The package is small and clearly organized, with tests, a matching repository, an Apache-2.0 license, and no install scripts. Its organization backing helps, but there is not enough release or commit history to establish dependable maintenance.
64%
Total Score
75
79
75
This is the first release, published today, so there is no release cadence or track record yet. That is a meaningful maturity gap, although the repository and organization backing provide some context.
The repository has no commits from active maintainers in the last three months. Because the package was only published today, this may reflect its newness, but it leaves maintenance capacity unproven.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools were detected. That is a transparency and hygiene gap, not a severe supply-chain finding.
The repository has no security policy, leaving vulnerability reporting expectations unclear. This is a minor transparency concern for a newly published package.
The release is not marked prerelease, but the 0.x major version signals an API that may still change. This is a modest concern for dependency stability rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.