Package Health

automattic/jetpack-options

It is clearly licensed, documented, and backed by a matching Automattic repository. Its small dependency surface and security policy help, but workflow permissions are under-specified and security scanning is absent.

Latest v2.0.1PackagistPackagist

15%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

56

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

The entire package is marked abandoned on Packagist, with automattic/jetpack-connection listed as a replacement; this directly makes depending on the package unsuitable without a compelling compatibility need.

Release historydanger

The package has 45 releases over more than 7 years, but it has had no release in the last 12 months and its latest release was over 2 years ago, indicating abandonment risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the archived state and indicating no current maintenance capacity.

Repository archiveddanger

The linked repository is archived and was last pushed over 2 years ago, so ongoing fixes and maintenance should not be expected.

Dangerous workflowscaution

One of two workflows uses pull_request_target, which warrants care because that trigger can expose privileged workflow behavior to pull requests, although no untrusted checkout or script injection was detected.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
automattic/jetpack-connection
Version ^2.9.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform