The Apache-2.0 license, matching repository, included tests, and lack of install scripts provide useful safeguards. Its maintenance record is not yet established, so pin this exact version and reassess future releases.
65%
Total Score
75
100
79
83
This is the package's first release, published today, with only one release and no established release cadence. That leaves long-term maintenance maturity unproven.
The repository has zero commits and zero active maintainers in the last three months. Because it was created today, this is partly explained by its age, but it still provides no demonstrated ongoing activity.
Composer is used as the build tool, but no security-scanning tool is configured. The missing scanner is a hygiene gap rather than evidence that the package is unsafe to depend on.
The repository has no security policy. For a small generated implementation package this is a transparency gap, but it is not severe on its own.
Version 0.459.0.0 is not marked prerelease, which is appropriate for a published implementation package, but the single-release history limits evidence of stability.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.