Package Health

capell-app/notes

Private, assignable notes and @mentions for any Capell admin record

Latest v1.1.0-beta.41PackagistPackagist

48%

Total Score

unhealthy

Risky: a two-day-old beta has one active contributor and a pull-request workflow with untrusted checkout and write access.

Health Score Breakdown

Workflow auditdanger

The sole workflow combines pull_request_target, an untrusted checkout, top-level write permissions, and two unpinned actions. Because these conditions occur in the same workflow, they create a material supply-chain exposure.

Release historycaution

The package is only 2 days old, despite 40 releases, so its long-term maintenance record is not yet established.

Repo bus factorcaution

One contributor made all recent commits, creating a concentrated maintenance path. Organization ownership offers some handoff capacity, but no second active contributor is shown.

Repo commit activitycaution

There was one commit in the last 3 months, showing recent activity but too little history to demonstrate sustained maintenance.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool was detected, leaving a modest repository-hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Capell Team

Direct Dependencies

DependencyLast ReleaseScore
capell-app/admin
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
3 days ago
Created
25 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform