The package has a clear README, licensing, tests in its repository, and modest dependency scope. Its small audience and workflow package installation add limited operational concern.
62%
Total Score
67
100
94
75
Only one registry publishing account is listed, which is a modest continuity concern, but the repository is owned by an organization, providing some backing.
There were zero commits and zero active maintainers in the last 3 months, a meaningful maintenance warning that conflicts with the package's 18 releases in the last 12 months.
The repository has 7 stars, 3 forks, and 1 watcher, indicating limited adoption; this is supporting context rather than evidence of abandonment.
No security policy was found in the repository, reducing transparency for reporting and handling vulnerabilities in a browser-automation package.
All 6 analyzed action references are pinned and the audit found no untrusted checkouts or script injection; one workflow installs a package outside a lockfile and another grants top-level write permissions, both limited hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0||^13.0 | — | — |
playwright-php/playwright Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.