Package Health

tempest/container

This is a healthy, actively maintained release with strong recent release and commit activity, a stable major version, an unarchived repository, clear MIT licensing, and a modest runtime dependency profile. The repository is organization-owned and includes tests even though tests and a README are not packaged, which compensates for the artifact-level scaffolding gap. The main reservations are that 94% of recent commits come from one contributor, the repository has no security scanning or security policy, and repository popularity is very low; these are meaningful transparency and resilience concerns but do not outweigh the evidence of current maintenance and frequent releases.

Latest v3.19.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Repo bus factorcaution

Although four contributors were active, the top contributor made 46 of 49 recent commits, creating substantial contributor-concentration risk. Organization backing partly compensates because maintenance can be handed off within the project.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured; this is a moderate supply-chain transparency gap rather than evidence of abandonment.

Security policycaution

The repository has no documented security policy, reducing transparency around vulnerability reporting and response procedures.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^2.0
—
—
tempest/reflection
Version 3.19.2
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform