Package Health

tempest/icon

This release appears usable but has some meaningful transparency and continuity concerns. It has a strong recent release cadence, a stable non-prerelease version, no registry deprecation, active repository commits, an organization-owned project, a clear MIT license, and no install-time scripts or dangerous workflows. However, the artifact contains no README or tests, the repository has very low popularity, commit activity is highly concentrated in one of two contributors, no security policy is present, and the linked repository does not clearly match or mention the package. These issues do not indicate abandonment, but they warrant caution before adopting it as a critical dependency.

Latest v3.19.2PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Package scaffoldingcaution

The artifact lacks a README, tests, and changelog, which reduces release transparency, but repository tests are present and compensate for the missing packaged tests.

Repo bus factorcaution

One contributor made 46 of 47 recent commits, creating a significant concentration risk. The second active contributor and organization ownership partially compensate, but maintenance remains highly dependent on one person.

Repo package mentioncaution

The repository name does not match the package name and the README mention is unknown, so the linkage between this registry package and its source repository is not clearly established.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 0 watchers. Low popularity is supporting caution rather than a verdict, since active maintenance is shown elsewhere.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured, leaving a security-process gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/cache
Version ^7.3|^8.0
—
—
tempest/support
Version 3.19.2
—
—
tempest/container
Version 3.19.2
—
—
tempest/http-client
Version 3.19.2
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform