Documentation, tests, and release notes give consumers useful guidance, while the MIT licensing and matching source repository improve transparency. Unpinned workflow actions and absent security scanning add smaller maintenance and build-hygiene concerns.
15%
Total Score
25
57
100
Packagist marks the entire package as abandoned, with no replacement named. Package-level abandonment is a severe dependency-health warning.
The package has 43 releases over roughly nine years, but none in the last 12 months. The historically regular median interval does not compensate for the current release halt.
There were no commits and no active maintainers in the last three months. This confirms the current lack of maintenance rather than merely showing a temporary slow release cadence.
The linked repository is archived, which strongly indicates the project is no longer accepting normal maintenance. Its last push was on February 7, 2025, so the archive status outweighs the repository's popularity.
The repository has 329 open issues and 128 open pull requests, with no new or closed issues or merged pull requests in the last month. The backlog and absent recent handling reinforce the abandonment concern.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-32931 tcg/voyager is vulnerable to Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in versions 1.4.0 - 1.8.0. | 1.4.0 - 1.8.0 | Critical |
CVE-2024-55415 tcg/voyager is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 1.8.0. | 0.0.0 - 1.8.0 | High |
CVE-2024-55416 tcg/voyager is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.8.0. | 0.0.0 - 1.8.0 | Low |
CVE-2024-55417 tcg/voyager is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 1.8.0. | 0.0.0 - 1.8.0 | Medium |
CVE-2020-36070 tcg/voyager is vulnerable to Improper Preservation of Permissions in versions 0.0.0 - 1.4.0. | 0.0.0 - 1.4.0 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
laravel/ui Version >=1.0 | — | — |
league/flysystem Version ~1.1|~2.0|~3.0 | — | — |
illuminate/support Version 11.* | — | — |
intervention/image Version ^2.7 | — | — |
arrilot/laravel-widgets Version ^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.