The package is licensed, documented, and has a focused dependency set. It lacks a security policy and automated security scanning, while its repository has seen no recent development, limiting confidence in continued maintenance.
64%
Total Score
75
100
88
75
Only two releases were published, both within about 20 hours, and no later release activity is shown despite the package being about 10 months old. This leaves its maintenance cadence uncertain.
There were zero commits and zero active maintainers in the last three months, and the repository was last pushed around 10 months ago. This is a meaningful maintenance and abandonment concern.
Composer build tooling is present, but no security-scanning tools were detected. That weakens automated oversight without making the package unfit by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for an SDK that handles cloud-service integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alibabacloud/darabonba Version ^1.0.0 | — | — |
alibabacloud/openapi-core Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.