A high-level API to control headless Chrome over the DevTools Protocol
94%
Total Score
healthy
Long-lived, actively maintained release with strong repository, licensing, provenance, and workflow hygiene.
The package uses postinstall and prepack scripts, and its README explains that installation downloads a compatible browser. This is an expected part of Puppeteer's operation but requires care in restricted or locked-down builds.
| Title | Versions | Severity |
|---|---|---|
CVE-2019-5786 puppeteer is vulnerable to Use After Free in versions 0.0.0 - 1.13.0. | 0.0.0 - 1.13.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
lilconfig Version ^3.1.3 | — | — |
chromium-bidi Version 157.0.8090-0 | — | — |
puppeteer-core Version 25.13.0 | — | — |
devtools-protocol Version 0.0.1696802 | — | — |
@puppeteer/browsers Version 3.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.