It is clearly licensed, documented, and backed by a matching Automattic repository. Its small dependency surface and security policy help, but workflow permissions are under-specified and security scanning is absent.
15%
Total Score
50
56
75
The entire package is marked abandoned on Packagist, with automattic/jetpack-connection listed as a replacement; this directly makes depending on the package unsuitable without a compelling compatibility need.
The package has 45 releases over more than 7 years, but it has had no release in the last 12 months and its latest release was over 2 years ago, indicating abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the archived state and indicating no current maintenance capacity.
The linked repository is archived and was last pushed over 2 years ago, so ongoing fixes and maintenance should not be expected.
One of two workflows uses pull_request_target, which warrants care because that trigger can expose privileged workflow behavior to pull requests, although no untrusted checkout or script injection was detected.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
automattic/jetpack-connection Version ^2.9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.