Package Health

chevere/xr-server

The source repository remains active and has security scanning, but only one contributor made the last four commits and no security policy is published. The workflow audit also found all 11 action references unpinned, reducing build reproducibility.

Latest 2.0.3PackagistPackagist

22%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Registry deprecationdanger

The registry marks the entire package as abandoned and names chevere/xrdebug as its replacement, making this release unsuitable for a new dependency despite other healthy project evidence.

Lifecycle scriptscaution

A post-autoload-dump install-time script runs during dependency installation, adding execution behavior that developers should account for, though this alone is not evidence of abandonment.

Release historycaution

The package has 17 releases over roughly four years, but has had no registry release in the last 21 months, indicating a substantial release gap.

Repo bus factorcaution

All four recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown.

Repo package mentioncaution

The repository name differs from the package name and its README does not mention the package, so the link may not clearly establish that this repository publishes this package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rodolfo Berrios

Direct Dependencies

DependencyLast ReleaseScore
relay/relay
Version ~2.0
chevere/http
Version ^0.4.0
chevere/router
Version ^0.6.0
chevere/schwager
Version ^0.2.0
chevere/standard
Version ^1.0.1

Weekly Downloads

Info

Last Published
1 year ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform