Package Health

tempest/framework

This release appears healthy and suitable for dependency use: it has a stable major version, 102 releases over roughly 2 years, 80 releases in the last 12 months, and very recent repository activity. The linked organization-owned repository is active, has 24 contributors in the last 3 months, substantial issue and pull-request throughput, tests, documentation, changelog coverage, and clear package references. The main deductions are supply-chain hygiene concerns in the repository: no security policy, limited explicit workflow permission declarations, two workflows with top-level write permissions, and one detected script-injection pattern. These merit review but do not outweigh the strong maintenance and transparency evidence.

Latest v3.19.2PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

All 15 workflows were analyzed with no pull_request_target or untrusted-checkout findings, but one workflow contains a script-injection pattern. This is a concrete workflow-security concern requiring review.

Dependency profilecaution

The release declares 44 runtime dependencies, reflecting a broad framework scope and increasing transitive maintenance exposure. The dependency count is a moderate consideration, but it is not independently severe for a full-stack framework.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing scanning automation is a genuine hygiene gap, though it does not outweigh the repository's strong activity and build evidence.

Security policycaution

No repository security policy was found. This reduces vulnerability-reporting transparency and is a maintenance hygiene gap, although the active repository and organization backing provide some compensation.

Token permissionscaution

Thirteen of 15 workflows lack top-level permission declarations, two workflows grant top-level write permissions, and no workflows declare read-only permissions. Broad or implicit token permissions increase CI supply-chain exposure and warrant tightening.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0.0
—
—
psr/cache
Version ^3.0
—
—
psr/clock
Version ^1.0.0
—
—
filp/whoops
Version ^2.15
—
—
symfony/uid
Version ^7.1|^8.0
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform