Its Apache-2.0 licensing, focused dependency set, tests, and organization ownership provide useful baseline context. The package is too new to establish a dependable maintenance track record; pin this version and recheck future releases.
62%
Total Score
75
100
79
75
This is the first and only release, published 0 days ago, so release cadence and long-term maintenance cannot yet be demonstrated. The very recent package age makes this an uncertainty rather than evidence of abandonment.
There were no commits or active maintainers in the last 3 months, but the repository and package are both 0 days old. The lack of history is therefore expected for now, while still leaving maintenance capacity unproven.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tool is reported. For this small, newly created package that is a modest transparency gap rather than a severe risk.
The repository has no security policy. This is a transparency and reporting gap, though the package's organization-backed ownership and very recent creation provide some context against treating it as a severe concern.
Version 0.459.0.0 is not a stable major version, but it is not marked as a prerelease and has no recent prerelease history. This is a minor maturity concern for a newly published package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.