Package Health

oat-sa/lib-tao-elasticsearch

Tests, a changelog, a clear license, and automated security scanning improve transparency. Use extension-tao-advanced-search instead, as the release notes direct.

Latest v2.5.2PackagistPackagist

15%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Using this package? Scan for Free

Health Score Breakdown

Package scaffoldingdanger

The README explicitly says the library must not be used anymore, and the release notes direct users to extension-tao-advanced-search. Tests and a changelog are present, but they do not offset this release-specific abandonment warning.

Release historydanger

The package has had no releases in the last 12 months, despite 18 releases since 2018. This supports the explicit deprecation message and indicates no current release maintenance.

Repo commit activitycaution

Only 1 commit was recorded in the last 3 months, from 1 active maintainer. This is limited current activity for a package whose own documentation says it should no longer be used.

Security policycaution

The linked repository has no security policy. This is a transparency gap, although it is secondary to the release's explicit replacement guidance.

Workflow auditcaution

The single workflow was fully analyzed with no detected audit findings or dangerous triggers, but all 3 action references are unpinned. That leaves avoidable build-integrity exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Open Assessment Technologies S.A.
Aleksej Tikhanovich

Direct Dependencies

DependencyLast ReleaseScore
oat-sa/tao-core
Version >=50.5.0||dev-develop
—
—
elasticsearch/elasticsearch
Version ~7.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform