The Apache-2.0 licensing and included tests make the package straightforward to inspect and use. Its organization-owned repository is not archived or deprecated, but the project has not yet demonstrated sustained maintenance.
68%
Total Score
75
100
79
75
The package is brand new: it has one release, published today, with no established release cadence. This limits evidence of maturity, though it is not abandonment evidence by itself.
There were no commits or active maintainers in the last three months, although the repository was only created or updated today. This provides little evidence of sustained maintenance rather than proving abandonment.
Composer is used as a build tool, but no security scanning tool was detected. The missing scanner is a hygiene gap, not a standalone dependency blocker.
The repository has no security policy. For a newly published package this is a transparency gap, though it is not severe enough to indicate that the release is unfit on its own.
Version 0.459.0.0 is not a stable major release, but it is not marked as a prerelease and has no recent prerelease history. This is a modest maturity concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.