The Apache-2.0 license, tests, focused dependency profile, and matching repository are reassuring. The organization-owned project is not archived, but its maintenance record is too short to establish reliability.
62%
Total Score
75
100
81
83
This is a first-day package with one release and no established release cadence, so its maturity and maintenance reliability are unproven.
There were zero commits and zero active maintainers in the prior three months. Because the repository was created and released on the same day, this mainly shows that maintenance history is unavailable rather than proving abandonment.
Composer is used for the build, but no security scanning tool was detected. The missing scanning is a transparency and hygiene gap, not evidence of malicious behavior.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for consumers.
Version 0.459.0.0 is not a stable major version, although it is not marked as a prerelease; this is a modest maturity concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.