The package is licensed, documented, and has a simple runtime dependency. Its repository is active in ownership and matches the package, but it lacks security scanning and shows no recent commit activity.
65%
Total Score
75
100
86
75
The package has a substantial history with 1,062 releases and a median interval of about 1 day, but it has had no releases in the last 12 months and its latest release was roughly 14 months ago. This is a meaningful maintenance concern despite the strong historical cadence.
The repository recorded zero commits and zero active maintainers during the last 3 months, consistent with the absence of releases over the last year. This raises current maintenance and abandonment risk.
The repository uses Composer for builds, but no security-scanning tools were detected. The missing scanning is a modest transparency and hygiene gap rather than evidence of unsafe code.
The repository has no security policy. For an SDK that handles cloud API credentials, this leaves vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tencentcloud/common Version 3.0.1414 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.