Launch latest Chrome with the Devtools Protocol port open
76%
Total Score
healthy
Healthy, backed by a current release and GoogleChrome repository despite no commits in three months.
There were no commits and no active maintainers in the repository during the last three months. This is the main maintenance concern, although the current release and recent repository push provide some counterweight.
The project uses TypeScript and npm build tooling, but no security scanning tools were detected. The build setup is positive, while the missing scanning is a modest hygiene gap.
No security policy was found in the linked repository, reducing the transparency of vulnerability reporting and response expectations.
All three workflows were analyzed, but all nine action references are unpinned and one workflow grants top-level write permissions. The audit also found a high-severity cache-poisoning pattern with low confidence and a high-confidence ad hoc package install; these are workflow hygiene concerns rather than standalone disqualifiers.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-7645 chrome-launcher is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.0.0 - 0.13.2. | 0.0.0 - 0.13.2 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
is-wsl Version ^2.2.0 | — | — |
@types/node Version * | — | — |
lighthouse-logger Version ^2.0.1 | — | — |
escape-string-regexp Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.