The package is clearly documented and licensed, and its small metapackage structure keeps the dependency surface narrow. Treat its maintenance track record as unproven until more releases and commits appear.
70%
Total Score
75
100
79
50
The package was published today and has only one release, so there is no demonstrated release cadence or maintenance history yet.
There have been no commits and no active maintainers in the last three months, but the repository and package were created today, making this an unproven history rather than evidence of a collapsed project.
The repository uses Composer, which fits the package, but no security-scanning tooling was detected. For this small generated package that is a modest transparency gap rather than a severe risk.
The repository has no security policy. This limits vulnerability-reporting transparency, although the package is a small type-definition metapackage with no runtime lifecycle scripts.
Version 0.459.0 is a regular release rather than a prerelease, but the 0.x major version indicates an API-stability track record that is not yet established.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-oauth2-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.