This release appears healthy and suitable for dependency use: it is actively maintained, with 81 releases in the last 12 months, 46 commits in the last 3 months, a stable non-prerelease version, no registry deprecation, and a non-archived organization-owned repository. The main concerns are concentrated recent commit activity from one maintainer, the absence of a security policy and security-scanning tooling, and repository/package identity evidence that is incomplete; these warrant review but do not outweigh the strong release and maintenance cadence. The package artifact also lacks a README, tests, and changelog, although repository tests and a complete license file provide some compensation.
78%
Total Score
75
100
88
90
All 46 recent commits came from one contributor, creating a genuine continuity and bus-factor concern. Organization ownership provides some maintenance backing, but no second active contributor is shown.
No new issues or pull requests were recorded in the last month, and there were no merged pull requests. This is limited evidence because the open-issues count is unknown, while the strong release and commit cadence provides some compensation.
The repository name does not exactly match the package name, and no README mention was collected, so the linkage evidence is incomplete. Although naming differences can occur for subpackages, this signal still warrants verifying that the repository is the intended source.
Composer build tooling is present, but no security-scanning tools are configured. The missing scanning is a transparency and hygiene gap, though it is not by itself evidence of unsafe code.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^3.0 | — | — |
tempest/core Version 3.19.2 | — | — |
symfony/cache Version ^7.3|^8.0 | — | — |
tempest/clock Version 3.19.2 | — | — |
tempest/kv-store Version 3.19.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.