The source project is licensed, documented, security-conscious, and still receives occasional maintenance. Its workflows use unpinned actions, adding avoidable build-integrity risk.
38%
Total Score
83
75
100
Packagist marks the entire package abandoned and provides google/apiclient as the replacement. This is a direct adoption warning for this release, despite the linked project remaining active.
The package has 57 releases over more than 12 years, but its latest registry release was in December 2021 and it had no releases in the last 12 months. That suggests the published package line is stale.
The repository recorded one commit in the last three months, showing some ongoing activity but a very low maintenance cadence for a dependency.
The linked repository name does not match the package name and its README does not mention this package. Although the repository is backed by the googleapis organization, the package-to-repository relationship is not transparent.
All three workflows were analyzed with no high-confidence audit findings or untrusted checkouts, but all 15 action references are unpinned and two workflows grant top-level write permissions. The unpinned actions are a hygiene concern; the write permissions are only a mild caution without an untrusted trigger or sink.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/auth Version ^1.10 | — | — |
guzzlehttp/psr7 Version ^1.7||^2.0.0 | — | — |
monolog/monolog Version ^1.17||^2.0 | — | — |
firebase/php-jwt Version ~2.0||~3.0||~4.0||~5.0 | — | — |
guzzlehttp/guzzle Version ~5.3.3||~6.0||~7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.