Package Health

sylius/order-bundle

This is a mature, actively released MIT-licensed package with 318 releases over more than 12 years, a stable non-prerelease version, an unarchived organization-owned repository, and a repository security policy. The main concerns are that the linked repository shows no commits or pull requests in the last three months, has no detected security-scanning tooling, and does not explicitly mention this package in its README; these reduce confidence in current maintenance and repository association, though the package artifact is substantial and repository tests compensate for the absence of packaged tests.

Latest v2.2.9PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the last 3 months, which is a meaningful current-maintenance concern despite the strong historical release record and recent repository push timestamp.

Repo issue activitycaution

There were no new or closed issues or pull requests and no merged pull requests in the last month; this is consistent with low current development activity, although the open-issue count is unknown.

Repo package mentioncaution

The repository name does not exactly match the package name and its README does not mention the package, creating a caution that the repository association may be indirect; the dedicated SyliusOrderBundle repository name makes the mismatch less severe than an unrelated popular-project repository.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. This is a genuine supply-chain hygiene gap, though it is not by itself evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Paweł Jędrzejewski
Sylius project
Community contributions

Direct Dependencies

DependencyLast ReleaseScore
sylius/order
Version ^2.0
—
—
sylius/money-bundle
Version ^2.0
—
—
sylius/resource-bundle
Version ^1.12
—
—
symfony/framework-bundle
Version ^6.4.1 || ^7.4
—
—
symfony/service-contracts
Version ^3.5
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform