Package Health

tempest/cryptography

This is a healthy, actively maintained release with strong recent release cadence, stable versioning, an unarchived organization-owned repository, a clear MIT license, a focused dependency profile, and recent activity from five contributors. The main concerns are highly concentrated commit activity, absent repository security scanning and security policy, and the linked repository not clearly matching or mentioning the package; these reduce transparency and resilience but are partly offset by the organization backing, active commits, and repository tests. The package appears reasonable to depend on, with normal supply-chain diligence recommended.

Latest v3.19.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo bus factorcaution

Commit activity is highly concentrated: one contributor made 47 of 51 commits, or about 92%. Organization ownership and four additional active contributors provide some handoff capacity, but the concentration remains a resilience concern.

Repo package mentioncaution

The repository name does not exactly match the package name, and the README mention value is null, so the package-to-repository relationship is not fully demonstrated by this signal. The repository URL is nevertheless specifically named for Tempest cryptography, making this a limited rather than severe concern.

Repo popularitycaution

The repository reports zero stars, forks, and watchers. This provides no supporting adoption evidence, but popularity is not decisive and the active release and commit signals are stronger indicators here.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are configured, leaving a security-process gap for a cryptography package.

Security policycaution

The repository has no security policy, which is a transparency and vulnerability-reporting gap for a package implementing encryption, signing, and password hashing.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
tempest/clock
Version 3.19.2
—
—
tempest/support
Version 3.19.2
—
—
tempest/container
Version 3.19.2
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform