The Apache-2.0 license, matching repository, and organization ownership provide clear provenance. Its small metapackage layout is appropriate, but there is not yet enough release or repository history to establish sustained maintenance.
68%
Total Score
75
100
79
88
This is the package's first release, published 0 days ago, so there is no release cadence or track record yet. That limits confidence in sustained maintenance but does not show abandonment.
The repository recorded 0 commits and 0 active maintainers in the last 3 months; because the package is newly published, this is limited evidence rather than proof of neglect.
The repository has 0 stars, forks, and watchers. For a package released 0 days ago this is unsurprising, but it provides no supporting evidence of established adoption.
The repository uses Composer build tooling, appropriate for this package, but has no reported security scanning tool. That is a minor transparency gap rather than a severe concern for this minimal metapackage.
No repository security policy was found. This is a modest transparency gap, although the package is a small metapackage with no reported executable lifecycle scripts.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-firebaseappcheck-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.