Joona appears to be a currently maintained and usable dependency: it has a substantial release history, a stable non-prerelease version, an active non-archived repository, clear MIT licensing, package/repository identity alignment, and no install-time lifecycle scripts. The main concerns are that all seven commits in the last three months came from one contributor, the artifact and repository have no tests or changelog, the repository has no security policy, and it has negligible adoption indicators. Organization ownership provides some continuity for the concentrated contributor base, but the limited validation and security-process evidence warrant caution rather than an unequivocally healthy rating.
78%
Total Score
60
100
83
83
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tightenco/ziggy Version ^2.0 | — | — |
jenssegers/agent Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.