Package Health

bitbag/sylius-customer-reorder-plugin

Testing, release notes, and a clear license improve transparency. The project has had no commits or releases for about three years, and its README says it is deprecated and will not be maintained; workflow pinning is also weak.

Latest v2.0.1PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

57

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Package scaffoldingdanger

The package includes a README and tests, and this exact version has GitHub release notes, which provide useful consumer and maintenance context. However, the README explicitly warns that the repository is deprecated and will not be maintained or receive bug fixes.

Release historydanger

There have been 12 releases since June 2022, but none in the last 12 months and the latest release was about three years ago. This indicates a materially stalled release cadence.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the README's statement that maintenance has ended.

Repo issue activitycaution

There were no new issues, closed issues, or pull requests in the last month. This supports the broader picture of inactivity, although the available issue count is incomplete.

Repo toolingcaution

Composer build tooling is present, but no security scanning tooling was detected. This is a secondary transparency and maintenance gap beside the stronger evidence of abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Bartosz Pietrzak

Direct Dependencies

DependencyLast ReleaseScore
sylius/sylius
Version ~1.10.0 || ~1.11.0
—
—
bitbag/coding-standard
Version ^v2.0.2
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform