Package Health

tempest/router

This release appears healthy and reasonably safe to depend on: it is actively maintained, with 59 commits from 7 maintainers in the last 3 months, 99 releases over 561 days, and 81 releases in the last 12 months. The package is stable, not deprecated, licensed under MIT with a license file, backed by an organization-owned repository, and has no install-time lifecycle scripts. The main concerns are concentration of activity in one contributor, absence of a security policy and security-scanning tooling, and limited artifact documentation; however, repository tests and strong recent maintenance partially compensate for those hygiene gaps.

Latest v3.19.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

The artifact lacks a README, tests, and changelog, which reduces release transparency, but repository tests are present and compensate for the most important testing gap.

Repo bus factorcaution

One contributor made about 81% of the 59 recent commits, creating concentration risk. The other six active contributors and organization ownership provide partial mitigation, but the concentration still warrants caution.

Repo popularitycaution

The repository has only 1 star and 0 forks, so external popularity is limited, but popularity is supporting evidence and does not outweigh the strong activity indicators.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools are reported; this is a transparency and security-hygiene gap rather than evidence of abandonment.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
tempest/http
Version 3.19.2
—
—
tempest/view
Version 3.19.2
—
—
tempest/highlight
Version ^2.11.4
—
—
symfony/var-exporter
Version ^7.1|^8.0
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform