@webflow/webflow-cli
The Webflow CLI is a command-line interface that allows you to interact with various Webflow developer products, including Devlink and Designer Extensions.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-dropped | AI (source-diff): Size drop consistent with moving from bundled to unbundled dist; not indicative of malicious stub replacement for this package. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Webflow's official CLI managed by webflow-bot; team roster changes are expected for this org-owned package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Official Webflow-scoped CLI with 128 versions and 77.8k downloads; gap explained by major feature work. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): jsdom is a well-established package; addition is consistent with CLI HTML-processing use cases. | ai | |
| phantom-deps | phantom-dep:inquirer | AI (phantom-deps): inquirer is declared and used indirectly via config parsing; expected for CLI tools with interactive prompts. | ai | |
| provenance | no-provenance | AI (provenance): Provenance attestation is not yet standard practice; absence is not a security concern for this mature package. | ai | |
| dependencies | unvetted-dep:webflow-api | AI (dependencies): webflow-api is Webflow's own official SDK; its use in the Webflow CLI is expected and first-party. Not a security concern. | ai | |
| phantom-deps | phantom-dep:jsonc-parser | AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established @webflow scoped package with 42k weekly downloads and 113 versions. Heuristics are false positives for this org's CLI tool. | ai | |
| phantom-deps | phantom-dep:filenamify | AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:env-paths | AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:css-tree | AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:ora | AI (phantom-deps): Bundled CLI tool; deps referenced in build/config files rather than directly imported. Stable false positive for this package. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 2.0.0 | 46 / 23 | |
| 1.20.0 | 48 / 25 | |
| 1.15.1 | 47 / 25 | |
| 1.15.0 | 47 / 25 | |
| 1.14.0 | 47 / 25 | |
| 1.13.1 | 47 / 25 | |
| 1.12.6 | 45 / 25 | |
| 1.12.4 | 45 / 25 | |
| 1.12.3 | 45 / 25 | |
| 1.12.0 | 45 / 25 | |
| 1.9.0 | 45 / 25 | |
| 1.8.51 | 45 / 25 | |
| 1.8.49 | 45 / 25 | |
| 1.8.48 | 45 / 26 | |
| 1.8.47 | 45 / 26 | |
| 1.8.39 | 43 / 26 | |
| 1.8.32 | 42 / 25 | |
| 1.8.9 | 32 / 24 | |
| 1.8.1 | 28 / 21 | |
| 1.8.0 | 28 / 21 | |
| 1.7.4 | 10 / 12 | |
| 1.7.3 | 2 / 12 | |
| 1.7.2 | 1 / 12 | |
| 1.7.1 | 1 / 12 | |
| 1.7.0 | 1 / 12 |
v2.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.15.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.13.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.12.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.12.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.12.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.12.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.9.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.51
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.49
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.48
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.47
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.39
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.