Usable with caveats: the package is licensed, actively published, and not deprecated or archived, but it is young with only one recent commit from a single contributor and no tests or security policy. Depend on it only if you can accept limited maintenance depth.
62%
Total Score
50
100
83
75
The package defines a post-autoload-dump script, so installation performs an automated lifecycle action. This is a review point for dependency safety, though the signal alone does not establish poor maintenance.
A README and changelog are present, but neither the package artifact nor repository contains tests. For a documentation generator, this leaves behavior and regression coverage less transparent.
The package and repository are owned by the same individual account, confirming source alignment but providing no organizational maintenance depth or handoff capacity.
The package is only 168 days old with four releases and a median interval of about 48 days. That shows ongoing publishing but not yet a long maintenance record.
All recent commits came from one contributor, with a 100% commit share. Because the repository is user-owned rather than organization-backed, there is no provided project-backing evidence to offset this concentration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zircote/swagger-php Version 6.* | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.