Its Composer-only metapackage layout is appropriate, and the repository is neither archived nor misidentified. Security policy and scanning are absent, while its one-day age leaves maintenance capacity unproven.
68%
Total Score
75
100
81
88
The package was first released 0 days ago and has only one release, so there is no meaningful release track record yet. This is a genuine maturity concern, though the repository is organization-backed.
No commits or active maintainers were observed in the last 3 months. Because the repository was created only 0 days ago, this is primarily unproven maintenance capacity rather than clear abandonment.
The repository uses Composer, matching the package ecosystem, but no security scanning tools were detected. That is a modest transparency and maintenance gap.
The repository has no security policy. For a small generated metapackage this is not severe, but it leaves vulnerability-reporting expectations undocumented.
Version 0.459.0 is not a prerelease and recent releases are not marked unstable, but the package remains before 1.0 and has no history to demonstrate stable evolution.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-datalabeling-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.