Risky to adopt: this package has had only one v0.0.1 release, with no commits or releases for about three years. Its matching repository, substantial README, and Apache-2.0 license help, but the tiny project lacks tests and security tooling.
43%
Total Score
0
64
50
There has been only one release, published about three years ago, with no releases in the last 12 months. That strongly suggests the package is dormant, although it is not deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This is a substantial maintenance and abandonment concern.
The package defines post-install, post-update, and pre-autoload-dump scripts, increasing the amount of install-time behavior that must be trusted. No other provided signal demonstrates why these hooks are necessary or limits their risk.
The repository has zero stars and forks and only one watcher, providing no supporting evidence of community review or adoption. Popularity is not required for a small package, so this is a secondary concern.
Composer build tooling is present, but no security scanning tools were detected. For a package handling Google Drive integration, that is a transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7|^2.0 | — | — |
google/apiclient Version ^2.2 | — | — |
league/flysystem Version ^2.1.1|^3.0 | — | — |
guzzlehttp/guzzle Version ^6.3 | ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.