Package Health

jolicode/jolitypo

Licensing and installation behavior are straightforward, and the package is well documented for consumers. The organization-backed project has a balanced recent contributor base and automated checks.

Latest v2.0.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Name lookalikedanger

The package strongly resembles jolicode/jolinotif, and it borrows that package's identity despite having no artifact overlap or self-described fork status. Consumers most likely wanted the lookalike, so verify the package name carefully.

Security policycaution

The repository has no published security policy, leaving vulnerability-reporting expectations less transparent. This is a minor documentation gap rather than evidence of abandonment.

Workflow auditcaution

All 4 workflows were analyzed successfully, all 19 action references are pinned, and no untrusted checkout or script-injection paths were found. One high-confidence medium-severity finding identifies an archived action in the release workflow, while two workflows grant top-level write permissions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Damien Alexandre

Direct Dependencies

DependencyLast ReleaseScore
org_heigl/hyphenator
Version ^3.2
—
—
symfony/polyfill-intl-normalizer
Version ^1.32
—
—

Weekly Downloads

Info

Last Published
8 days ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform