The small artifact is intentionally a Composer metapackage with one implementation dependency and no install scripts. Licensing is explicit, and the linked repository matches the package; lack of tests, changelog, security policy, and CI is limited evidence for this generated package.
76%
Total Score
75
100
86
50
This is the package's first release, published today, so it has no demonstrated release track record. Its fresh publication partly explains the absence of historical cadence rather than indicating abandonment.
There were no commits or active maintainers in the last three months, which would be concerning for an established project. Because the release and repository were created today, this is better interpreted as unproven maintenance capacity.
Composer build tooling is present, but no security-scanning tool was detected. That is a modest transparency gap, not a severe concern for this small generated metapackage.
The repository has no security policy, reducing the documented path for reporting vulnerabilities. This is a minor hygiene gap rather than evidence that the package is unsafe to depend on.
No GitHub Actions workflows were present, so there are no workflow findings or unpinned actions to assess. This provides no CI assurance but also exposes no workflow-specific risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-cloudresourcemanager-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.