Package Health

capell-app/ai-orchestrator

Recent releases, active repository work, clear documentation, and release notes support ongoing maintenance. The organization-backed project reduces handoff risk, but the licensing and repository security gaps merit care before adoption.

Latest v1.0.37PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Workflow auditdanger

The only workflow uses pull_request_target with an untrusted checkout and top-level write permissions; although no audit findings were reported, that combination increases the impact of compromised or malicious pull requests.

Licensecaution

The package declares a proprietary license and has no license file, which conflicts with open-source dependency expectations and may restrict downstream use.

Repo bus factorcaution

All 17 commits in the last 3 months came from one contributor, creating concentrated maintenance risk. Organization ownership provides some ability to hand off work, but no second active contributor is shown.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are reported, leaving a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a package that handles AI execution and provider integrations.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Howdu

Direct Dependencies

DependencyLast ReleaseScore
capell-app/core
Version ^1.0
prism-php/prism
Version ^0.100
capell-app/admin
Version ^1.0
spatie/laravel-data
Version ^4.5
lorisleiva/laravel-actions
Version ^2.8

Weekly Downloads

Info

Last Published
24 years ago
Created
26 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform