The README is clear, the package is correctly licensed, and organizational backing supports its generated-package model. Its maintenance record is still unproven, with no prior releases or observed commits, so pinning this exact version is prudent.
65%
Total Score
75
100
83
50
This is the first recorded release, published only recently, so there is no release history to demonstrate continuity or maintenance maturity. Its zero-day age makes the gap expected for a new package rather than evidence of abandonment.
The repository has recorded 0 commits and 0 active maintainers in the last 3 months. Because the package was published very recently, this shows unproven maintenance capacity rather than a collapsed long-running project.
Composer is used as the build tool, which fits the package ecosystem, but no repository security-scanning tool was detected. That is a modest transparency and hygiene gap, not a severe risk.
The linked repository has no security policy. For a small generated type-definition metapackage this is a limited gap, but it leaves no documented channel or process for security reports.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-binaryauthorization-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.