It has clear licensing, a security policy, and a complete-looking published artifact. Those positives do not offset the lack of current maintenance and the package’s withdrawn status.
12%
Total Score
25
50
75
Packagist marks the entire package as abandoned, with no replacement provided; this is a severe adoption risk for a dependency.
The repository had zero commits and zero active maintainers in the past 3 months, providing no evidence of ongoing maintenance.
The linked Automattic repository is archived, which signals that active development has ended even though it was pushed recently.
One of two workflows uses pull_request_target, creating elevated workflow risk, although no untrusted checkout or script-injection pattern was detected.
The package is backed by the Automattic organization, which provides project context, but organizational ownership does not compensate for the archived state and absent recent activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
automattic/jetpack-assets Version ^4.3.2 | — | — |
automattic/jetpack-status Version ^6.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.