The package has a clear Apache-2.0 license, tests, Composer build tooling, and organization ownership. Its small generated-package structure makes the missing README and security policy less significant, but adoption still carries limited history-based assurance.
58%
Total Score
75
100
81
83
This is the first recorded release, published 0 days ago, with only 1 release overall. That leaves no release cadence or track record to support confidence in ongoing maintenance.
The repository shows 0 commits and 0 active maintainers in the last 3 months, consistent with its newly created state but providing no evidence of sustained maintenance capacity.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, reducing transparency about how security reports would be handled. The package's new, small generated structure limits the weight of this gap but does not remove it.
The version is not a prerelease, but the package has only one release, so stable version labeling cannot compensate for the absence of release history.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.