Package Health

ecotone/tempest

The package has a substantial README, repository tests, organizational ownership, and a rapid release cadence. Its beta status, single active contributor, licensing split, and absent security policy leave less assurance for a foundational integration.

Latest 2.0.0-beta.1PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensecaution

The artifact contains license files and detected Apache-2.0 text, so the release is licensed. The manifest's additional proprietary declaration does not cleanly align with the detected Apache-2.0 license and warrants checking the enterprise terms.

Repo bus factorcaution

One contributor made all 14 commits in the last three months, creating a real continuity risk. Organizational ownership provides some handoff capacity, but no second active contributor is shown.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool was detected. For an integration package, that is a modest transparency and maintenance gap rather than evidence of unsafe code.

Security policycaution

The repository has no security policy. That leaves vulnerability reporting and response expectations unclear for a package handling application integration and database-related features.

Version stabilitycaution

Version 2.0.0-beta.1 is explicitly a prerelease, so its API and behavior may still change. Only 1 of the 15 recent releases was a prerelease, which partly limits the concern but does not remove beta risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dariusz Gafka

Direct Dependencies

DependencyLast ReleaseScore
ecotone/ecotone
Version ~2.0.0-beta.1
tempest/framework
Version ^3.11

Weekly Downloads

Info

Last Published
24 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform