It includes tests, a changelog, release notes, clear licensing, and security scanning. Workflow credentials are broader than needed in one release workflow and all seven actions are unpinned; the security policy is also missing.
78%
Total Score
100
100
100
75
No repository security policy was found. This is a transparency gap, though it is partly offset by the presence of Sonar scanning.
All four workflows were analyzed without untrusted checkouts or script injection, but all seven action references are unpinned and one release workflow inherits secrets, creating moderate workflow hygiene and credential-scope concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
oat-sa/generis Version >=17.0.0 | — | — |
oat-sa/tao-core Version >=56.0.0 | — | — |
oat-sa/extension-tao-item Version >=11.8.0 | — | — |
oat-sa/extension-tao-test Version >=15.0.0 | — | — |
oat-sa/extension-tao-itemqti Version >=28.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.