Package Health

chevere/parameter

chevere/parameter 2.0.8 appears suitable to depend on: it is a stable, actively released package with 22 releases over 967 days, 10 releases in the last 12 months, a current non-archived repository, clear licensing, source alignment, repository tests, and build/security tooling. The main concerns are that recent repository activity is limited to 3 commits from one contributor, there is no security policy, and the workflows do not declare top-level permissions; these reduce resilience and transparency but are not by themselves evidence of abandonment or an unfit release.

Latest 2.0.8PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

All 3 recent commits came from one contributor, producing a 100% top-contributor share and a single-contributor bus factor. This is a genuine continuity concern, though organization ownership provides some potential handoff capacity.

Repo commit activitycaution

The repository recorded 3 commits in the last 3 months from one active maintainer. Recent activity is present but light, so maintenance capacity is more limited than the release history alone suggests.

Repo issue activitycaution

There are 6 open issues and no pull requests, with no new or closed issues or pull requests in the last month. The lack of recent issue activity is a modest transparency concern, although it does not establish abandonment.

Repo popularitycaution

The repository has 10 stars, 1 fork, and 0 watchers. This indicates limited adoption evidence, but popularity is supporting evidence and does not outweigh the package's release and maintenance signals.

Security policycaution

No repository security policy was found. This is a transparency and vulnerability-reporting gap, although the repository does use Sonar security scanning.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rodolfo Berrios

Direct Dependencies

DependencyLast ReleaseScore
chevere/regex
Version ^1.0.1
chevere/message
Version ^1.0.0
chevere/data-structure
Version ^1.1.0

Weekly Downloads

Info

Last Published
18 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform