It includes an Apache-2.0 license, tests, and a small explicit dependency set. The organization-owned repository is not archived, but its maintenance record is too new to establish long-term durability.
78%
Total Score
75
100
79
88
This release is the package's first and was published only hours ago, so there is no release history to demonstrate sustained maintenance. Its age also means the lack of history is not evidence of abandonment yet.
There were zero commits and zero active maintainers in the last three months. Because the repository was created only hours ago, this is an unproven maintenance record rather than evidence of a collapsed project.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tool was detected. That is a modest supply-chain hygiene gap.
The repository has no security policy. For a newly created, small implementation package this limits vulnerability-reporting transparency, but it is not independently severe.
The release is not marked as a prerelease, although the 0.x version indicates an API that may still evolve. That is a modest maturity concern rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.