This is a healthy, mature release with a long release history, regular recent publishing, stable versioning, an active non-archived source repository, organization backing, and strong package/repository alignment. The artifact is substantial, licensed, documented, and includes a changelog; its lack of packaged tests is compensated by repository tests. The main reservations are the absence of a repository security policy and security-scanning tooling, plus some concentration of recent commits in one contributor, although three active contributors and Google organization ownership reduce the abandonment risk.
88%
Total Score
100
100
94
88
Composer build tooling is present, but no security-scanning tools are detected; this is a transparency and assurance gap rather than evidence of abandonment.
No repository security policy was found, leaving vulnerability-reporting expectations and disclosure procedures less transparent.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10419 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. googleads/google-ads-php is vulnerable to Exposure of Sensitive Information in versions 6.1.0 - 28.0.0. | 6.1.0 - 28.0.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
grpc/grpc Version >=1.57.0 | — | — |
google/gax Version ^1.49.0 | — | — |
google/auth Version ^1.30 || ^2.0 | — | — |
google/protobuf Version ^3.21.5 || ^4.26.1 || ^5.34 | — | — |
monolog/monolog Version ^1.26 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.