The README clearly explains the metapackage, its generated type dependency, and the intended Composer usage. The linked organization owns a matching repository with an Apache-2.0 license, but the package is too new to demonstrate durable maintenance.
70%
Total Score
75
100
86
75
This package was first published today and has only one release, so there is no release history yet to establish sustained maintenance. Its recency explains the absence of a longer record but does not compensate for it.
The repository has no commits or active maintainers in the last three months. Because the package is only zero days old, this is mainly an unproven maintenance record rather than evidence of abandonment.
The repository uses Composer, appropriate for the package, but no security scanning tool was detected. For a newly published small metapackage this is a modest transparency gap, not a severe risk.
No security policy was found in the linked repository, leaving vulnerability-reporting expectations unspecified.
No GitHub Actions workflows were present, so there were no workflow findings; this also provides no automated build or security assurance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-dfareporting-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.