Package Health

alibabacloud/ossagent-20260622

This is a young but currently active and coherently published package: it has four releases over 37 days, a stable non-prerelease version, an unarchived repository pushed recently, matching repository/package identity, an organization-owned project, an Apache-2.0 license, and no install-time lifecycle scripts. The main concerns are the absence of tests, security scanning, and a security policy, along with all recent commits coming from one contributor; however, the organization backing and ongoing release activity reduce the abandonment risk. It appears reasonable to depend on, with normal caution due to its short history and limited independent maintenance evidence.

Latest 1.1.1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry publishing account is listed, which is a limited registry-maintenance signal. Because the source project is organization-owned, this is less concerning than a one-person project.

Package scaffoldingcaution

A README and changelog are present and the repository has GitHub Releases, but neither the artifact nor repository contains tests. The missing tests are a genuine quality-evidence gap for an SDK, though the release documentation partially compensates for broader project hygiene.

Repo commit activitycaution

The repository recorded three commits in the last three months, all within a very recent development window, indicating some activity but limited maintenance history.

Repo issue activitycaution

There were no new or closed issues and no pull requests in the last month, so there is little evidence of community support or review activity. This is a modest transparency concern, but the package is very new and recent releases show active publishing.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are configured. The build setup is present, while the missing security automation is a hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alibaba Cloud SDK

Direct Dependencies

DependencyLast ReleaseScore
alibabacloud/darabonba
Version ^1.0.0
alibabacloud/openapi-core
Version ^1.0.10

Weekly Downloads

Info

Last Published
15 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform