Package Health

chevere/message

The repository is small but documented, licensed, tested, and backed by an organization with security scanning. Maintenance has slowed, and all seven workflow actions are unpinned, with one archived action adding supply-chain hygiene risk.

Latest 1.0.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

There have been only two releases, with none in the last 12 months and the latest released over two years ago. This indicates limited ongoing release activity, although the package may be stable.

Repo commit activitycaution

There were no commits and no active maintainers in the three months measured. This is a maintenance concern, partly offset by the repository having been pushed in March 2025.

Security policycaution

No repository security policy was found. For a small library this is a transparency gap, though security scanning is present.

Workflow auditcaution

All seven analyzed action references are unpinned, and a high-confidence medium-severity finding identifies an archived action. The workflows have no untrusted checkout or script-injection findings, but their dependency hygiene still needs attention.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rodolfo Berrios

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform