The organization-owned repository matches the package, and installation has no lifecycle scripts. The main limitation is that this release has no track record yet; no security tooling or policy is visible.
76%
Total Score
75
100
79
88
This is the package's first release, published today, so there is no release cadence or history to demonstrate sustained maintenance. Its same-day repository activity is consistent with a newly launched package rather than abandonment.
There were no commits or active maintainers in the prior three months, but the repository and package are only one day old. This provides little maintenance evidence rather than strong evidence of abandonment.
Composer is used as the build tool, but no security-scanning tools are configured. The missing scanning is a modest transparency and maintenance gap, not a severe risk by itself.
The repository has no security policy. For a newly published package this lowers disclosure transparency, although it is not by itself evidence that the package is unsafe.
The release is not marked prerelease, although its 0.x version means the public API may still change. The generated package context and absence of prerelease labeling partly compensate for that limitation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.