Recent releases, active repository work, clear documentation, and release notes support ongoing maintenance. The organization-backed project reduces handoff risk, but the licensing and repository security gaps merit care before adoption.
57%
Total Score
75
86
75
The only workflow uses pull_request_target with an untrusted checkout and top-level write permissions; although no audit findings were reported, that combination increases the impact of compromised or malicious pull requests.
The package declares a proprietary license and has no license file, which conflicts with open-source dependency expectations and may restrict downstream use.
All 17 commits in the last 3 months came from one contributor, creating concentrated maintenance risk. Organization ownership provides some ability to hand off work, but no second active contributor is shown.
Composer build tooling is present, but no security scanning tools are reported, leaving a modest transparency and maintenance gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a package that handles AI execution and provider integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
capell-app/core Version ^1.0 | — | — |
prism-php/prism Version ^0.100 | — | — |
capell-app/admin Version ^1.0 | — | — |
spatie/laravel-data Version ^4.5 | — | — |
lorisleiva/laravel-actions Version ^2.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.