A Puppeteer bridge for PHP, supporting the entire API.
43%
Total Score
unhealthy
Risky: no releases or commits since September 2022, leaving this stable-looking package effectively unmaintained.
The package has only two releases, both published in September 2022, with none in the last four years. This strongly suggests the release line is no longer maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The package defines a post-install Composer script. Install-time execution adds some supply-chain exposure, although this signal alone does not show that the script is unsafe.
Only one registry account has publish access. That is a thin publishing base for a package already showing no recent release or commit activity.
The linked repository has no security policy. This reduces transparency for reporting and handling security issues, especially for a package that launches browser-related resources.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0|^3.0 | — | — |
nesk/rialto Version ^1.2.0 | — | — |
vierbergenlars/php-semver Version ^3.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.