It has an Apache-2.0 license, tests, and no install-time scripts. The organization-owned repository matches the package, but there is no security policy or observed maintenance activity yet.
62%
Total Score
75
100
79
88
The package was first and last released 0 days ago and has only one release, so there is not enough history to establish sustained maintenance. Its newness is evidence-limited rather than proof of abandonment.
The repository has 0 commits and 0 active maintainers in the last 3 months. Because the package is newly published, this may reflect its age, but it leaves maintenance capacity unproven.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than a severe risk for this small generated package.
The repository has no security policy. For a newly published package this reduces transparency about vulnerability handling, although the package's narrow generated-artifact scope limits the impact.
Version 0.459.0.0 is not a stable major release, but it is not marked as a prerelease and recent prerelease share is 0%. This is a minor maturity concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.