Its Apache-2.0 licensing, focused metapackage design, and organization-owned repository make its purpose clear. Composer build support is present, but the project has no security policy or scanning tooling. Pin this version only if accepting the limited operating history.
64%
Total Score
75
100
86
88
This is the package's first release, published 0 days ago, with only one release recorded. That leaves maintenance and release consistency unproven despite the repository being newly updated.
There were 0 commits and 0 active maintainers in the last 3 months, but the repository itself was created or updated on the release day. For a first-day release this is mainly an absence of history rather than evidence of abandonment.
The repository uses Composer, which fits the package, but it reports no security-scanning tools. That weakens defensive maintenance evidence without indicating an immediate dependency problem.
No security policy is present in the linked repository. This is a transparency and response-process gap, particularly for a package intended to be consumed as a development dependency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-apimanagement-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.