The package is clearly licensed, tied to a matching repository, and backed by an organization with recent release notes and two active contributors. Its automation needs tightening before treating it as a low-maintenance dependency.
70%
Total Score
100
100
94
67
The package has existed since 2016 but has only 12 releases, with one release in the last 12 months and a median interval of about 261 days; this indicates a slow maintenance cadence.
The repository has no SECURITY.md policy, leaving vulnerability reporting and response expectations undocumented.
All six analyzed action references are unpinned, and the release workflow has a high-confidence medium-severity secrets-inherit finding. The audit found no untrusted checkout or script-injection path, so this is a hygiene and credential-scope concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
oat-sa/generis Version >=14.0.0 | — | — |
oat-sa/extension-tao-itemqti Version >=27.0.0 | — | — |
oat-sa/extension-tao-xmledit Version >=4.0.0 | — | — |
oat-sa/oatbox-extension-installer Version ~1.1||dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.