The package includes tests, organization backing, and an Apache-2.0 license. Pin this first release and verify its generated dependency set before relying on it.
58%
Total Score
75
50
79
50
The package declares 338 runtime dependencies, including the base Google API client and many generated service packages. This broad dependency surface increases update and compatibility risk, even though it may be expected for an implementation bundle.
This is the package's first release, published 0 days ago, with only one release recorded. That leaves maintenance cadence and long-term reliability unproven.
The repository has no commits and no active maintainers in the last 3 months. Because it was created only 0 days ago, this is primarily limited history rather than evidence of a collapsed project, but ongoing maintenance remains unproven.
The repository uses Composer, which is appropriate for this Packagist package, but no security-scanning tools were detected. The missing scanning is a modest supply-chain hygiene gap.
The linked repository has no security policy. This is a transparency and incident-response gap, with no provided compensating security process.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
tyhpdef/google-apiclient-services-css Version @dev | — | — |
tyhpdef/google-apiclient-services-dlp Version @dev | — | — |
tyhpdef/google-apiclient-services-dns Version @dev | — | — |
tyhpdef/google-apiclient-services-iam Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.