Organization ownership, an Apache-2.0 license, and included tests provide useful safeguards. The package is too new to demonstrate sustained maintenance, and its repository has no security policy or scanning tools.
68%
Total Score
75
100
79
83
This is the first release, published today, so there is no release history or cadence demonstrating sustained maintenance. The linked organization and current repository activity provide some context but cannot establish longevity.
There were no commits from active maintainers in the last three months, but the repository and package were created today, so this is insufficient history rather than evidence of collapsed maintenance.
Composer build tooling is present, but no security-scanning tools were detected. That leaves a modest transparency and maintenance-hygiene gap, especially for a package intended for dependency use.
The repository has no security policy. This is a real but limited transparency gap; it does not by itself indicate that the package is unsafe to depend on.
Version 0.459.0.0 is not marked prerelease, which avoids prerelease instability, but the package has only one release and no track record to support stronger confidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.