Is It Dead Yet? dependency vitals

cacheablenpm

Signals · last 1 check

Commits 90d
48
Open issues
0
Unanswered
0
Contributors
5
State history 1
WhenChange
2026-09-03 first verdict: active
Supply-chain history 1
  1. account hijacked 2026-08 2.5.1

    The maintainer’s GitHub account was compromised and malicious commits to main triggered releases, with valid provenance, whose pre-install step stole npm, GitHub, cloud and Vault secrets and republished every package the stolen tokens could reach.

    Commits deleted and versions removed; the worm reached over 2,200 versions across 444 packages.

    Source: Aikido, Datadog Security Labs and Sonatype analyses, 4–5 August 2026. History, not a warning about today — the verdict above is about maintenance now.

Badge

maintenance: active

Drop this in your README. It re-renders itself as the verdict changes.

[![maintenance](https://isitdeadyet.dev/badge/npm/cacheable.svg)](https://isitdeadyet.dev/npm/cacheable)

Watch it

Get told when cacheable changes state, changes licence, or is deprecated — instead of finding out during an incident.

Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.