The package is newly published, so it has no demonstrated release or maintenance track record yet. Its organization-backed repository, matching package metadata, Apache-2.0 licensing, and minimal metapackage design are reassuring; security tooling is not present.
72%
Total Score
75
100
86
83
This is the first release, published today, so there is no historical cadence or evidence of sustained maintenance yet. That limits maturity confidence but does not by itself indicate abandonment.
No commits or active maintainers were observed in the preceding three months, but the repository was created or updated today and the package itself is brand new. This is limited track-record evidence rather than clear maintenance collapse.
Composer build tooling is present, but no security scanning tool was detected. For a small generated package this is a hygiene gap, not a severe dependency risk.
The repository has no security policy. That reduces transparency for vulnerability reporting, although the package is a minimal metapackage with no reported install scripts.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-deploymentmanager-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.