This is a mature, actively maintained and transparently published package: it has existed for over 11 years, has 261 releases, a recent stable release, a non-archived repository, current commit activity from four contributors, tests, a changelog, licensing, build and security tooling, and no registry deprecation. The main concerns are that 22 of 26 recent commits came from one contributor and the repository lacks a security policy and explicit top-level workflow permissions, which create maintainability and CI-governance gaps but are partly mitigated by organization backing, ongoing activity, and workflows with no detected dangerous patterns. Overall, it appears suitable to depend on, subject to normal review of its substantial runtime dependency set.
88%
Total Score
88
50
100
80
The package declares 12 runtime dependencies and no development dependencies; this is a meaningful dependency surface to review, but the signal alone does not show instability or excessive risk.
One contributor made about 85% of the 26 recent commits, creating concentration risk; organization ownership and three additional active contributors partly mitigate, but do not eliminate, the concern.
The repository has no security policy, leaving vulnerability-reporting and disclosure expectations less transparent for dependents.
All 4 workflows lack top-level permissions declarations; although none declares top-level write access, explicitly restricting token permissions would provide stronger CI governance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
oat-sa/generis Version >=17.0.0 | — | — |
oat-sa/tao-core Version >=56.0.0 | — | — |
oat-sa/lib-tao-dtms Version ^1.0.1 | — | — |
sinergi/browser-detector Version ^6.0.2 | — | — |
oat-sa/extension-tao-test Version >=15.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.