The 39-file artifact is substantive and has no install scripts, but it lacks a security policy and automated security scanning. Pinning this version leaves you with an old dependency whose maintenance and licensing status should be treated as a liability.
43%
Total Score
100
50
83
The package has had no release in about five years: its latest release was July 2021, despite 13 releases overall. That long pause is strong evidence of abandonment risk.
No license is declared, no license file is present in the artifact, and no repository license file was found. This creates a real legal and adoption concern.
The linked repository name does not match the package name, and no README mention was available. Although this could reflect a naming convention, the package-to-source relationship is not transparent.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these counts provide little external evidence of active use or review.
Composer build tooling is present, which supports ordinary packaging, but no security-scanning tooling is configured. That is a modest maintenance and assurance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
scancode-system/order-module Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.