The project is organized and actively publishing, with clear documentation and an organization behind it. Its single-contributor history and risky workflow permissions make long-term maintenance and release safety less reassuring.
58%
Total Score
80
100
88
63
The only workflow combines a pull_request_target trigger and an untrusted checkout with top-level write permissions; all 2 action references are also unpinned. Although no injection finding was reported, untrusted code can reach a broadly permitted token, making this a serious release-workflow risk.
The package is only 6 days old, despite 39 releases, so it has little demonstrated longevity. The rapid release cadence shows active publishing but does not yet establish maturity.
One contributor made all recent commits, creating a concentrated bus factor. Organization backing partly offsets handoff risk but no second active contributor is evidenced.
Only 3 commits from 1 active maintainer were recorded in the last 3 months. The organization owner provides some continuity, but no broader recent contributor activity is shown.
Composer build tooling is present, but no security scanning tools were detected. This is a modest assurance gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
capell-app/core Version ^1.0 | — | — |
capell-app/frontend Version ^1.0 | — | — |
capell-app/theme-foundation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.