The SDK is clearly documented, licensed, tied to an organization-owned repository, and has no install-time scripts. Its security process is thin, with no security policy or scanning tools, while its newly published history provides little evidence of sustained maintenance.
72%
Total Score
75
100
86
75
This is the package's only release and it is newly published, so there is no established release cadence or track record yet. The recent repository publication provides some context but does not replace longer-term evidence.
There were no commits or active maintainers in the preceding three months, which would normally weaken maintenance evidence. Because the package and repository are newly published, this is better treated as limited history than as demonstrated abandonment.
Composer is used for the build, but no security-scanning tools are configured. That leaves a meaningful security-process gap even though the package has a straightforward build setup.
The repository has no security policy, so the process for reporting and handling vulnerabilities is unclear. This is a maintenance and transparency concern, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alibabacloud/darabonba Version ^1.0.0 | — | — |
alibabacloud/openapi-core Version ^1.0.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.