The Apache-2.0 license, focused README, and matching repository make its purpose and packaging clear. Organization backing helps, but the missing security policy leaves a modest process gap.
68%
Total Score
100
100
79
50
This package is 0 days old with only 1 release, so there is no observed release cadence or long-term maintenance record yet. Its newly pushed repository and organization backing provide some context, but not evidence of sustained upkeep.
The repository uses Composer, matching the package ecosystem. No security scanning tools were detected, leaving a modest transparency and maintenance-process gap.
The linked repository has no security policy. That does not show a vulnerability, but it provides less guidance for reporting and handling security issues.
Version 0.459.0 is not on a stable major version, though it is not marked prerelease and appears aligned with the underlying package version. This is a modest maturity concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-cloudcommercepartnerprocurementservice-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.