Frequent releases, current documentation, and repository tests show a maintained package. Dependence on one active contributor and a broadly permissioned workflow add meaningful continuity and supply-chain concerns.
68%
Total Score
90
100
94
75
The sole workflow combines pull_request_target, an untrusted checkout, top-level write permissions, and two unpinned actions. The audit found no injected scripts or other findings, but this combination is a serious workflow risk.
All 17 recent commits came from one contributor, creating a meaningful continuity risk despite the active repository.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, reducing clarity about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
capell-app/core Version ^1.0.21 | — | — |
capell-app/admin Version ^1.0 | — | — |
capell-app/frontend Version ^1.0 | — | — |
spatie/laravel-data Version ^4.5 | — | — |
lorisleiva/laravel-actions Version ^2.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.