The published artifact is well documented, tested, licensed, and has no install-time scripts. Those strengths do not offset the weak evidence of ongoing ownership and maintenance.
44%
Total Score
33
50
72
75
The latest release was published on May 16, 2023, and there have been no releases in the last 12 months despite the package being about 3 years and 7 months old. The nine releases appear concentrated in a short initial burst, which provides little evidence of continued maintenance.
There were zero commits and zero active maintainers in the last three months. Combined with the old last push and release gap, this is strong evidence that active maintenance has stopped.
Seven runtime dependencies, including HTTP, logging, and another SDK package, create a moderate dependency surface for a cloud SDK. The profile is not unusually large, but it adds maintenance exposure to an already inactive project.
Only one registry account has publish access. Because the repository is also owned by an individual rather than an organization, there is little visible publishing redundancy if that person stops maintaining the package.
The registry namespace is Inspur, but the linked repository is owned by the individual account dangcingzzw rather than an organization. That provides limited visible institutional backing for continued maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version >=1.4.2 | — | — |
monolog/monolog Version >=1.23.0 | — | — |
psr/http-message Version >=1.0.1 | — | — |
guzzlehttp/guzzle Version >=6.3.0 | — | — |
guzzlehttp/promises Version >=1.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.