Package Health

harvesthq/chosen

The MIT license, clear package contents, and absent install hooks reduce adoption and supply-chain friction. The organization-backed source is not archived, but the registry has not published a release since 2018 and recent repository activity is absent.

Latest v1.8.7PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Are you affected? Scan for Free

Health Score Breakdown

Release historycaution

Only two releases were published, with the latest in 2018 and none in the last 12 months. This is a meaningful maintenance concern, although the linked repository is not archived.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last 3 months, weakening evidence of ongoing maintenance even though the repository is not archived.

Security policycaution

The linked repository has no security policy, leaving vulnerability-reporting expectations unspecified. This is a hygiene gap, not evidence that the package is unsafe by itself.

Vulnerabilities

TitleVersionsSeverity
CVE-2018-25050
harvesthq/chosen is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.8.7.
0.0.0 - 1.8.7
Medium

Package versions

Maintainers

Koen Punt
Patrick Filler
Christophe Coevoet
Ken Earley

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
8 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform