The organization-backed repository matches the package and the release is licensed, but the project shows little recent activity or security oversight. Its small, stable artifact is easy to inspect, yet ongoing support is uncertain.
45%
Total Score
50
75
75
The package has had no releases in the last 12 months, and its latest release was published nearly seven years ago. The high historical release count does not compensate for the prolonged release pause.
There were no commits and no active maintainers in the last three months, while the repository was last pushed in March 2021. The repository is not archived, but the long inactivity still raises abandonment risk.
The repository has zero stars and forks and only two watchers, providing little supporting evidence of broad community review or adoption. Popularity is only secondary evidence, so this is a modest concern.
Composer is used for builds, which fits the package, but no security-scanning tools were detected. This is a hygiene gap rather than evidence that the package is unsafe.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. The organization backing provides some context but does not replace a published process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alibabacloud/client Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.