tempest/http v3.19.2 appears healthy and suitable for dependency use: it has a stable release, 103 releases over roughly 2 years, 80 releases in the last 12 months, an active non-archived repository, and 62 commits from 8 active maintainers in the last 3 months. The main concerns are concentrated commit ownership, limited repository security hygiene, very low repository popularity, and incomplete package documentation; these lower confidence and keep the score below the top tier, but the organization-backed project and strong release cadence materially reduce abandonment risk.
82%
Total Score
88
50
83
88
The package has 11 runtime dependencies and no development dependencies declared. This is a meaningful dependency surface for a library, but the signal alone does not show excessive or clearly problematic dependencies.
The artifact has no README, tests, or changelog, and the repository also lacks a changelog; however, repository tests are present, compensating for the missing packaged tests. The absent README remains a modest documentation gap for a library.
Eight contributors were active in the last 3 months, but the top contributor made about 81% of commits. This concentration is a real continuity concern, partially mitigated by the organization-owned repository and the presence of several additional active contributors.
The repository has only 1 star, 0 forks, and 1 watcher. This is weak supporting evidence, but popularity is not decisive and is outweighed by the demonstrated release and commit activity.
Composer build tooling is present, but no security scanning tools were detected. The build setup is appropriate, while the missing security automation is a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^7.1|^8.0 | — | — |
tempest/core Version 3.19.2 | — | — |
tempest/clock Version 3.19.2 | — | — |
tempest/mapper Version 3.19.2 | — | — |
tempest/console Version 3.19.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.