The package has tests, a matching repository, a clear Apache-2.0 license, and no install-time scripts. Its history is too new to establish dependable maintenance, and the repository has no security policy or scanning tooling.
58%
Total Score
75
100
83
83
This is the first and only release, published 0 days ago, so there is no release track record or demonstrated maintenance cadence yet.
The repository records 0 commits and 0 active maintainers in the last 3 months. Because it is newly created, this mainly shows that maintenance capacity has not yet been demonstrated rather than clear abandonment.
The repository has 0 stars, forks, and watchers. This is consistent with a newly published package and is supporting evidence only, but it provides no community maturity signal.
Composer is used as the build tool, but no security scanning tools are configured, leaving a modest transparency and security-process gap.
The repository has no security policy. This is a real disclosure-process gap, though it is not severe enough by itself to make the package unfit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/auth Version 1.54.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.