The organization-backed repository is current, unarchived, and clearly matches this package. Its Apache-2.0 licensing and minimal generated-package layout are appropriate, but there is not yet enough release or commit history to establish long-term maintenance.
68%
Total Score
75
100
86
83
This package is 0 days old with only 1 release, so there is no demonstrated release cadence or track record yet. That is a meaningful maturity gap, but it is not evidence of abandonment for a newly published package.
There were no commits or active maintainers in the prior 3 months, which would be concerning for an established package. Because the package was first released today and the repository was pushed today, this mainly reflects its lack of track record.
Composer is used as the build tool, which fits the ecosystem, but no security scanning tooling was detected. This is a modest transparency and hygiene gap rather than a severe supply-chain concern.
The linked repository has no security policy. That reduces vulnerability-reporting transparency, although the package's small generated-artifact scope limits the significance of this gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-firebasehosting-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.