The package is small and clearly licensed, with a focused dependency set and organization backing. Documentation and security process are thin, so pin this exact version until a track record emerges.
59%
Total Score
75
100
75
75
The package has no README, which is a real integration gap for a library, although missing tests and changelog files are normal for published artifacts and do not count against it.
This is the first published release, released today, so there is no registry track record or established cadence to assess.
The repository has zero commits and zero active maintainers in the past three months, limiting evidence of ongoing maintenance; its same-day push partly explains this snapshot.
Composer is used for the build, but no security scanning tooling was detected, leaving a modest process gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
voyager/contracts Version ^0.8.0 | — | — |
voyager/nuts-and-bolts Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.