The MIT license and Composer-based setup provide a clear legal and build foundation. Consumer documentation, repository tests, and a security policy are missing, leaving limited evidence for safe integration or ongoing quality.
44%
Total Score
75
64
83
This is the package's first release, published today, with only one release recorded. That leaves no history from which to judge maintenance consistency or release reliability.
The package and repository have no README or tests, and the repository has no changelog. Missing tests and changelog can be normal for a small published artifact, but the absent README makes this library harder to integrate safely.
The repository records zero commits and zero active maintainers over the last three months. The repository was only pushed today, which explains the result but still provides no demonstrated maintenance track record.
Composer is used as the build tool, which is appropriate, but no security-scanning tooling is present. That is a modest hygiene gap rather than evidence of an unsafe release by itself.
The repository has no security policy. For an encryption library, this is a meaningful transparency gap because it gives users no stated process for reporting or handling security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
venusian-voyager/contracts Version ^0.8.0 | — | — |
venusian-voyager/nuts-and-bolts Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.