[1]: https://github.com/greenpau/caddy-security/issues?q=is%3Aiss...
I'll consoder stable code fine without new releases for years even, but security issues? Responses and fixes need to be measured in days, not months.
(Some may say "but what about"..., and note all rhe conditions I listed above. Publicly disclosed + timefame. Doesn't matter who it is, big or small, 6 months means the software maintainers show no serious commitment to security, and one should run to other solutions.)
Better know that up front, than get popped and think "What happened?".
That’s entirely on the idiot that assumes a similarity in name means the project is maintained by the same owner.
If you put your work in the open, advertise it as an officially supported solution, and advertise it as secure, it had better be supported and secure. You can't just put out broken software and hide behind "but you didn't pay for it so who cares." Even worse when the attitude is "it's not my fault, go fix it yourself and submit a PR."
If that is the intent, why even open source it in the first place and tell people to use it. Just keep the code private and use it for yourself.
Over the last decade I have written hundreds of thousands of lines of code for personal projects that will never see the light of day, precisely for this reason. It's not production-quality software, and it would be horrendously irresponsible for me to put it out in the open, advertise it, and tell people to use it, compromising the security of their homelabs (or worse, enterprise deployments).
the point of free software(tm) is gaining benefit from cooperation and community, and nobody is obligated to do anything.