All templates

Automated npm Package Maintenance Reviews

Every Monday, WebRun signs into npm, reviews each package you publish for how long since the last version, whether the readme, repository link and licence fields are complete, and whether any deprecation notice is showing, opens a Trello maintenance card per package that needs work, and sends you the summary on WhatsApp.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 npm review your published packages
2 Trello open a maintenance card
3 WhatsApp send the weekly summary
In short

How do I keep my published npm packages maintained?

WebRun signs into npm every Monday and reviews each package you publish for stale versions, missing readme, repository or licence fields, and deprecation notices. It opens a Trello maintenance card per flagged package with its download figure and sends you a WhatsApp summary of what needs work.

  • Stale packages surface every Monday rather than after a bug report
  • Missing readme, repository, and licence fields get caught and ticketed
  • The most downloaded packages get fixed first

Built for open source maintainers · JavaScript developers · platform teams · engineering leads

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens www.npmjs.com/login in a real browser with your saved login - no setup, no API keys.

  2. 1
    npm - review your published packages
    npmjs.com
    WebRun in npm: review your published packages
    WebRun opens npm to review your published packages.
    • Sign into npm and open the list of packages you publish
    • For each package read the latest version, its publish date, and the weekly download figure
    • Check the package page for a readme, a repository link, a licence, and any deprecation notice
    • Flag packages with no new version for more than 6 months or a missing metadata field
    • Only read. Never publish a version, deprecate a package, or change access

    Done when Every published package has a last-publish date and a metadata check.

  3. 2
    Trello - open a maintenance card
    trello.com
    WebRun in Trello: open a maintenance card
    WebRun opens Trello to open a maintenance card.
    • Open your maintenance board in Trello
    • Create one card per flagged package named for the package and the reason it was flagged
    • List the missing fields and the months since the last publish in the description
    • Add the weekly download figure so the busiest packages can be prioritised
    • Update rather than duplicate a card that already exists, and archive cards for packages now healthy

    Done when Every flagged package has one current Trello maintenance card.

  4. 3
    WhatsApp - send the weekly summary
    whatsapp.com
    WebRun in WhatsApp: send the weekly summary
    WebRun opens WhatsApp to send the weekly summary.
    • Send yourself a short weekly summary on WhatsApp
    • Show how many packages are healthy and how many were flagged
    • Name the three flagged packages with the highest download figures first
    • Send a single all-clear line when nothing needs attention

    Done when You have this week's package maintenance summary in WhatsApp.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
www.npmjs.com/login
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Package maintenance summary · WhatsApp
OutputWhat each run produces - A weekly maintenance review of your published npm packages, flagging stale versions and missing metadata, with a Trello card for each.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it publish or deprecate a package?

No. WebRun only reads your npm package pages. It never publishes a version, deprecates a package, changes access, or edits any package setting. Every release stays a manual action.

What makes a package get flagged?

No new version for more than six months, or a missing readme, repository link, or licence field, or a deprecation notice showing on the page. You can change the staleness window.

How does it help me prioritise?

Each Trello card carries the package's weekly download figure, and the WhatsApp summary names the three most downloaded flagged packages first, so the widely used ones get attention before the quiet ones.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.