Package Health

alibabacloud/aicontent-20240611

This is a healthy, actively maintained release with strong evidence of ongoing stewardship: 31 releases over roughly 763 days, 21 releases in the last 12 months, a stable non-prerelease version, a current non-archived repository, and an organization-owned source project. The package is licensed, has a substantial generated source tree and changelog, uses only three runtime dependencies, and has no install-time lifecycle scripts. The main concerns are that all seven recent commits came from one contributor, the repository has no tests or security scanning, and there is no security policy; low popularity is also a limited supporting concern. These are meaningful transparency and resilience gaps, but they do not outweigh the strong release cadence and active organizational backing.

Latest 6.11.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

A README and changelog are present and the repository uses GitHub Releases, which supports transparency; however, neither the artifact nor repository contains tests. For this generated SDK, the missing tests are a modest hygiene gap rather than a severe health risk.

Repo bus factorcaution

One contributor made all seven commits in the last three months, creating a real continuity risk. Organization ownership provides some mitigation, but no second active contributor is shown.

Repo popularitycaution

The repository has zero stars and forks and only three watchers. This is weak supporting evidence, but popularity alone does not establish abandonment, especially given the active release and commit history.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are present. The missing scanning reduces security-process transparency, although it does not directly demonstrate poor package maintenance.

Security policycaution

No security policy was found, leaving vulnerability-reporting and response expectations undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alibaba Cloud SDK

Direct Dependencies

DependencyLast ReleaseScore
alibabacloud/darabonba
Version ^1.0.0
alibabacloud/openapi-core
Version ^1.0.10

Weekly Downloads

Info

Last Published
20 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform