The codebase is small and easy to inspect, with a clear MIT license and no install-time scripts. Its security documentation and independent maintenance coverage are limited, so pin v0.8.0 and watch future releases.
58%
Total Score
83
63
75
The artifact has no README, while the repository also reports no tests or changelog. The small nine-file library is inspectable, but the missing consumer documentation reduces transparency.
The package is brand new, with only two releases recorded on the same day and no demonstrated release cadence. That leaves maturity and long-term maintenance largely unproven.
All four recent commits came from one contributor, leaving maintenance highly concentrated. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities. For a package intended to integrate with hardware interfaces, this is a meaningful transparency gap.
v0.8.0 is not a stable-major release, so its API and behavior may still change substantially. It is not marked as a prerelease, which provides a small compensating signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gpio/contracts Version ^0.8.0 | — | — |
venusian-voyager/contracts Version ^0.8.0 | — | — |
venusian-voyager/collections Version ^0.8.0 | — | — |
venusian-voyager/magic-aliases Version ^0.8.0 | — | — |
venusian-voyager/nuts-and-bolts Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.