The Apache-2.0 declaration, simple Composer build, and absent install scripts reduce avoidable dependency risk. Its small artifact and organization backing are reassuring, but limited history leaves long-term maintenance less established.
62%
Total Score
75
50
71
75
The package declares 11 runtime dependencies and no development dependencies. This is a meaningful dependency surface, though the dependencies are consistent with a generated SDK client.
The package is only 94 days old with two releases, so there is limited evidence of sustained maintenance, although the releases arrived about 10 days apart.
One contributor accounts for all two recent commits. Organization ownership offers some handoff capacity, but no second active contributor is shown.
Only two commits from one active maintainer were recorded in the last three months. Recent activity exists, but it provides limited evidence of sustained maintenance capacity.
The repository name does not match the package name, and no README mention was collected. The repository may still be a package-specific generated source, but its relationship to this package is not clearly demonstrated.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alibabacloud/tea-xml Version ^0.2 | — | — |
alibabacloud/tea-utils Version ^0.2.22 | — | — |
alibabacloud/credentials Version ^1.2.2 | — | — |
alibabacloud/gateway-spi Version ^1 | — | — |
alibabacloud/openapi-util Version ^0.1.10|^0.2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.