Package Health

bamagid/laraswagger

Usable with caveats: the release is current, stable, licensed, and backed by an unarchived repository, but maintenance rests on one contributor with only one commit in the last three months. The repository also has no tests, changelog, security policy, or security scanning.

Latest v2.0.2PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script. This is a meaningful operational consideration because dependency installation triggers package code, even though the signal does not show that the script is malicious or unsafe.

Package scaffoldingcaution

A substantial README is present, but neither the package nor repository contains tests or a changelog. For a Laravel documentation generator, the absence of both reduces maintenance transparency and makes regressions harder to assess.

Repo bus factorcaution

All recent repository commits came from one contributor, so maintenance depends entirely on that person and has a high single-contributor risk.

Repo commit activitycaution

Only 1 commit was recorded in the last 3 months, with 1 active maintainer, indicating limited recent maintenance capacity despite the current release.

Repo toolingcaution

Composer is used for builds, but no security scanning tools are present. This leaves dependency and repository security hygiene less independently checked.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Magid Ba

Direct Dependencies

DependencyLast ReleaseScore
nikic/php-parser
Version ^4.18 || ^5.0
laravel/framework
Version >=10.0
swagger-api/swagger-ui
Version ^3.0 || >=4.1.3

Weekly Downloads

Info

Last Published
11 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform