It has a clear Apache-2.0 license, tests, and an unarchived organization-owned repository. The project is too new to establish maintenance reliability; pin this exact version.
67%
Total Score
75
83
75
The package was released only once, on the assessment day, so there is no release history or cadence demonstrating sustained maintenance.
The repository shows zero commits and zero active maintainers in the last 3 months; because the repository is brand new, this is limited evidence rather than abandonment proof.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest supply-chain hygiene gap.
The linked repository has no security policy. This is a transparency gap, though the package's very recent creation limits how much weight it carries.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.