It has a clear README, explicit GPL licensing, and a small, consistent Composer package with no install-time scripts. The single-maintainer project has little activity or release history, so pinning this release creates meaningful abandonment risk.
38%
Total Score
25
79
100
The package has only one release, published about 8 years ago, with no releases in the last 12 months. That is strong evidence of an unmaintained dependency.
The repository recorded no commits and no active maintainers in the last 3 months, while its last push was about 5 years ago. This materially increases abandonment risk.
One registry maintainer leaves little demonstrated publishing capacity, although the linked repository is owned by the same individual and matches the package.
The assessed version is still a prerelease, and all recent releases are prereleases. Combined with the package's single-release history, this suggests it never reached a mature stable release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.