The package is licensed, not deprecated, and backed by an organization with a clear source repository. It has a changelog and read-only workflow permissions, but one workflow action is unpinned and repository security scanning is absent.
62%
Total Score
67
100
81
100
The repository recorded zero commits and zero active maintainers during the last three months. This conflicts with the strong registry release cadence and indicates a real maintenance concern.
There were no new or closed issues or pull requests in the last month. With no recent commits, this provides little evidence of active community or maintainer engagement.
The repository has only 1 star, 1 fork, and 2 watchers. Low popularity is supporting evidence rather than a verdict, but it offers little independent evidence of maturity or community support.
Composer is used for builds, but no repository security-scanning tools were detected. That is a hygiene gap rather than evidence that the release is unsafe.
This release is not a prerelease, but it remains on major version 0, so compatibility expectations are somewhat less mature than for a stable major release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
automattic/jetpack-jitm Version ^4.3.35 | — | — |
automattic/jetpack-plans Version ^0.11.6 | — | — |
automattic/jetpack-stats Version ^0.19.1 | — | — |
automattic/jetpack-status Version ^6.1.4 | — | — |
automattic/jetpack-constants Version ^3.0.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.