Clear licensing, release notes, and a security policy make the project easier to evaluate. One workflow grants top-level write access, although the audit found no untrusted checkout, script injection, or unpinned actions.
88%
Total Score
100
100
94
100
Composer is used for builds, but no repository security-scanning tool was detected. The security policy and clean workflow audit provide some compensating transparency, so this is only a minor concern.
All three workflows were analyzed successfully: actions are pinned, no untrusted checkout or script injection was found, and two workflows use read-only permissions. One autorelease workflow has top-level write access, which is a mild permissions concern without an identified untrusted sink.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
automattic/jetpack-logo Version ^3.0.5 | — | — |
automattic/jetpack-autoloader Version ^5.0.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.