Its stable major version is not deprecated, and Composer provides a clear build path. The single maintainer and lack of security scanning leave limited evidence of ongoing project capacity.
43%
Total Score
50
67
75
The latest release was nearly three years ago, with no releases in the last 12 months. That is strong evidence of stalled maintenance for a package intended to remain a dependency.
Only one registry account has publish access, and project backing identifies an individual owner rather than an organization. This creates a thin maintainer base and increases continuity risk.
The package contains only seven files, including IDE metadata and one source file. This is not inherently unsafe, but the unusually sparse tree provides little evidence of documentation, tests, or project maturity.
The artifact has no tests or changelog, which is normal for published packages, and it has a GitHub release for this version. However, it also has no README, leaving consumers without in-package usage guidance.
The repository owner is an individual user, not an organization, and no broader project backing is shown. Combined with the single registry maintainer, this leaves limited continuity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/cloud Version ^0.165.0 | — | — |
google/cloud-translate Version ^1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.