Package Health

telesign/telesignenterprise

This release appears suitable for dependency use: it has a long release history dating from 2017, nine releases in the last 12 months, stable versioning, no registry deprecation, an unarchived repository recently pushed, an MIT license, tests, a clear README, and a small dependency footprint. The main concerns are that recent repository activity is sparse and concentrated in one contributor, the repository has little popularity and no security policy or security-scanning tooling. Those concerns are moderated by the TeleSign organization backing the repository and by the package's continued release cadence, but they warrant monitoring rather than making the package a clear low-risk choice.

Latest v5.3.1PackagistPackagist

79%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health checks

Repo bus factorcaution

All recent commits came from one contributor, creating concentration risk; the organization-owned repository provides some ability to hand maintenance off, so this is caution rather than severe risk.

Repo commit activitycaution

Only 1 commit was recorded in the last 3 months from 1 active maintainer, indicating sparse recent repository activity despite the strong registry release cadence.

Repo issue activitycaution

There are 2 open issues and 1 open pull request, but no issues or pull requests were opened or merged in the last month, suggesting limited recent community activity.

Repo popularitycaution

The repository has only 5 stars and 5 forks, which limits external validation and community support; this is a caution, but popularity is supporting evidence rather than a verdict.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected, leaving a security-hygiene gap that is relevant to a dependency SDK.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Telesign Corp.

Direct Dependencies

DependencyLast ReleaseScore
telesign/telesign
Version ^5.2

Weekly Downloads

Info

Last Published
15 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform