The source repository remains active and has security scanning, but only one contributor made the last four commits and no security policy is published. The workflow audit also found all 11 action references unpinned, reducing build reproducibility.
22%
Total Score
83
71
50
The registry marks the entire package as abandoned and names chevere/xrdebug as its replacement, making this release unsuitable for a new dependency despite other healthy project evidence.
A post-autoload-dump install-time script runs during dependency installation, adding execution behavior that developers should account for, though this alone is not evidence of abandonment.
The package has 17 releases over roughly four years, but has had no registry release in the last 21 months, indicating a substantial release gap.
All four recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository name differs from the package name and its README does not mention the package, so the link may not clearly establish that this repository publishes this package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
relay/relay Version ~2.0 | — | — |
chevere/http Version ^0.4.0 | — | — |
chevere/router Version ^0.6.0 | — | — |
chevere/schwager Version ^0.2.0 | — | — |
chevere/standard Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.