Package Health

tempest/discovery

This release appears suitable to depend on: it has a strong and current release cadence, a stable non-prerelease version, an MIT license, no registry deprecation, an active non-archived repository, and substantial recent commit activity from four contributors. The main concerns are that 92.2% of recent commits come from one contributor, the repository has no security scanning or security policy, repository popularity is minimal, and the repository does not match the package name with no README mention available to confirm the linkage. The artifact's lack of tests and a README is partly compensated by the repository containing tests and a complete source tree, so these are not major release-health concerns.

Latest v3.19.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo bus factorcaution

Although four contributors were active, one contributor made 47 of 51 commits (92.2%), creating a meaningful concentration and handoff risk. Organization ownership partly mitigates this because maintenance can be transferred within the organization.

Repo package mentioncaution

The repository name does not match the package name, and no README package mention was available to confirm the relationship. This warrants caution about repository linkage, although a name mismatch can be normal for a sub-package or project repository.

Repo popularitycaution

The repository has zero stars and forks and only one watcher, so external adoption evidence is minimal; this lowers supporting confidence but is not decisive for a small package.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured, leaving a security-hygiene gap in the repository.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and response procedures.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/container
Version ^2.0
—
—
symfony/cache
Version ^7.3|^8.0
—
—
tempest/support
Version 3.19.2
—
—
tempest/reflection
Version 3.19.2
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform