Apache-2.0 licensing, release notes, and regular recent releases support transparent packaging. Organization backing and a current repository reduce abandonment risk, though security controls are not documented.
82%
Total Score
83
100
89
88
All three recent commits came from one contributor, concentrating maintenance knowledge and creating a continuity risk despite the organization-owned repository.
The repository has no stars or forks and only three watchers; popularity is limited, but this is supporting evidence rather than a health verdict and is offset by active releases and organization backing.
Composer build tooling is present, but no security scanning tools were detected, leaving repository security checks less transparent.
The repository has no documented security policy, which weakens vulnerability-reporting transparency for an SDK that handles cloud service integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alibabacloud/darabonba Version ^1.0.0 | — | — |
alibabacloud/openapi-core Version ^1.0.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.