This is a generally healthy release to depend on: it is actively and frequently released, is on a stable major version, is not deprecated, has a permissive MIT license, uses a modest runtime dependency set, and is backed by a non-archived organization-owned repository with recent activity and four active contributors. The main concerns are that nearly all recent commits come from one contributor and the repository lacks a security policy and security-scanning tooling; these reduce resilience and transparency but do not indicate abandonment, especially given the organization backing and strong release cadence. The package artifact is minimal, but repository tests compensate for the absence of packaged tests and documentation.
78%
Total Score
88
100
94
90
One contributor made 46 of 49 commits, or about 94%, creating a meaningful concentration risk. The presence of three additional active contributors and organization ownership partly compensates, so this is caution rather than danger.
Composer build tooling is present, but no security-scanning tools are reported. This is a security-hygiene gap, although it is not evidence of abandonment or malicious behavior.
The repository has no security policy, reducing transparency around vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tempest/intl Version 3.19.2 | — | — |
tempest/support Version 3.19.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.