The organization-owned repository matches the package, and the artifact has a clear Apache-2.0 license, README, and expected metapackage dependency. Its single release and zero commits in the last three months leave maintenance maturity unproven.
68%
Total Score
75
100
86
83
This package was first released today and has only one release, so there is no release track record yet. That limits evidence of maturity, although the lack of history is consistent with a newly published package.
The repository has zero commits and zero active maintainers over the last three months. Because it was created and released today, this is mainly an absence of evidence rather than proof of abandonment, but it limits confidence.
Composer is used as the build tool, which fits the package ecosystem. No security-scanning tools were detected, leaving a modest repository-hygiene gap.
The repository has no security policy. For this small, newly created metapackage this is a transparency gap, though it is not by itself evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-cloudalloydbadmin-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.