Its Composer-only metapackage layout is clear and the repository matches the package. Organization backing and Apache-2.0 licensing help, but ongoing maintenance has not yet been demonstrated.
68%
Total Score
75
100
88
83
This is the package's first release, published 0 days ago, with only one release recorded. That is expected for a new package but provides no history for judging sustained maintenance.
The repository has 0 commits and 0 active maintainers in the last 3 months. Because the package is 0 days old, this is mainly an absence of evidence rather than proof of abandonment, but it limits confidence.
Composer is used as the build tool, fitting the package ecosystem, but no security scanning tools were detected. This is a modest repository-hygiene gap rather than a standalone dependency blocker.
The repository has no security policy. For a newly published, small generated package this is a transparency gap, though it is not evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-cloudkms-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.