Another good measure is the number of dependencies used: if too much, the quality might be poor (= poor maintainability).
Is the application vulnerable? Check OWASP for this.