Its single release is brand new, so there is no maintenance track record yet. Apache-2.0 licensing, an explicit README, matching source repository, and organization backing make the generated metapackage reasonably transparent.
70%
Total Score
75
100
79
88
The package was first and last released on the same day, with only one release and no established release cadence. This limits evidence of ongoing maintenance, though its zero-day age makes the gap expected rather than proof of abandonment.
There were no commits or active maintainers in the preceding three months. Because the repository and package are brand new, this is a missing track record rather than clear evidence that maintenance has collapsed.
The repository uses Composer, appropriate for this package, but no security-scanning tools were detected. For a tiny generated metapackage this is a modest hygiene gap, not a severe supply-chain concern.
No security policy was found in the linked repository. That reduces disclosure transparency, although the package is a small generated metapackage with no install scripts.
Version 0.459.0 is not a prerelease, but this is still a new 0.x package with no prior release history to demonstrate stability.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-securesourcemanager-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.