The package is licensed, includes a changelog, and has substantial recent repository activity. Its short release history, absent security policy, and README/package identity mismatch leave maintenance and provenance less established.
62%
Total Score
67
100
86
83
The repository is owned by a user account rather than an organization, so there is no shown organizational backing to offset the concentrated contribution pattern.
The package is only 40 days old with two releases, so its long-term maintenance record is not established. Recent repository activity partly compensates for the limited release history.
Eleven contributors are active, but the top contributor accounts for about 69% of recent commits. That concentration creates some continuity risk for a user-owned project.
The repository name matches the package, but its README does not mention ycookies/apidoc and instead presents installation instructions for dedoc/scramble. That mismatch makes package provenance and consumer guidance less clear.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.0 | — | — |
myclabs/deep-copy Version ^1.12 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
phpstan/phpdoc-parser Version ^1.0|^2.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.