Package Health

tempest/http-client

This is a healthy, actively maintained release with strong recent publishing activity, a stable non-prerelease version, an unarchived organization-backed repository, and 47 commits from two active maintainers in the last three months. The main concerns are highly concentrated commit ownership, limited repository popularity, absent security scanning and security policy, and the repository not clearly mentioning the package name; however, these are moderated by the organization backing, recent releases, repository tests, a valid MIT license, and the absence of install-time scripts or dangerous workflows. It appears reasonable to depend on, while recognizing some maintainer-concentration and transparency risk.

Latest v3.19.2PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo bus factorcaution

Two contributors are active, but one contributor made about 95.7% of the 47 recent commits, creating a genuine concentration and continuity risk. Organization backing partly mitigates the risk because maintenance can potentially be handed off.

Repo issue activitycaution

No new or closed issues were recorded in the last month and there are no open pull requests, but the open issue count is unknown; this provides little actionable maintenance evidence rather than a negative conclusion.

Repo package mentioncaution

The repository name does not match the package name, and the README mention status is unknown, so the package-to-repository relationship is not fully transparent. The mismatch alone is not decisive because this may be a subpackage or component repository.

Repo popularitycaution

The repository has zero stars and forks and only one watcher, indicating limited visible adoption; this is supporting caution rather than a decisive health problem because recent release and commit activity is strong.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are reported, leaving a security-hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
tempest/http
Version 3.19.2
—
—
psr/http-client
Version ^1.0.0
—
—
psr/http-message
Version ^1.0|^2.0
—
—
tempest/container
Version 3.19.2
—
—
psr-discovery/http-client-implementations
Version ^1.4
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform