The repository has 95 commits in three months, three active contributors, clear documentation, tests, and release notes. One contributor makes 79% of commits, and the sole workflow accepts untrusted pull-request code with broad write access and unpinned actions.
82%
Total Score
88
100
94
75
Three contributors are active, but one accounts for about 79% of recent commits, leaving maintenance somewhat concentrated despite organization backing.
Composer build tooling is present, but no security-scanning tool was detected; this is a modest transparency gap rather than evidence of abandonment.
The repository has no security policy, reducing guidance for vulnerability reporting and response.
The only workflow combines pull_request_target, an untrusted checkout, top-level write permissions, and two unpinned actions. The complete audit found no classified findings, but this combination creates avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
capell-app/core Version ^1.0 | — | — |
capell-app/frontend Version ^1.0 | — | — |
capell-app/layout-builder Version ^1.0 | — | — |
capell-app/theme-foundation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.