Package Health

specdocular/laravel-openapi

Generate OpenAPI Specification for Laravel Applications

Latest v0.7.1PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Lifecycle scriptscaution

The package uses a post-autoload-dump install-time script. This is common in Composer packages but means installation performs package-defined automation that should be reviewed before use.

Repo bus factorcaution

All 12 recent commits came from one contributor, giving the project a fragile maintenance base. Organization ownership provides some handoff capacity, but no second active contributor is shown.

Repo popularitycaution

The repository has zero stars, forks, and watchers, so there is little evidence of external use or community validation. The package is relatively young, making this a supporting concern rather than a standalone adoption blocker.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The build setup is adequate, while the lack of automated security checks reduces transparency somewhat.

Token permissionscaution

One workflow declares read-only permissions and none declares top-level write access; the remaining workflow lacks top-level permissions, leaving a minor least-privilege gap but no observed write permission.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mohammad Alavi

Direct Dependencies

DependencyLast ReleaseScore
webmozart/assert
Version ^1.11
—
—
laravel/framework
Version ^10.0|^11.0|^12.0
—
—
specdocular/php-openapi
Version ^0.1.0
—
—
composer/class-map-generator
Version ^1.6
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform