Private, assignable notes and @mentions for any Capell admin record
48%
Total Score
unhealthy
Risky: a two-day-old beta has one active contributor and a pull-request workflow with untrusted checkout and write access.
The sole workflow combines pull_request_target, an untrusted checkout, top-level write permissions, and two unpinned actions. Because these conditions occur in the same workflow, they create a material supply-chain exposure.
The package is only 2 days old, despite 40 releases, so its long-term maintenance record is not yet established.
One contributor made all recent commits, creating a concentrated maintenance path. Organization ownership offers some handoff capacity, but no second active contributor is shown.
There was one commit in the last 3 months, showing recent activity but too little history to demonstrate sustained maintenance.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest repository-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
capell-app/admin Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.