The Apache-2.0 license, clear README, and matching repository make its purpose and licensing easy to verify. It is a small organization-backed metapackage, but the missing security policy leaves limited process evidence.
70%
Total Score
75
100
86
83
The package is 0 days old with only 1 release, so there is no track record for release consistency or maintenance. Its purpose as a generated type-definition metapackage limits how concerning the short history is, but maturity remains unproven.
No commits or active maintainers were recorded in the last 3 months, but the repository was created or updated immediately before this assessment and the package is newly published. This does not establish abandonment, though it provides little maintenance history.
The repository uses Composer, matching the package ecosystem. No security scanning tool was detected, which is a modest process gap for a small generated package.
No security policy was found in the repository. This limits vulnerability-reporting transparency, although the package is a small generated metapackage with no reported security workflow concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-adexchangebuyer-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.