Package Health

chevere/action

Clear licensing, repository tests, release notes, and security tooling add useful confidence. The single active contributor and unpinned workflow actions remain the main reservations.

Latest 3.0.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo bus factorcaution

All 2 recent commits came from one contributor, concentrating maintenance responsibility; organization backing provides some ability to hand work off, but no second active contributor is shown.

Repo commit activitycaution

Only 2 commits were recorded in the last 3 months, showing limited recent development activity, although the release history provides compensating evidence of continued publishing.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting expectations unclear for a library consumers may integrate into applications.

Workflow auditcaution

Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all 7 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rodolfo Berrios

Direct Dependencies

DependencyLast ReleaseScore
chevere/message
Version ^1.0.0
—
—
chevere/parameter
Version ^2.0.5
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform