Package Health

byrcsc/laravel-mentions

Usable with caveats: the release is well documented, tested in its repository, licensed, and actively maintained, but it is only 37 days old with one release and all recent commits from one contributor. Review its GitHub Actions permissions before adopting it in a sensitive build environment.

Latest v1.0.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

One of three workflows uses pull_request_target, which can expose elevated workflow context when handling pull requests. No untrusted checkout or script injection was detected, limiting the demonstrated risk.

Lifecycle scriptscaution

A post-autoload-dump install script is present. This is a real supply-chain surface, though the signal does not show a broader or unusually invasive set of lifecycle scripts.

Maintainerscaution

Only one registry account has publishing access. The repository is organization-owned, which provides some continuity beyond the registry account, but the publishing base remains narrow.

Release historycaution

This is a young package, only 37 days old, with a single release and no established release interval, so long-term maintenance reliability is not yet demonstrated.

Repo bus factorcaution

One contributor made all 11 commits in the last three months, creating a concentrated maintenance dependency; organization backing reduces but does not remove this risk because no second active contributor is shown.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ryan Catapang

Direct Dependencies

DependencyLast ReleaseScore
illuminate/events
Version ^12.0||^13.0
—
—
illuminate/support
Version ^12.0||^13.0
—
—
illuminate/database
Version ^12.0||^13.0
—
—
illuminate/contracts
Version ^12.0||^13.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform