Organization ownership and a repository matching the package provide useful provenance. The package includes tests, an Apache-2.0 license, and no install scripts, but security policy and scanning are absent.
68%
Total Score
75
100
81
83
This is the first and only release, published today, so there is no demonstrated release track or maintenance history yet. The new repository limits how strongly the absence of history can be interpreted.
There were no commits or active maintainers in the last three months. Because the repository was created today, this is mainly a lack of demonstrated history rather than evidence of a collapsed project.
Composer is used as a build tool, but no repository security scanning tool was detected. That is a modest transparency and maintenance gap, not a severe dependency risk by itself.
The repository has no security policy. This reduces disclosure transparency, though the package's very recent creation and organization backing partly offset the concern.
The release is not marked prerelease and uses a stable version format, although the 0.x major version indicates the API may still evolve.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient-services Version 0.459.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.