Healthy and suitable to depend on, with clear licensing, recent releases, repository tests, and active organization backing. The main caveat is that recent work is concentrated in one contributor, while 12 issues remain open and the workflows do not declare top-level permissions.
82%
Total Score
70
100
100
75
All 3 recent commits came from one contributor, creating continuity risk. Organization ownership partly compensates because maintenance can be handed off, but no second recent contributor is shown.
The repository had 3 commits in the last 3 months, showing recent activity, but the pace is light for a maintained library.
There are 12 open issues, with one new issue and no issues or pull requests closed in the last month. This is a modest maintenance concern, though it is not by itself evidence of abandonment.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, although the available security scanning provides some compensating evidence.
Neither workflow declares top-level token permissions. No workflow requests top-level write access, but explicit least-privilege settings are still absent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
chevere/trace Version ^2.0.2 | — | — |
chevere/message Version ^1.0.0 | — | — |
chevere/var-dump Version ^2.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.