This is a healthy, actively maintained release with strong release cadence, current repository activity, stable versioning, an unarchived organization-backed repository, clear MIT licensing, and no install-time lifecycle scripts. The main concerns are that recent commit activity is highly concentrated in one contributor, the repository has no security scanning or security policy, and the artifact lacks a README and changelog; however, repository tests and substantial package structure provide meaningful compensation. The package appears reasonable to depend on, with normal monitoring of maintainer continuity and security practices advisable.
82%
Total Score
75
100
89
90
The artifact lacks a README, tests, and changelog, but the linked repository does contain tests; the missing packaged tests are therefore compensated, while the absent README and changelog remain minor transparency gaps.
Four contributors were active, but the leading contributor made 48 of 52 commits, or about 92%, creating a genuine concentration and continuity risk. Organization backing partly mitigates handoff risk, but does not remove the dependence on one active contributor.
There were no new or closed issues and no pull requests in the last month, which provides little evidence of community interaction, although the lack of open pull requests does not itself indicate abandonment.
Composer build tooling is present, but no security scanning tools are configured, leaving a security-process gap despite otherwise normal build support.
The repository has no published security policy, which reduces transparency around vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tempest/log Version 3.19.2 | — | — |
tempest/core Version 3.19.2 | — | — |
tempest/support Version 3.19.2 | — | — |
tempest/container Version 3.19.2 | — | — |
tempest/highlight Version ^2.11.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.