The linked project remains active, with 30 commits from 8 contributors in the last three months and a recent release. Workflow references are not pinned, and no security policy or scanning tools were found; use the replacement package for new dependencies.
42%
Total Score
100
81
50
Packagist marks the entire package as abandoned and names chrome-php/chrome as its replacement, which is a serious adoption risk despite the linked repository remaining active.
The project uses Make and Composer, but no security scanning tools were detected, leaving a modest maintenance-hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response.
Both workflows use read-only permissions and the audit found no dangerous patterns, but all 21 action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
monolog/monolog Version ^1.27.1 || ^2.8 || ^3.2 | — | — |
symfony/process Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
chrome-php/wrench Version ^1.9 | — | — |
symfony/filesystem Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.