CANARY is a research prototype that collects Jenkins security advisories and produces an explainable baseline risk score for plugins.