This is a healthy, actively maintained release with a long history, regular recent releases, stable versioning, a non-deprecated registry status, an unarchived matching repository, and current commit and pull-request activity. The organization-backed project has reproducible-looking Composer scaffolding, tests, CI, Sonar scanning, and no analyzed dangerous workflow patterns. The main reservations are a concentrated recent contributor share, the absence of a repository security policy, and workflows that do not declare top-level token permissions; these are meaningful hygiene concerns but do not outweigh the evidence of active maintenance and project backing.
88%
Total Score
90
100
100
80
Recent activity is concentrated in one contributor at 75% of commits, which is a caution for continuity, although two additional active contributors and organization backing reduce the practical bus-factor risk.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented; active tooling and maintenance help, but do not replace this transparency.
All 4 workflows lack top-level token permission declarations. Although none declares top-level write access, explicit least-privilege permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
oat-sa/generis Version >=16.0.0 | — | — |
oat-sa/tao-core Version >=54.26.0 | — | — |
oat-sa/extension-tao-testqti Version >=41.0.0 | — | — |
oat-sa/extension-tao-itemqti-pci Version >=7.0.0 | — | — |
oat-sa/extension-tao-mediamanager Version >=12.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.