Package Health

chrome-launcher

Launch latest Chrome with the Devtools Protocol port open

Latest 1.2.2NPMNPM

76%

Total Score

healthy

Healthy, backed by a current release and GoogleChrome repository despite no commits in three months.

Are you affected? Scan for Free

Health Score Breakdown

Repo commit activitycaution

There were no commits and no active maintainers in the repository during the last three months. This is the main maintenance concern, although the current release and recent repository push provide some counterweight.

Repo toolingcaution

The project uses TypeScript and npm build tooling, but no security scanning tools were detected. The build setup is positive, while the missing scanning is a modest hygiene gap.

Security policycaution

No security policy was found in the linked repository, reducing the transparency of vulnerability reporting and response expectations.

Workflow auditcaution

All three workflows were analyzed, but all nine action references are unpinned and one workflow grants top-level write permissions. The audit also found a high-severity cache-poisoning pattern with low confidence and a high-confidence ad hoc package install; these are workflow hygiene concerns rather than standalone disqualifiers.

Vulnerabilities

TitleVersionsSeverity
CVE-2020-7645
chrome-launcher is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.0.0 - 0.13.2.
0.0.0 - 0.13.2
Critical

Package versions

Direct Dependencies

DependencyLast ReleaseScore
is-wsl
Version ^2.2.0
—
—
@types/node
Version *
—
—
lighthouse-logger
Version ^2.0.1
—
—
escape-string-regexp
Version ^4.0.0
—
—

Weekly Downloads

Info

Last Published
11 days ago
Created
9 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform