The package includes a clear README, matching Apache-2.0 licensing, repository tests, and no install-time scripts. Organization ownership and Composer/Sonar tooling add useful structure, but the release has little evidence of ongoing stewardship.
42%
Total Score
50
100
75
67
This is the package's only release, published in February 2022, with no releases in the following four years and seven months. That strongly increases abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of newer registry releases. This is a substantial maintenance concern.
The repository has zero stars, forks, and watchers, providing no community adoption signal. Popularity is supporting evidence rather than a verdict, so this only modestly reinforces the broader inactivity concern.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented. This is a transparency gap, though it is less severe than the maintenance evidence.
Version 0.1.0 is not a stable major release, which signals an immature API. It is not marked prerelease, so the concern is limited to maturity rather than release labeling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
chevere/chevere Version ^0.3 | — | — |
chevere/var-dump Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.