It has a clear MIT license, a useful README, repository tests, and Dependabot scanning. Its small dependency set and matching organization-backed repository are reassuring, though the workflow audit still finds high-confidence bot-condition and package-installation issues.
58%
Total Score
83
100
94
50
The package has had no release in over 18 months and no releases in the last 12 months, which points to slowing maintenance despite eight releases since October 2024.
There were zero commits and zero active maintainers in the last three months, reinforcing the release-history evidence of a currently inactive project.
No security policy is present in the repository, which is a transparency gap for a package that renders application data through Chromium, though it is not a severe risk by itself.
All four workflows were analyzed, but all 10 action references are unpinned and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow; a low-confidence-independent adhoc package install is an additional hygiene concern. The pull_request_target trigger has no untrusted checkout or script-injection sink, so it is not dangerous on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
chrome-php/chrome Version ^1.11 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
spatie/temporary-directory Version ^2.2.1 | — | — |
spatie/laravel-package-tools Version ^1.16.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.