Package Health

amplify/order-rule

This release is usable but presents meaningful maintenance and transparency concerns. It has a current stable version, is not deprecated, is backed by a non-archived organization-owned repository, and has a recent release, which support continued availability. However, the package is small and lightly adopted, has only three releases over roughly one year, shows no commits or active maintainers in the last three months, and lacks README, tests, changelog, security policy, and security scanning. The repository contents do provide a coherent Composer package structure, and the dependency footprint and workflow risk are limited, so this is a cautionary dependency rather than an obviously unfit one.

Latest 1.0.2PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. That is a limited publishing base, though the linked repository is organization-owned, which provides some compensating project backing.

Package scaffoldingcaution

The artifact and repository lack a README, tests, and changelog. GitHub Releases provide some release communication, but the absence of tests and user-facing documentation remains a maintenance and transparency gap for a framework package.

Release historycaution

There have been three releases over about 357 days, with three releases in the last 12 months and a median interval of about 179 days. This shows ongoing publication but only modest release cadence and maturity.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. This is a significant maintenance concern, despite the recent registry release and repository push.

Repo package mentioncaution

The repository name does not exactly match the package name, but it is a dedicated-looking order-rule-module repository and the organization ownership provides contextual support. The missing README means package-name mention could not be confirmed, so this remains a mild transparency concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Hafijul Islam

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
27 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform