The repository includes tests, a useful README, and a matching MIT license. Two active contributors provide some maintenance capacity, but the project has little release history and lacks a security policy or scanning.
71%
Total Score
100
100
83
83
The package is only 109 days old with three releases, and its latest release was about 12 weeks before collection. This is too little history to establish durable maintenance, though it does not yet show abandonment.
Composer build tooling is present, but no security scanning tools were detected. This modestly weakens assurance around dependency and source maintenance.
The repository has no security policy, leaving maintainers' reporting and response process unclear. This is a transparency gap for a library that executes an external downloader.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tempest/mapper Version ^3.9 | — | — |
tempest/process Version ^3.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.