A long project history, stable versioning, typed sources, and repository tests support continued use. The lack of a security policy and security scanning leaves less evidence for maintaining a server dependency.
68%
Total Score
70
100
89
50
50
No build attestation or trusted-publisher identity is present, reducing publication transparency, but this is not by itself evidence of an unhealthy release.
A prepare lifecycle script runs during installation or publishing, adding build behavior that consumers should account for, though this alone is not a severe concern.
Only one registry account has publish access, which is a concentration concern, although the linked repository is owned by an organization that can provide backing.
The package has existed for about 9 years with 105 releases and a release within the last 2 months, but only one release appeared in the last 12 months, indicating limited recent release cadence.
All 19 commits in the last 3 months came from one contributor, creating a meaningful continuity risk; organization ownership provides only partial compensation.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-912749 webdav-server is vulnerable to Improper Access Control in versions 2.0.0 - 2.6.2. | 2.0.0 - 2.6.2 | High |
AIKIDO-2026-593413 webdav-server is vulnerable to Path Traversal in versions 2.0.0 - 2.6.2. | 2.0.0 - 2.6.2 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
mime-types Version ^2.1.18 | — | — |
xml-js-builder Version ^1.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.