The proprietary license may restrict use in projects that require open licensing. Tests, frequent releases, recent commits, and organization backing support continued maintenance, but the workflow needs tighter permissions and pinned actions.
68%
Total Score
83
88
50
The package declares a proprietary license and provides no license file, which can restrict adoption and redistribution. This is a real legal transparency concern, but not evidence of abandonment.
One contributor made 17 of 18 recent commits, creating concentration risk. The organization-owned project provides some handoff capacity, so this is a caution rather than a severe abandonment signal.
The project uses Composer build tooling, which fits the package ecosystem, but no security scanning tooling was detected. This is a modest process gap rather than evidence of unsafe code.
No repository security policy was found, reducing transparency for vulnerability reporting. The gap matters, but it is partially offset by recent maintenance and active project backing.
The only workflow combines pull_request_target, an untrusted checkout, top-level write permissions, and two unpinned actions. The audit found no classified findings, but this combination creates a meaningful supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
capell-app/core Version ^1.0 | — | — |
capell-app/admin Version ^1.0 | — | — |
filament/filament Version ~5.7.6 | — | — |
laravel/framework Version ^12.61.1|^13.12.0 | — | — |
livewire/livewire Version ^3.0|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.