Licensing and installation behavior are straightforward, and the package is well documented for consumers. The organization-backed project has a balanced recent contributor base and automated checks.
62%
Total Score
100
89
75
The package strongly resembles jolicode/jolinotif, and it borrows that package's identity despite having no artifact overlap or self-described fork status. Consumers most likely wanted the lookalike, so verify the package name carefully.
The repository has no published security policy, leaving vulnerability-reporting expectations less transparent. This is a minor documentation gap rather than evidence of abandonment.
All 4 workflows were analyzed successfully, all 19 action references are pinned, and no untrusted checkout or script-injection paths were found. One high-confidence medium-severity finding identifies an archived action in the release workflow, while two workflows grant top-level write permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
org_heigl/hyphenator Version ^3.2 | — | — |
symfony/polyfill-intl-normalizer Version ^1.32 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.