← Home

@webflow/webflow-cli

The Webflow CLI is a command-line interface that allows you to interact with various Webflow developer products, including Devlink and Designer Extensions.

25
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

callmevladwebflow-botfederico.fioriniiammerrick-wfalbert.changwf-guillermozmcnellis_webflow

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-dropped AI (source-diff): Size drop consistent with moving from bundled to unbundled dist; not indicative of malicious stub replacement for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): Webflow's official CLI managed by webflow-bot; team roster changes are expected for this org-owned package. ai
publish-pattern dormant-publish AI (publish-pattern): Official Webflow-scoped CLI with 128 versions and 77.8k downloads; gap explained by major feature work. ai
publish-pattern new-deps-added AI (publish-pattern): jsdom is a well-established package; addition is consistent with CLI HTML-processing use cases. ai
phantom-deps phantom-dep:inquirer AI (phantom-deps): inquirer is declared and used indirectly via config parsing; expected for CLI tools with interactive prompts. ai
provenance no-provenance AI (provenance): Provenance attestation is not yet standard practice; absence is not a security concern for this mature package. ai
dependencies unvetted-dep:webflow-api AI (dependencies): webflow-api is Webflow's own official SDK; its use in the Webflow CLI is expected and first-party. Not a security concern. ai
phantom-deps phantom-dep:jsonc-parser AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. ai
bogus-package bogus-package AI (bogus-package): Established @webflow scoped package with 42k weekly downloads and 113 versions. Heuristics are false positives for this org's CLI tool. ai
phantom-deps phantom-dep:filenamify AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. ai
phantom-deps phantom-dep:env-paths AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. ai
phantom-deps phantom-dep:css-tree AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. ai
phantom-deps phantom-dep:ora AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. ai

Versions (showing 25 of 25)

Version Deps Published
2.0.0 46 / 23
1.20.0 48 / 25
1.15.1 47 / 25
1.15.0 47 / 25
1.14.0 47 / 25
1.13.1 47 / 25
1.12.6 45 / 25
1.12.4 45 / 25
1.12.3 45 / 25
1.12.0 45 / 25
1.9.0 45 / 25
1.8.51 45 / 25
1.8.49 45 / 25
1.8.48 45 / 26
1.8.47 45 / 26
1.8.39 43 / 26
1.8.32 42 / 25
1.8.9 32 / 24
1.8.1 28 / 21
1.8.0 28 / 21
1.7.4 10 / 12
1.7.3 2 / 12
1.7.2 1 / 12
1.7.1 1 / 12
1.7.0 1 / 12

v2.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.15.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.51

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.49

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.48

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.47

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.39

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.32

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.