The matching organization repository, MIT license, and lack of install-time scripts provide useful baseline transparency. The release is brand new, with no observed commit or issue activity, and the repository has no security policy or consumer README.
62%
Total Score
67
100
71
83
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README is a minor consumer-facing transparency gap for a library.
This is the package's first release, published 0 days ago, so there is no release track record or established maintenance cadence yet.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Because the package is 0 days old, this indicates no demonstrated maintenance history yet rather than proven abandonment.
There are no issues or pull requests and no activity in the last month. With a repository created or populated only on the assessment date, this is limited evidence of maturity rather than a severe concern.
Composer build tooling is present, but no security scanning tools were detected. The build setup is appropriate, while security-process transparency is limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
venusian-voyager/contracts Version ^0.8.0 | — | — |
venusian-voyager/macroable Version ^0.8.0 | — | — |
venusian-voyager/collections Version ^0.8.0 | — | — |
venusian-voyager/nuts-and-bolts Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.