PHP requirements listed there.

## FAQ

### Is Flarum free?

Yes. Flarum is open-source software licensed under the MIT License, with the LICENSE file at the repository root. The MIT License permits commercial and closed-source use.

### How do I install Flarum?

The README directs you to the installation guide at docs.flarum.org/install rather than listing steps itself. The repository is a Composer skeleton, and the flarum file at its root is the console entry point the guide's commands run against.

### What are the key differences between Discourse and Flarum?

Flarum is built with PHP and its interface is powered by Mithril, a small JavaScript framework. Discourse does not share that PHP runtime, so the deployment shape differs from the first step. The README does not provide a feature-by-feature comparison of the two.

### Is Flarum dead?

No. The repository is not archived, and the last push was on 2026-08-27. The most recent releases are v2.0.0-rc.8, v2.0.0-rc.7 and v2.0.0-rc.6, all dated August 2026, so the 2.x line is on release candidates rather than a stable v2.0.0.

### What is Flarum?

Flarum is a PHP discussion platform, described in the README as a simple forum for building communities, with an interface powered by Mithril. This repository holds only the skeleton application; the engine and most development live in flarum/core.

## Sources

- [flarum/flarum on GitHub](https://github.com/flarum/flarum)
- [License: MIT](https://github.com/flarum/flarum/blob/2.x/LICENSE)
- [Project website](https://flarum.org)
- [README](https://github.com/flarum/flarum/blob/2.x/README.md)
- [Releases](https://github.com/flarum/flarum/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/flarum-flarum
