The Apache-2.0 license, matching source repository, and focused metapackage design make adoption straightforward. There is no security policy or scanning evidence, so long-term maintenance confidence is limited.
70%
Total Score
75
100
86
50
This is the package's first release, published 0 days ago, so it has no demonstrated release track record yet. Its newness limits maturity evidence but does not indicate abandonment.
No commits or active maintainers were recorded in the preceding 3 months, but the repository and package were created 0 days ago, so this is an absence of history rather than evidence that maintenance collapsed.
The repository uses Composer, which fits the package ecosystem, but no security-scanning tool was detected. For a small generated metapackage this is a hygiene limitation rather than a severe supply-chain signal.
The linked repository has no security policy. This reduces transparency for reporting vulnerabilities, although the package's narrow metapackage role limits the practical impact.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-versionhistory-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.