The package includes tests, a README, release notes, and a clear MIT license, with five runtime dependencies. Its workflow configuration leaves all 12 action references unpinned and lacks a security policy, while recent commit activity is absent.
52%
Total Score
50
92
75
The package has 31 releases but none in the last 12 months, and its latest registry release was over two years ago. This indicates materially slowed maintenance for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months. Although it was pushed recently, the measured development activity remains absent.
The repository has no security policy. This reduces transparency for reporting vulnerabilities, though it is a documentation gap rather than evidence that the package is unsafe.
All 12 analyzed action references are unpinned, and the audit found a high-confidence, high-severity unpinned container image. There were no untrusted checkouts or script-injection findings, but release-build reproducibility is weakened.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tcg/voyager Version ^1.4|dev-1.6-l10 | — | — |
joy/voyager-core Version ^1.0|^2.0|^3.0 | — | — |
illuminate/support Version ^7|^8|^9|^10 | — | — |
joy/voyager-datatable Version ^1.0|^2.0|^3.0|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.