The organization-backed project has only one active contributor, and it has no security policy or scanning tools. Its focused artifact and single runtime dependency keep adoption relatively simple.
82%
Total Score
83
100
94
50
All 32 recent commits came from one contributor, giving the project a complete single-contributor concentration. Organization backing provides some handoff capacity, but the observed maintenance base is still thin.
Composer is used for builds, but no security scanning tools were detected. The missing scanning coverage is a modest transparency and maintenance-hygiene gap.
The repository has no security policy. For an SDK that handles cloud credentials and API access, the absence of documented vulnerability-reporting guidance is a real transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tencentcloud/common Version >=3.0.1670 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.