The Apache-2.0 licensing is clear, the repository matches the package, and the metapackage uses no install scripts. Organization ownership helps, though security and maintenance evidence is still limited.
76%
Total Score
75
100
86
83
The package is brand new: it has one release, published 0 days ago, with no established release cadence. This limits evidence of ongoing maintenance but does not by itself indicate abandonment.
The repository has 0 commits and 0 active maintainers in the last 3 months. Because it was created immediately before this first release, this is mainly a lack of track record rather than evidence of a collapsed project.
Composer build tooling is present, but no security scanning tools were detected. For this very small generated package this is a limited hygiene gap, not a severe supply-chain concern.
The repository has no security policy. That reduces the transparency of vulnerability-reporting procedures, although the package's small generated metapackage scope limits the practical impact.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-manufacturercenter-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.