The Apache-2.0 license, release notes, changelog, and organization-backed repository provide useful transparency. There is no repository security policy, so vulnerability-reporting guidance is limited.
66%
Total Score
75
100
88
75
The package has 8 releases over 1,130 days, with a median interval of about 68 days, but no releases in the last 12 months. This indicates a meaningful maintenance slowdown for a package whose latest release is still stable.
There were zero commits and zero active maintainers in the last 3 months. Combined with no releases in the last 12 months, this is the clearest evidence of slowed maintenance.
The repository uses Composer build tooling, but no security scanning tool was detected. The build setup is appropriate, while the missing scanning is a modest hygiene gap.
No repository security policy was found. This leaves reporting and response expectations unclear, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alibabacloud/darabonba Version ^1.0.0 | — | — |
alibabacloud/openapi-core Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.