The package is clearly licensed, documented, and has a stable major release. Its only notable weaknesses are two recent commits from one contributor and no published security policy.
84%
Total Score
88
100
94
83
All two recent commits came from one contributor. This is a concentration risk, although the organization-owned repository provides some capacity for handoff.
Composer build tooling is present, but no security scanning tools were detected. That is a maintenance and transparency gap, not evidence that the package is unsafe.
No repository security policy was found, leaving vulnerability-reporting expectations unclear. The active release cadence partly offsets this documentation gap but does not remove it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alibabacloud/darabonba Version ^1.0.0 | — | — |
alibabacloud/openapi-core Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.