Package Health

tempest/database

This release appears healthy and suitable for dependency use: it is actively maintained, with 80 releases in the last 12 months, 59 commits from 8 active maintainers in the last 3 months, a stable non-prerelease version, an unarchived repository, and no deprecation notice. The MIT license, substantial package tree, repository tests, Composer build tooling, and absence of install-time lifecycle scripts support transparency and predictable consumption. The main concerns are heavy recent commit concentration in one contributor, no security policy or security scanning, and very low repository popularity, although organization backing and continued activity reduce the abandonment risk. Several potentially useful signals were not collected, so this assessment is not fully certain.

Latest v3.19.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo bus factorcaution

One contributor made about 83% of the 59 recent commits, creating concentration risk; however, seven other contributors were active and the repository is owned by an organization, which partly mitigates handoff risk.

Repo popularitycaution

The repository has 0 stars and 0 forks, with 2 watchers. Low popularity is supporting caution about external adoption and validation, but it is not decisive because the package shows strong direct maintenance activity.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The build setup is appropriate, while the missing security automation is a modest transparency and assurance gap.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations undocumented and creating a modest maintenance and transparency gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
tempest/intl
Version 3.19.2
tempest/mapper
Version 3.19.2
tempest/support
Version 3.19.2
tempest/container
Version 3.19.2
tempest/event-bus
Version 3.19.2

Weekly Downloads

Info

Last Published
16 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform