Its one runtime dependency limits transitive complexity, and the release is a stable major version. There is little evidence of current project oversight, leaving maintenance risk with your team.
35%
Total Score
100
100
61
75
The package has had no releases in more than six years, despite 12 releases early in its history; this strongly indicates abandonment risk.
Neither the package nor the linked repository provides a declared or detected license file, leaving the legal terms for use unclear.
The artifact and repository contain no tests or changelog, while the package also has no README. Missing tests and changelog are normal in published artifacts, but the absence of consumer documentation is a minor transparency gap for this framework module.
The repository name does not match the package name, and the package is not confirmed in the README. This raises concern that the repository may not be the package's actual source.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide no meaningful community backing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
scancode-system/order-module Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.