The README and release notes make installation and the current changes clear, while the package has a manageable dependency set. Its install hook and missing security policy add smaller maintenance concerns, but the main issue is that development appears to have stopped.
43%
Total Score
25
79
50
The package has 40 releases, but none in the last 12 months; its latest release was over a year ago after a brief burst of activity. That sharp stop is a meaningful abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap. This is strong evidence that fixes and support may not arrive promptly.
A post-install command runs during installation, adding operational complexity and another execution point compared with a package that only exposes files. The signal is a modest concern, not evidence that the package is unsafe.
There are 16 open issues, with no issues or pull requests opened, closed, or merged in the last month. The unresolved backlog reinforces the maintenance concern.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported. This is a secondary concern compared with the stalled development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.2 | — | — |
tempest/core Version * | — | — |
league/commonmark Version ^2.7 | — | — |
tempest/framework Version ^1.0 | — | — |
tempest/highlight Version ^2.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.