This is a healthy, actively maintained release with strong recent publishing activity, a stable non-prerelease version, an unarchived organization-backed repository, and 47 commits from two active maintainers in the last three months. The main concerns are highly concentrated commit ownership, limited repository popularity, absent security scanning and security policy, and the repository not clearly mentioning the package name; however, these are moderated by the organization backing, recent releases, repository tests, a valid MIT license, and the absence of install-time scripts or dangerous workflows. It appears reasonable to depend on, while recognizing some maintainer-concentration and transparency risk.
84%
Total Score
75
100
83
90
Two contributors are active, but one contributor made about 95.7% of the 47 recent commits, creating a genuine concentration and continuity risk. Organization backing partly mitigates the risk because maintenance can potentially be handed off.
No new or closed issues were recorded in the last month and there are no open pull requests, but the open issue count is unknown; this provides little actionable maintenance evidence rather than a negative conclusion.
The repository name does not match the package name, and the README mention status is unknown, so the package-to-repository relationship is not fully transparent. The mismatch alone is not decisive because this may be a subpackage or component repository.
The repository has zero stars and forks and only one watcher, indicating limited visible adoption; this is supporting caution rather than a decisive health problem because recent release and commit activity is strong.
Composer build tooling is present, but no security scanning tools are reported, leaving a security-hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tempest/http Version 3.19.2 | — | — |
psr/http-client Version ^1.0.0 | — | — |
psr/http-message Version ^1.0|^2.0 | — | — |
tempest/container Version 3.19.2 | — | — |
psr-discovery/http-client-implementations Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.