The package is clearly licensed, narrowly scoped, and backed by an organization with matching repository documentation. Its generated-package structure is appropriate, but there is not yet enough history to establish durable maintenance.
68%
Total Score
75
100
79
83
This is the first and only release, published within the last day, with no established release cadence. That limits evidence of ongoing maintenance for a dependency.
There were zero commits and zero active maintainers in the last three months, although the repository was only recently created. This is insufficient history rather than clear abandonment.
The repository uses Composer as its build tool, appropriate for this package, but no security-scanning tools were detected. That is a modest transparency gap for supply-chain maintenance.
No repository security policy was found. For a small generated package this is a hygiene gap, but it does not by itself indicate that the release is unsafe to adopt.
Version 0.459.0 is not marked prerelease, which is appropriate for a published release, but the pre-1.0 series offers less maturity evidence than a stable major version.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-pubsub-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.