Package Health

tempest/command-bus

This release appears healthy and suitable for dependency use: it is actively and frequently released, stable, not deprecated, backed by a non-archived organization-owned repository, and includes a clear MIT license. The repository contains tests and shows recent activity from four contributors, although commit ownership is highly concentrated in one contributor, the repository has no security scanning or security policy, and the linked repository does not clearly mention the package in its README. These are meaningful transparency and resilience concerns, but they do not outweigh the strong release and maintenance evidence.

Latest v3.19.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo bus factorcaution

Four contributors were active, but one contributor made 45 of 49 commits, a 91.8% share. Organization ownership provides some handoff capacity, yet the observed activity remains highly concentrated and creates contributor-resilience risk.

Repo package mentioncaution

The repository name does not match the package name, and no README package mention was available. Because the repository URL is otherwise package-specific, this is a transparency concern rather than conclusive evidence of repository misassociation.

Repo popularitycaution

The repository has zero stars and forks and one watcher. This is weak supporting evidence, but popularity is not decisive and is outweighed by the observed release and commit activity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are detected. The build setup is adequate, while the missing security automation is a modest transparency and hygiene gap.

Security policycaution

The repository has no security policy. This is a genuine disclosure-process gap, although it is not evidence that the package is unsafe or abandoned on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
tempest/core
Version 3.19.2
—
—
tempest/console
Version 3.19.2
—
—
tempest/container
Version 3.19.2
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform