A large, active contributor base and frequent releases reduce abandonment risk. Clear licensing, security documentation, and readme coverage support responsible adoption, while the extensive dependency set adds some operational complexity.
94%
Total Score
100
50
94
100
The package declares 36 runtime dependencies, many within the same Jetpack project; this reflects substantial scope and adds operational complexity, but the dependencies are explicit rather than hidden.
The repository uses Composer for builds, providing an established build mechanism; no security-scanning tools were detected, which is a modest transparency gap but not decisive against a well-maintained project.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-24374 automattic/jetpack is vulnerable to Improper Access Control in versions 0.0.0 - 9.8. | 0.0.0 - 9.8 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
automattic/jetpack-waf Version ^0.1 | — | — |
automattic/jetpack-jitm Version ^2.2 | — | — |
automattic/jetpack-logo Version ^1.5 | — | — |
automattic/jetpack-sync Version ^1.30 | — | — |
automattic/jetpack-error Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.