Usable with caveats: the release is current, stable, licensed, and backed by an unarchived repository, but maintenance rests on one contributor with only one commit in the last three months. The repository also has no tests, changelog, security policy, or security scanning.
62%
Total Score
50
86
50
The package runs a post-autoload-dump install-time script. This is a meaningful operational consideration because dependency installation triggers package code, even though the signal does not show that the script is malicious or unsafe.
A substantial README is present, but neither the package nor repository contains tests or a changelog. For a Laravel documentation generator, the absence of both reduces maintenance transparency and makes regressions harder to assess.
All recent repository commits came from one contributor, so maintenance depends entirely on that person and has a high single-contributor risk.
Only 1 commit was recorded in the last 3 months, with 1 active maintainer, indicating limited recent maintenance capacity despite the current release.
Composer is used for builds, but no security scanning tools are present. This leaves dependency and repository security hygiene less independently checked.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^4.18 || ^5.0 | — | — |
laravel/framework Version >=10.0 | — | — |
swagger-api/swagger-ui Version ^3.0 || >=4.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.