The Apache-2.0 license and organization-owned, package-matching repository provide clear provenance. This is a newly published metapackage, so maintenance history and security practices are not yet established.
78%
Total Score
75
100
88
88
This release is the package's first and was published 0 days ago, so there is no release history or cadence demonstrating sustained maintenance. Its very recent age partly explains the absence of history but leaves maturity unproven.
The repository has recorded 0 commits and 0 active maintainers in the last 3 months. Because the package is 0 days old, this is not evidence of abandonment, but it provides no demonstrated maintenance capacity yet.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are reported. For a tiny metadata-only package this is a modest hygiene gap rather than a severe risk.
The linked repository has no security policy. This limits disclosure transparency, although the package is a small metapackage with no reported executable install scripts.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-firebasestorage-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.