云账户综合服务平台 API 调用封装
67%
Total Score
caution
Usable with caveats: no commits in the last three months and a license mismatch weaken confidence.
The artifact contains a license file, but it is detected as Apache-2.0 while the manifest declares MIT. That mismatch should be resolved before relying on the stated licensing terms.
The repository is owned by a user account rather than an organization. That does not establish poor health, but it provides less visible institutional backing for a payment-related library.
Seven releases since October 2020 and one release in the last 12 months show ongoing publication, but the median interval of about 227 days indicates a slow cadence.
There were zero commits and zero active maintainers in the last three months, which is a concrete sign of slowed maintenance for a package handling payment integrations.
Composer build tooling is present, but no security-scanning tools are configured. This is a modest transparency and maintenance gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.