Risky to adopt for a new project: the package has had only one release, published about seven years ago, with no subsequent repository updates. It is licensed, documented, and not deprecated, but the long inactivity and minimal adoption evidence make abandonment a significant concern.
42%
Total Score
100
71
75
The package has only one release, with no releases in roughly seven years; this is strong evidence that maintenance has stopped, despite the package not being deprecated.
The repository has zero stars and forks and only one watcher, offering little supporting evidence of sustained community use. Popularity is not decisive by itself, but it provides no compensation for the inactivity.
The repository is not formally archived, but its last push was about seven years ago, reinforcing the release history's abandonment concern.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; this is a transparency gap for a package handling Google API credentials.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.