Documentation is present and the repository is backed by an organization, while no security scanning or security policy is provided. Pin this version only where its older API and limited maintenance are acceptable.
58%
Total Score
75
100
81
50
This package has only one release, published about five years ago, with no releases in the last 12 months. That makes ongoing compatibility fixes and maintenance uncertain.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a long period of inactivity. The organization-backed repository provides context but does not show current maintenance.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning coverage modestly reduces release assurance.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a hygiene and maintenance concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alibabacloud/tea-utils Version ^0.2.0 | — | — |
alibabacloud/endpoint-util Version ^0.1.0 | — | — |
alibabacloud/darabonba-openapi Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.