Moorkeep

Keep your Flowise flows. Get the security releases.

Flowise was archived on 13 August 2026. The app still works. What decays is everything underneath it: a frozen dependency tree that nobody upstream will update again. Moorkeep is an independent, maintained fork of Flowise: open source, with security releases on a stated schedule from the first release. It runs on your servers, never ours. For teams that need someone on the hook for the deadlines, there is a support plan.

Tell us what you run Get release news
349 published security advisories in the 3.1.4 dependency tree
18 of them rated critical, 132 high
0 upstream releases since the archive, and none planned

Distinct GitHub advisory IDs in pnpm audit --json, counted on 29 September 2026 against the archived 3.1.4 lockfile, development tooling included; the same tree counts higher as new advisories are published. Our first patch set, committed but not yet released or fully tested, brings the count to 89 (1 critical, 28 high), measured the same day with the same database. That count leaves out one more critical advisory, CVE-2026-12866 in expr-eval: the patch set swaps the package for a fork the advisory does not name, the fork still contains the vulnerable function, and our own code never calls it. The two widely reported Flowise CVEs were fixed upstream before the archive. Anything found since stays unfixed upstream: four defects in 3.1.4's own code have already been published by another fork, and our first patch set contains fixes for them, not yet fully tested; the dependencies beneath keep accumulating advisories.

What we ship

Security releases

From the first release, the following deadlines are in writing for Supported customers and best effort for everyone else, with the same public releases for both. Security advisories that affect code Moorkeep ships, rated Critical or High by the GitHub Advisory Database (or, if it gives no rating, by the US National Vulnerability Database), are resolved within 14 calendar days if Critical and within 30 calendar days if High: by a release that fixes or removes the vulnerable code or, until that release can ship, by a published mitigation or by published evidence that nothing Moorkeep ships can reach it. The clock starts when the advisory is first published or first reported to us, whichever is earlier, and never before Moorkeep's first release. The public changelog records each outcome, its deadline and whether we met it, misses included. Nothing has shipped yet, so there is no record to show you; judge us on the first quarter.

Monthly maintenance

Dependencies and toolchain kept current on Node.js 24 LTS, with the release notes to match.

An upgrade path from Flowise 3.x

Designed to take over an existing single-workspace 3.x database: flows, credentials, API keys and files. We will test it against throwaway 3.x databases that operators create for the purpose, with no real data, and publish the result before the first release ships; if it does not pass, it does not ship. Back up before you upgrade, and expect installations with several workspaces or users to need work.

Open source, Apache-2.0

The maintained line is free, and nothing is held back from it. You pay only for the deadlines in writing and someone to call.

Plans

Monthly, per production deployment.

CommunitySupported
Maintained releases, Apache-2.0YesYes
Deadlines in writing: Critical 14 calendar days, High 30 calendar daysNo, best effortYes
Every outcome and deadline in the public changelog, misses includedYesYes
Named contact, answers in business hoursNoYes
Help upgrading from Flowise 3.xNoYes
Runs onyour serversyour servers
PriceFree$299

Nothing is held back from the free line. You pay for the commitment, not for access: the same builds, the same code, the same licence. What $299 buys is a deadline we are on the hook for and someone to call. We do not host anything — your data never reaches us, on either plan.

Founding customers: the first 10

Supported at $249 a month, locked for 12 months, starting in the month the first release ships. Reserve it today with a non-binding letter of intent. No payment is taken now, and you can withdraw it at any time. To use the price, subscribe within 60 days after that release.

The small print, up front

Moorkeep is an independent, maintained fork of Flowise under the Apache License 2.0. It is not affiliated with or endorsed by FlowiseAI, Inc. or Workday, Inc.

It is single-tenant: one organization, one workspace, one administrator, plus API keys. The multi-user roles and SSO of the old enterprise edition are not part of it.

Support runs in business hours, Israel time, which overlaps the European day and the US East Coast morning. It is not 24/7.

Tell us what you run

Six questions, under 90 seconds. Answer as many as you like — even one is useful. We read every answer and reply to each one.

  1. Which Flowise version runs in production?
  2. How long has it been running, and how many people depend on it?
  3. What broke, or what worries you, since the project was archived?
  4. What does it do for your business, in one sentence?
  5. What would you want from a maintained build — security releases, someone to run it, someone to call, help migrating away, or nothing yet?
  6. What would that be worth per month?

Answer by e-mail

The link opens your own mail program with the questions already in it, so nothing you write passes through a form service. Or write to eitanp214@gmail.com in your own words. We use what you send only to reply and to decide what to build, we never sell it, and we delete it if you ask. An AI assistant helps us read and answer mail; the Privacy Policy names every company involved and the few cases where we must share anything at all.

Release news only

One e-mail per release, nothing else.

Ask to be added

Questions

Is this the official Flowise?

No. Its owner archived the project and suggested that teams fork it, naming no successor. Moorkeep is one independent fork, under its own name, and not affiliated with FlowiseAI, Inc. or Workday, Inc.

When does the first release ship?

When the build passes its tests on SQLite and Postgres, including the 3.x upgrade tests. Everyone gets it the same day: it is Apache-2.0 software and there is no private build. What founding customers get is the price, not a head start. Everyone on the release list hears the date.

Why not just migrate to another tool?

You can, and for some teams it is the right call. It means rebuilding and re-testing every flow. Moorkeep is for teams whose flows work and who need them kept secure.

What happens to the enterprise features?

The enterprise edition was under a separate commercial licence, so it is not in Moorkeep; those paths were removed before the first commit. Sign-in, one workspace and API keys are still there. We cannot speak for other forks; check what each one ships.