Package Health

tempest/event-bus

This release appears healthy and suitable for dependency use: it is a stable major release with 104 releases, 81 releases in the last 12 months, and a latest release published very recently. The repository is active, not archived, backed by an organization, and has four active maintainers with 50 commits in the last three months; repository tests also compensate for the absence of packaged tests. The main concerns are highly concentrated commit activity, with one contributor responsible for 94% of recent commits, and limited security-process evidence because no security scanning tools or security policy were found. Overall, the strong release and maintenance activity outweighs these cautions.

Latest v3.19.2PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Package scaffoldingcaution

The artifact lacks a README, tests, and changelog, but the linked repository contains tests, which compensates for the missing packaged tests; the remaining documentation gap is a modest transparency concern.

Repo bus factorcaution

Recent activity is highly concentrated: the top contributor made 94% of commits, while the other three contributors made one commit each. Although organization backing provides some maintenance continuity, this concentration remains a caution.

Repo popularitycaution

The repository has zero stars and forks and only one watcher. This provides little external validation, but popularity is supporting evidence and does not outweigh the demonstrated release and commit activity.

Repo toolingcaution

The repository uses Composer for builds, but no security scanning tools are present. Composer supports reproducible project tooling, while the absence of scanning modestly reduces assurance.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
tempest/core
Version 3.19.2
—
—
tempest/container
Version 3.19.2
—
—
tempest/reflection
Version 3.19.2
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform