The MIT license and organization-owned repository provide clear legal and ownership context. Recent activity is concentrated in one contributor, while the missing README and security policy reduce maintenance and integration confidence.
58%
Total Score
75
79
75
The package has no README, which is a minor integration and transparency gap for a library. Missing tests and a changelog in the published artifact are normal packaging practice and do not add concern here.
The package is newly published, with only two releases arriving within minutes and no established release history. That makes its maintenance maturity difficult to assess.
All six commits in the last three months came from one contributor, creating a thin operational base. Organization ownership offers some handoff capacity, but no second active contributor is shown.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap rather than evidence of unsafe code.
Version v0.8.0 is not a stable major release, indicating an API that may still change substantially. It is not marked as a prerelease, which provides a small counterpoint but does not remove the maturity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gpio/contracts Version ^0.8.0 | — | — |
venusian-voyager/contracts Version ^0.8.0 | — | — |
venusian-voyager/collections Version ^0.8.0 | — | — |
venusian-voyager/magic-aliases Version ^0.8.0 | — | — |
venusian-voyager/nuts-and-bolts Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.