The repository is clearly tied to the package and backed by an organization, with licensing, release notes, and a stable version. Recent maintenance has slowed substantially, and the repository has no security scanning or published security policy.
67%
Total Score
83
100
83
75
The package has 8 releases over 848 days, but none in the last 12 months; the latest release was about 13 months ago. This is meaningful maintenance concern despite the earlier release history.
There were no commits and no active maintainers in the last 3 months. Combined with no releases in the last year, this indicates substantially reduced recent maintenance.
The repository has no stars or forks and only 3 watchers, so independent adoption evidence is limited. This is supporting context rather than a decisive health problem for an organization-backed SDK.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance-hygiene gap, not a standalone severe risk.
The repository has no published security policy. That weakens vulnerability-reporting transparency, although organizational backing and an identifiable source repository partly compensate.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alibabacloud/darabonba Version ^1.0.0 | — | — |
alibabacloud/openapi-core Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.