Skip to content
CAI
Software that uses CAICheck a score

googleapis/google-api-php-client

64.9

Adequate · 26 September 2026

4.9k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a PHP client library for interacting with Google APIs, currently in maintenance mode with a minimum requirement of PHP 8.0. It provides core functionality for authentication, HTTP transport, and token management, while delegating specific API service definitions to a separate repository. The library has been modernized to use PSR-7/PSR-6 standards and Guzzle 8, removing legacy internal implementations for caching, HTTP, and authentication in favor of external, standards-compliant components.

How it got here

2013 — PHP 8.0+ modernization and legacy cleanup

14 changes.

The library entered maintenance mode and raised its minimum PHP version to 8.0, triggering a comprehensive removal of legacy core classes, authentication mechanisms, and HTTP transport layers. This architectural shift replaced custom implementations with modern standards like PSR-4 autoloading, PSR-6 caching, and Guzzle, while updating examples and tests to reflect the new namespace structure and security practices.

2015–2024 — PHP 8 and Guzzle 8 modernization

13 changes.

The library underwent a major modernization to support PHP 8 and Guzzle 7/8, migrating namespaces, rewriting the HTTP layer with PSR-7, and refactoring authentication handlers. This period also introduced dedicated classes for token revocation and verification, alongside a new task component for retry logic and Composer cleanup. Comprehensive unit tests were added to cover these core components and ensure backward compatibility during the transition.

Features

Introduce Task component with Composer cleanup and retry runner

Adds a new \Google\\Task\ namespace containing a \Composer\ class that cleans up unused Google API service files during installation, a \Runner\ class that executes tasks with configurable exponential backoff and retry logic, and supporting \Exception\ and \Retryable\ classes. This provides a dedicated mechanism for handling API retries and managing Composer dependencies for the API client services.

src/Task · high confidence

New AccessToken Revoke and Verify classes

Added src/AccessToken/Revoke.php and src/AccessToken/Verify.php to provide dedicated classes for revoking OAuth2 tokens and verifying ID tokens. The Revoke class handles token revocation via Google's revoke endpoint, while the Verify class uses Firebase JWT with a CachedKeySet for efficient certificate caching and validates ID tokens against Google's issuers and audience claims.

src/AccessToken · high confidence

Refactored HTTP layer to use PSR-7 and support Guzzle 8

The HTTP transport layer has been rewritten to use PSR-7 interfaces (RequestInterface, ResponseInterface) and Guzzle 8's PSR-7 implementation, replacing the previous custom request classes. This update introduces a new Batch class for handling batched API requests, refactors the MediaFileUpload class to accept PSR-7 requests, and updates the REST client to handle Guzzle 8's exception hierarchy. Users benefit from better standards compliance and compatibility with modern HTTP client versions.

src/Http · high confidence

Removals

Removal of deprecated Google API service classes

The library has removed several legacy Google API service definitions from the \src/Google/Service\ directory, including AdExchangeSeller, AdSense, AdSenseHost, Adexchangebuyer, Analytics, Androidpublisher, Appstate, Audit, Bigquery, and Blogger. Users relying on these specific services will no longer have access to their client-side wrappers and must migrate to updated API versions or alternative libraries.

src/Google/Service · high confidence

Removal of legacy Google Cache implementations

The legacy Google-specific caching classes (Abstract, Apc, File, and Memcache) have been removed from the library. This change eliminates the custom caching infrastructure in favor of the standard PSR-6 caching interface, meaning users must now configure their application to use a PSR-6 compatible cache provider instead of the previous Google\Cache\\* classes.

src/Google/Cache · high confidence

Removal of legacy HTTP transport components

The \src/Google/Http\ directory has been completely removed, deleting the \Batch\, \CacheParser\, \REST\, and \Request\ classes. This eliminates the library's previous internal HTTP transport and caching implementation, requiring users to rely on the updated HTTP layer (likely Guzzle-based) for all API requests.

src/Google/Http · high confidence

Removal of legacy P12 signer and PEM verifier classes

The legacy \Google\_Signer\_P12\ and \Google\_Verifier\_Pem\ classes have been removed from the codebase. This eliminates the specific implementation details for signing data using PKCS\#12 files and verifying signatures using PEM-encoded certificates, indicating a shift away from these older authentication and verification mechanisms in favor of newer approaches.

src/Google/Signer · high confidence

Removal of legacy PHP IO transport layer

The \src/Google/IO\ directory has been removed, deleting the \Google\_IO\_Abstract\ base class, the \Google\_IO\_Stream\ HTTP stream implementation, the \Google\_IO\_Exception\ class, and the bundled \cacerts.pem\ certificate file. This eliminates the legacy PHP stream-based HTTP transport and its associated caching and header-parsing logic from the library.

src/Google/IO · high confidence

Removal of legacy authentication classes

The \src/Google/Auth\ directory has been cleaned up by removing several obsolete authentication implementation files: \Abstract.php\, \AssertionCredentials.php\, \LoginTicket.php\, \OAuth2.php\, and \Simple.php\. This change eliminates the legacy authentication classes that were previously used for handling OAuth2 flows, service account assertions, and simple API key access, effectively removing these components from the library's public API.

src/Google/Auth · high confidence

Removal of legacy core classes from the Google API Client library

The \src/Google\ directory has removed the legacy \Google\_Client\, \Google\_Config\, \Google\_Model\, and \Google\_Utils\ classes. This change eliminates the internal configuration system, model handling, and utility methods that were previously bundled with the client, indicating a shift toward a simplified or externalized architecture for these core components.

src/Google · high confidence

Behavioural changes

Auth handler refactored for Guzzle 7/8 support with Guzzle 6 deprecation

The authentication handler system has been restructured to support Guzzle 7 and 8, while marking Guzzle 6 as deprecated. The previous abstract verifier and signer classes have been replaced by concrete handlers: a new Guzzle6AuthHandler (now deprecated) and a Guzzle7AuthHandler that extends it. The AuthHandlerFactory now dynamically selects the appropriate handler based on the installed Guzzle version (7 or 8), throwing an exception for unsupported versions. This change aligns the library with modern Guzzle versions and simplifies the handler selection process for users.

src/AuthHandler · high confidence

Enhanced example templates with session management and credential validation

The base template in examples/templates has been significantly expanded to improve the developer experience when running samples. It now automatically starts PHP sessions to store access tokens and CSRF tokens, ensuring stateful interactions work correctly. New helper functions provide clear, user-facing warnings when required API keys, client secrets, service account credentials, or OAuth2 credentials are missing, guiding users on where to obtain them from the Google API console. Additionally, utilities for generating and validating CSRF tokens have been added to prevent cross-site request forgery, and functions to read API keys from local files have been introduced to simplify configuration.

examples/templates · high confidence

Examples updated to use namespaced classes and modern OAuth 2.0 flows

The sample code in the examples directory has been modernized to align with the current library structure. Hardcoded client IDs and secrets have been replaced with credential file loading (setAuthConfig) and environment variable support for service accounts. The examples now use the new namespaced class structure (e.g., Google\\Client, Google\\Service\\Drive) and the vendor autoloader instead of manual require statements. Authentication flows have been updated to use fetchAccessTokenWithAuthCode and support PKCE (code verifier), and the UI templates have been standardized with consistent header/footer functions.

examples · high confidence

Library enters maintenance mode and drops support for PHP versions below 8.0

The library is now officially in maintenance mode, meaning only critical bugs and security issues will be addressed rather than new features. Additionally, the minimum supported PHP version has been raised to 8.0, dropping support for PHP 7.x and earlier. The README has been updated to reflect these changes, including updated installation instructions and examples using the new namespace structure.

(repo-wide) · high confidence

Namespace migration and PHP 8 compatibility updates

The library has migrated its core classes (Client, Model, Service, Collection, etc.) from the legacy flat namespace (e.g., \Google\_Client\) to the \Google\ namespace (e.g., \Google\\Client\), while maintaining backward compatibility through \src/aliases.php\ which maps old class names to the new ones. This change includes dropping support for PHP 7.3 and below, adding explicit return types to address Symfony deprecations, and updating the \Model\ class to support dynamic properties via the \\#\[\\AllowDynamicProperties\]\ attribute. The \Service\ constructor now accepts either a \Client\ instance or a configuration array, and the \Collection\ class has been refactored to use modern PHP iteration interfaces with proper null-safety checks.

src · high confidence

Service classes moved to dedicated repository and namespace refactored

The Google API Client Service classes have been moved to the separate google-api-php-client-services repository, as indicated by the new README. Within this package, the service namespace has been refactored (e.g., \src/Google/Service/Exception.php\ renamed to \src/Service/Exception.php\), and the \Resource\ class now explicitly defines stack parameters and handles API versioning via a protected \apiVersion\ property. The \Exception\ class has been updated to use modern PHP syntax, including nullable type hints for the \$previous\ parameter in the constructor and updated PHPDoc for the \getErrors\ method.

src/Service · high confidence

Test coverage

Added and refactored tests for example scripts; Added and refactored unit tests for Google Service resources; Added test coverage for HTTP batch processing, media uploads, and REST response handling; Added tests for Google AuthHandler token caching behavior; Added unit tests for Composer cleanup and Task Runner retry logic; Added unit tests for Google AccessToken Revoke and Verify components; Added unit tests for caching, client configuration, and model serialization; Modernized test infrastructure and added URI template coverage; Removal of legacy general test suite; Removed legacy PageSpeed and Plus API test suites.

Dependencies

Drops PHP 5.2 support and upgrades core dependencies to PHP 8.1+

The library now requires PHP 8.1 or higher, dropping support for all older PHP versions. Core dependencies have been updated to modern versions: google/auth is now ^1.53, google/apiclient-services is \~0.350, firebase/php-jwt supports ^6.0 or ^7.0, monolog/monolog supports ^2.9 or ^3.0, guzzlehttp/guzzle supports ^7.8.2 or ^8.0, and guzzlehttp/psr7 supports ^2.6.3 or ^3.0. The autoloading strategy has also shifted from PSR-0 to PSR-4, and several dev dependencies like phpunit and symfony components have been updated to their latest compatible versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 45 → 65 (+20.2)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 98 → 95 (-2.9)
  • Architecture 94 → 92 (-2.2)
  • Maturity 55 → 53 (-2.8)
  • Readiness 24 → 67 (+42.7)
  • Security 52 → 78 (+25.8)

Resolved (20)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • No exposed public API
  • No tests found
  • Test reliability not included

New (44)

  • Batch.parseResponse (cognitive 16) (src/Http/Batch.php)
  • ClassTooLong: Client (src/Client.php)
  • Confusingly similar names: attachCredentials and attachCredentialsCache are distinct methods but their names suggest a hierarchy or aliasing that isn't clear. attachCredentialsCache takes a FetchAuthTokenCache type, while attachCredentials takes FetchAuthTokenInterface. This implies one is a specialized wrapper for the other, but the naming doesn't clearly convey that attachCredentialsCache is for cached credentials specifically.
  • Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
  • Duplicate intent: ID token verification is exposed on both the main Client class and the dedicated Verify class. The signatures differ slightly (Client omits the audience parameter, likely deriving it from config, while Verify requires it explicitly), which creates confusion about which method to use and how audience validation is handled.
  • Duplicate intent: Token revocation is exposed on both the dedicated Revoke class and the main Client class. Users can achieve the same result via two different entry points with different signatures (one requires instantiating a specific class, the other is a method on the main client).
  • FileTooLong: src/Client.php (src/Client.php)
  • Further sole-owners (lower concentration)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 24 more

Changes since last survey

  • 4 commits — 3 feature/other, 1 fixes

By area

  • (root) — 3 commits
  • src/Http — 1 commit

Notable commits

  • fix: fix: match batch response parts to requests by Content-ID (#2726)
  • change: chore(main): release 2.20.0 (#2727)
  • change: chore(main): release 2.20.1 (#2728)
  • change: feat: add support for Guzzle 8 (#2725)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

googleapis/google-api-php-client was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 31b577e7012c4e68d5289d63aaf7e6d471ec1ff1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.