The package is clearly licensed, matches its source repository, and has no install-time scripts. Its project history is too new to establish durable maintenance, and all recent commits come from one contributor.
56%
Total Score
67
75
75
The package contains no README, tests, or changelog, and the repository also reports no tests or changelog. The small library may not require a published changelog, but the missing consumer documentation and tests reduce transparency.
The package is brand new, with both releases published on the same day and no established release interval. That leaves long-term maintenance and stability unproven.
One contributor made all three recent commits, leaving maintenance dependent on a single active contributor. Organization ownership provides some backing, but no second active contributor is shown.
Three commits were recorded in the last three months, showing some current activity, but this is a small evidence base for a package released only today.
Composer is used as the build tool, but no security scanning tools are reported. For this small PHP package, the missing scanning tooling is a modest transparency gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gpio/contracts Version ^0.8.0 | — | — |
venusian-voyager/contracts Version ^0.8.0 | — | — |
venusian-voyager/collections Version ^0.8.0 | — | — |
venusian-voyager/magic-aliases Version ^0.8.0 | — | — |
venusian-voyager/nuts-and-bolts Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.