Its Apache-2.0 licensing, focused metapackage design, and matching organization repository make the artifact transparent. Security scanning and broader project history are not evidenced.
67%
Total Score
75
100
86
83
This is the package's first and only release, published today, so there is no established release track record yet; the very recent age limits how strongly this weighs against it.
The repository recorded zero commits and zero active maintainers in the last three months, but the package and repository were created today, so this is limited evidence of abandonment rather than a severe concern.
Composer build tooling is present, but no security scanning tools were detected. For a small generated type-definition metapackage this is a modest transparency gap, not evidence of unsafe code.
The linked repository has no security policy. This is a minor maturity gap for a package with little demonstrated history, though the package is a narrow type-definition metapackage.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-ondemandscanning-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.