The Apache-2.0 license, matching license file, organization-owned repository, and focused metapackage structure are reassuring. There is no security policy or automated security scanning yet, and the project has no established maintenance history.
70%
Total Score
75
100
86
50
The package was first and last released today, with only one release and no release interval. This is expected for a newly published package but provides no track record for judging sustained maintenance.
There were no commits or active maintainers in the last three months, but the package and repository are only hours old. This is insufficient history rather than evidence of a collapsed project.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are configured. That is a modest transparency and maintenance gap.
The repository has no SECURITY.md policy. This does not show a security defect, but it leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/google-apiclient-services-walletobjects-impl Version ~0.459.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.