Apache-2.0 licensing, included tests, and no install-time scripts reduce adoption and execution concerns. Organization backing and a matching repository help, but the project has little operating history and lacks security-focused repository practices.
68%
Total Score
75
100
75
88
The package is brand new, with one release and no established release interval. This limits evidence of maintenance maturity, though the zero-day age means it is not evidence of abandonment yet.
There were no commits or active maintainers in the preceding three months, but the repository is only one day old. This leaves maintenance capacity unproven without showing a collapsed established project.
The repository has zero stars, forks, and watchers. Given that it was created on the release day, this is weak maturity evidence rather than a standalone abandonment signal.
Composer is used for the build, which is appropriate, but no security scanning tools were detected. The missing security tooling is a repository-hygiene concern, not evidence that the package is unsafe.
The repository has no security policy. For a newly published package this is a transparency gap, though the small package scope limits how strongly it affects dependency health.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.