The package includes practical documentation and release notes for consumers. Maintenance is concentrated in one contributor, while the sole workflow combines an untrusted checkout with broad, unpinned actions.
69%
Total Score
83
100
75
All 15 recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership provides some handoff capacity but does not remove the current concentration.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The only workflow uses a pull_request_target trigger with an untrusted checkout, grants top-level write permissions, and has both action references unpinned. The audit found no confirmed findings, but this combination creates workflow hygiene and exposure concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
capell-app/core Version ^1.0 | — | — |
capell-app/admin Version ^1.0 | — | — |
illuminate/support Version ^12.41.1|^13.0 | — | — |
illuminate/database Version ^11.0|^12.0|^13.0 | — | — |
lorisleiva/laravel-actions Version ^2.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.