Healthy and suitable to depend on. It has frequent releases, active recent commits, stable versioning, clear licensing, and organization backing; the main caveats are one active contributor and no security scanning or security policy.
82%
Total Score
90
100
83
90
A README is included, while tests and a changelog are absent in both the artifact and repository. For this generated SDK, the documentation gap is notable, but the lack of packaged tests is less concerning than it would be for application logic.
One contributor made all 36 commits in the last 3 months, creating concentration risk. The organization-owned repository partly compensates because maintenance can be handed off within the organization.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity alone does not outweigh the package's strong release and commit activity.
Composer is used as a build tool, but no security scanning tools are configured. The build setup is appropriate, while the missing scanning is a modest transparency and maintenance gap.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, though it is not evidence that the package is unsafe or abandoned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tencentcloud/common Version >=3.0.1669 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.