The stable release and matching organization-backed repository provide some continuity. Maintenance has stopped for over five years, and the package offers no license information or meaningful documentation for consumers.
38%
Total Score
50
67
50
The package has 13 releases since November 2018, but none in the last five years; the latest release was published in May 2021. This indicates substantial abandonment risk despite an established release history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the repository's last push in May 2021. The long period without observed development materially lowers maintenance confidence.
Neither the package nor the linked repository declares or contains a recognized license. That is a real transparency and adoption concern for a dependency.
The package includes a README, but it is only 17 characters and provides no useful integration guidance. Missing tests and a changelog are normal for published artifacts, while the GitHub release provides some release documentation evidence.
The linked repository has no security policy, leaving no documented path for reporting vulnerabilities. This adds a modest transparency concern alongside the package's otherwise limited maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bonnier/willow-mu-plugins Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.