The repository has tests, a clear MIT license, and a security policy. Its workflow leaves all seven action references unpinned and the project has no security scanning, so pinning and review matter before production use.
68%
Total Score
100
100
81
75
The package is only 2 days old, with 3 releases and a median interval of about 1 day, so there is too little history to establish long-term maintenance reliability.
The repository has 0 stars, forks, and watchers. This is weak supporting evidence, but the project is only 2 days old, so it does not independently indicate poor health.
Composer build tooling is present, but no security scanning tools were detected. That leaves a meaningful maintenance and transparency gap for a package that invokes Chromium processes.
The single workflow was fully analyzed with no untrusted checkout, injection, or high-severity findings, but all 7 of its action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.