Package Health

tempest/mapper

This release appears healthy and actively maintained: it has 103 releases over roughly 2 years, 80 releases in the last 12 months, a stable non-prerelease version, a current non-archived repository, and 47 commits from three active maintainers in the last 3 months. The main concerns are highly concentrated commit activity, with one contributor responsible for about 96% of recent commits, limited repository security hygiene, and the absence of a README and changelog in the package artifact; however, organization backing, repository tests, licensing, and strong release cadence provide meaningful compensation. The package is reasonable to depend on, with normal caution around maintainer concentration and security-process transparency.

Latest v3.19.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

The artifact lacks a README, tests, and changelog, while the repository does contain tests; the missing artifact documentation is a transparency gap, but the repository test coverage compensates for the missing packaged tests.

Repo bus factorcaution

One contributor made about 96% of the 47 recent commits, creating a meaningful concentration risk; the organization-owned repository and two additional active contributors partially compensate, so this is caution rather than a severe abandonment finding.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, and open issue count is unknown; this provides little evidence of community support, although it does not contradict the strong commit and release activity.

Repo popularitycaution

The repository has no stars or forks and only one watcher, indicating limited independent popularity; popularity is supporting evidence rather than a decisive health criterion, especially given the active release and commit signals.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a security-process hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
tempest/support
Version 3.19.2
—
—
tempest/container
Version 3.19.2
—
—
tempest/reflection
Version 3.19.2
—
—
tempest/validation
Version 3.19.2
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform