lighthouse-runner

Warn

Audited by Socket on Jun 29, 2026

1 alert found:

Anomaly
AnomalyLOW
package.json

The package's install-time actions are primarily to build sources and to run Playwright's installer for Chromium. This is not overtly malicious, but it carries moderate supply-chain and execution risk: npx invocation during postinstall allows remote code execution if the registry or npx behavior is subverted, and Playwright's installation downloads and runs additional software (browser binaries). If you trust the upstream packages (playwright, tsdown) and your npm registry, this is expected behavior for a Playwright-based tool. If you require a stricter security posture, avoid automatic postinstall network installs, audit tsdown and playwright package contents, or run installs in an isolated environment.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Jun 29, 2026, 02:33 AM
Package URL
pkg:socket/skills-sh/naporin0624%2Fclaude-web-audit-plugins%2Flighthouse-runner%2F@9954328235713e194aa66e2416500893258ec3b8395515c0b6716c041b4a8a23
Security Audit — socket — lighthouse-runner