Factotum V8 - Cme Module
58%
Total Score
caution
Usable with caveats: release activity stopped after a brief burst and the repository does not clearly identify this package.
A post-autoload-dump lifecycle script runs during installation. This is worth noting for reproducibility, but the signal provides no evidence that it is unsafe or unusually invasive.
The package has only 3 releases, all within a brief burst, and the latest release was nearly five months ago; this weakens evidence of ongoing maintenance.
The repository name does not match the package and its README does not mention wave8/factotum-cms, so the package-to-source relationship is not clearly established; organization backing partly offsets this concern.
The repository has 0 stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external adoption signal for this young package.
The repository has no security policy, leaving disclosure and response expectations undocumented; this is a transparency gap for a CMS module.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kalnoy/nestedset Version ^7.0 | — | — |
wave8/factotum-base Version ^1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.