The package is newly published, so its maintenance track record is still unproven. It includes tests, a matching Apache-2.0 license, and no install-time scripts, while the organization-owned repository is active and unarchived.
72%
Total Score
75
100
79
83
This is the first release, published 0 days ago, so there is no release cadence or long-term maintenance record to evaluate. Its freshness limits maturity evidence but does not indicate abandonment.
There were no commits or active maintainers in the last 3 months, but the package and repository are 0 days old, so this reflects insufficient elapsed history rather than a demonstrated collapse in maintenance.
Composer is used as the build tool, but no security scanning tools are reported. The missing scanning is a modest repository-hygiene gap, not evidence that the package is unsafe to depend on.
The repository has no security policy. For a newly published small implementation package this is a transparency gap, though it is not severe on its own.
Version 0.459.0.0 is not a stable major version, which is common for generated or implementation packages but still provides less compatibility assurance than a stable major release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.