A chevere throwable-handler component.
42%
Total Score
unhealthy
Risky: over four years without maintenance makes this release a liability despite clear licensing and tests.
This package has only one release, on February 10, 2022, and none in the last 12 months; the long period without releases materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's prolonged lack of releases and indicating no current maintenance capacity.
One registry account has publish access, a thin publishing base that adds some operational fragility; the organization-owned repository provides project backing but does not demonstrate active maintenance.
No repository security policy was found, leaving vulnerability-reporting guidance unclear; this is a modest transparency gap for a maintained dependency.
All 11 analyzed action references are unpinned, and a high-confidence medium-severity finding identifies an archived action; there are no untrusted checkouts, script injections, or broad top-level write permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
chevere/trace Version ^0.1 | — | — |
chevere/chevere Version ^0.3 | — | — |
chevere/var-dump Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.