The README, matching repository, Apache-2.0 licensing, and lack of install scripts make the package straightforward to inspect and consume. Organization backing helps, but its maintenance record is still unproven.
68%
Total Score
75
100
79
83
The package is brand new, with only one release and no established release cadence. Its age explains the limited history, but maintenance reliability is not yet demonstrated.
There were no commits or active maintainers in the preceding three months. Because the repository was created only recently, this is mainly an unproven-maintenance signal rather than evidence of abandonment.
The repository uses Composer build tooling, but no security-scanning tool was detected. For this small generated metapackage, the missing scanner is a modest hygiene gap.
No repository security policy was found. This is a transparency gap, though the package's small metapackage scope limits its weight.
Version 0.459.0 is not a prerelease, and the package has no recent prerelease pattern. The 0.x version still indicates a less mature stability contract.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-cloudcomposer-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.