The package is clearly a small generated metapackage with a matching repository, a license, and no install-time scripts. Its long-term maintenance record and security controls are not yet established, so pinning this exact release is wiser than assuming durable support.
58%
Total Score
75
100
88
75
This package is brand new: it has one release and is 0 days old, so there is no release history from which to judge continuity or responsiveness.
There were no commits and no active maintainers in the prior three months, but the repository and package are newly created, so this is mainly an absence of track record rather than evidence of a collapsed project.
Composer is used as the build tool, but no security-scanning tool is detected; for a generated package this is a modest transparency and assurance gap.
The repository has no security policy. This is a minor transparency gap, though the package contains only generated type-definition packaging metadata.
No GitHub Actions workflows were present, so the audit found no workflow vulnerabilities; this also means there is no observed automated release or security workflow to support maintenance confidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-travelimpactmodel-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.