Structured documentation tooling for Laravel projects
60%
Total Score
caution
Usable with caveats: maintenance is still thin and CI workflow hygiene needs attention.
All 14 analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. Three workflows also grant top-level write access, increasing CI hygiene and supply-chain risk.
A post-autoload-dump script runs during installation, adding execution at install time; this is a manageable caution for a Composer package rather than a severe concern.
The package is 129 days old with three releases, including one released recently; this shows early activity but not yet a mature history.
There were no commits and no active maintainers in the last three months, which is a meaningful maintenance concern despite the recent release.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external maturity signal for this young package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.