PkgRadar

Composer · packagist.org

oat-sa/extension-tao-clientdiag

Known Indicator Filename: oat-sa-extension-tao-clientdiag-1b08d92/views/build/grunt/bundle.js

Why PkgRadar flagged v9.0.1

SeveritySignalEvidence
highKnown Indicator Filenameoat-sa-extension-tao-clientdiag-1b08d92/views/build/grunt/bundle.js · oat-sa-extension-tao-clientdiag-1b08d92/views/build/grunt/bundle.js
mediumPhp Shell Callexec / system / passthru / shell_exec / proc_open — process spawning. · oat-sa-extension-tao-clientdiag-1b08d92/model/storage/Sql.php
mediumPhp Shell Callexec / system / passthru / shell_exec / proc_open — process spawning. · oat-sa-extension-tao-clientdiag-1b08d92/scripts/install/createDiagnosticTable.php
mediumPhp Shell Callexec / system / passthru / shell_exec / proc_open — process spawning. · oat-sa-extension-tao-clientdiag-1b08d92/scripts/update/Updater.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v9.0.1Review272026-05-27

Block this in CI

PkgRadar gates oat-sa/extension-tao-clientdiag (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer oat-sa/[email protected]