The Apache-2.0 license, clear README, matching repository, and organization backing provide useful transparency. Its generated metapackage design makes the tiny artifact and absent tests unsurprising; revisit after a release history develops.
74%
Total Score
75
100
83
88
The package was first and last released today, with only one release and no interval history. This limits evidence of sustained maintenance, though the package is newly published rather than demonstrably abandoned.
There were no commits or active maintainers in the last three months, but the repository was only created today and the package has one release. This is limited evidence rather than a strong abandonment signal.
The repository has zero stars, forks, and watchers. For a newly created generated package this is weak supporting evidence, not a serious health concern by itself.
Composer build tooling is present, but no security scanning tool was detected. That is a modest transparency and hygiene gap for a package with otherwise very small generated contents.
The repository has no security policy. For a small generated metapackage this is a minor process gap, but it leaves no documented channel for reporting issues.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-cloudbillingbudget-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.