The package has tests, an Apache-2.0 license, organization backing, and no install-time scripts. Its maintenance record is too new to establish long-term reliability, and the repository has no security scanning or policy.
68%
Total Score
75
100
86
83
This is the package's first release, published 0 days ago, so there is no release cadence or maturity record yet. That is a meaningful adoption uncertainty, though its newness explains the absence of history.
The repository has 0 commits and 0 active maintainers in the last 3 months, but it was also pushed on the release day. This does not show abandonment, yet it provides no evidence of sustained maintenance.
Composer is used for builds, which is appropriate, but no security scanning tools were detected. This is a modest repository hygiene gap rather than a severe supply-chain concern.
The linked repository has no security policy. That reduces transparency for vulnerability reporting, although the package's new age limits how strongly this absence should be weighted.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.