Generate OpenAPI Specification for Laravel Applications
70%
Total Score
83
81
75
The package uses a post-autoload-dump install-time script. This is common in Composer packages but means installation performs package-defined automation that should be reviewed before use.
All 12 recent commits came from one contributor, giving the project a fragile maintenance base. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has zero stars, forks, and watchers, so there is little evidence of external use or community validation. The package is relatively young, making this a supporting concern rather than a standalone adoption blocker.
Composer build tooling is present, but no security scanning tools were detected. The build setup is adequate, while the lack of automated security checks reduces transparency somewhat.
One workflow declares read-only permissions and none declares top-level write access; the remaining workflow lacks top-level permissions, leaving a minor least-privilege gap but no observed write permission.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.11 | — | — |
laravel/framework Version ^10.0|^11.0|^12.0 | — | — |
specdocular/php-openapi Version ^0.1.0 | — | — |
composer/class-map-generator Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.