Skip to content
CAI
Software that uses CAICheck a score

microsoft/playwright-mcp

50.9

Adequate · 28 September 2026

353

lines of production code

JavaScript

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Model Context Protocol (MCP) server package that enables Large Language Models to automate web browsers using Playwright. It provides a CLI and API for managing browser contexts, supporting features like vision, PDF generation, and testing, while allowing configuration for various browser engines and connection methods. The project includes infrastructure for building and publishing multi-architecture Docker images and a test suite to verify core automation capabilities.

Features

Initial release of Playwright MCP server package

This change introduces the initial standalone package for the Playwright Model Context Protocol (MCP) server, providing browser automation capabilities for LLMs. The package includes a CLI entry point (cli.js) and a public API (index.js) for creating MCP connections, along with a comprehensive configuration schema (config.d.ts) that supports browser selection, context isolation, CDP connections, and opt-in tool capabilities (such as vision, PDF, and testing). It also provides a Dockerfile for containerized deployment, a server manifest (server.json) for the MCP Registry, and documentation files (README, CONTRIBUTING, CLAUDE.md, SECURITY.md) to guide installation and contribution.

(repo-wide) · high confidence

New Docker build and publishing scripts for Playwright MCP

Added build and publishing utilities in utils/docker to streamline the creation and distribution of the Playwright MCP Docker image. The new build.sh script supports cross-compilation for both amd64 and arm64 architectures, integrates with an Azure Debian mirror via build arguments, and includes retry logic to handle intermittent QEMU emulation failures on arm64. The publish\_docker.sh script automates the tagging and pushing of images to the Azure Container Registry for stable and canary release channels, creates multi-architecture manifest lists, and attaches end-of-life metadata using the ORAS tool.

utils · high confidence

Test coverage

Initial test suite for browser automation capabilities and CLI

Added a new test suite in the tests directory to verify the MCP server's core functionality. This includes tests for the full list of available browser tools, verification that optional capabilities like PDF saving and vision (mouse actions) are correctly exposed via CLI arguments, and validation of the legacy --vision flag. The suite also covers basic navigation and click interactions, confirms the library's compatibility with CommonJS environments, and introduces a local test server with HTTPS support to facilitate these integration tests.

tests · high confidence

Dependencies

Update to Playwright 1.64.0-alpha and MCP SDK 1.30.0

The project dependencies have been updated to use Playwright 1.64.0-alpha (build 1789764292000) for both runtime and testing, alongside the @modelcontextprotocol/sdk bumped to version 1.30.0. This change also includes an update to the @hono/node-server dependency to version 1.19.14 and @types/node to 24.12.2, ensuring the MCP server aligns with the latest Playwright alpha features and SDK capabilities.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 48 → 51 (+2.8)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 89 → 90 (+0.9)
  • Architecture 65 (new)
  • Maturity 55 → 55 (+0.0)
  • Readiness 31 → 38 (+7.2)
  • Security 69 → 85 (+15.7)
  • Performance 60 (new)

Resolved (34)

  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 14 more

New (13)

  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • Low CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Medium CVE: [GHSA redacted] (package-lock.json)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium vulnerability: [GHSA redacted] (package-lock.json)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No ADRs found
  • PR-triggered workflow without a permissions block
  • Skipped (documented): (unnamed test) (tests/fixtures.ts)

Changes since last survey

  • 17 commits — 16 feature/other, 1 fixes

By area

  • (root) — 9 commits
  • .azure-pipelines/publish.yml — 3 commits
  • .github/workflows — 3 commits
  • .azure-pipelines/publish-docker.yml — 1 commit
  • utils/docker — 1 commit

Notable commits

  • fix: fix(docker): run server under tini to reap orphaned browser processes (#1771)
  • change: Pin GitHub Actions to full-length commit SHAs (#1717)
  • change: chore(deps): bump the github-actions group across 1 directory with 2 updates (#1721)
  • change: chore(deps): bump the github-actions group with 2 updates (#1747)
  • change: chore(docker): track the node LTS base image (#1760)
  • change: chore: mark v0.0.80 (#1730)
  • change: chore: mark v0.0.81 (#1751)
  • change: chore: mark v0.0.82 (#1764)
  • change: chore: roll Playwright to 1.63.0-alpha-2026-08-31 (#1729)
  • change: chore: roll Playwright to 1.64.0-alpha-1789764292000 (#1762)
  • change: chore: roll Playwright to 1.64.0-alpha-2026-09-14 (#1750)
  • change: devops(docker): move docker publishing to Azure Pipelines (#1756)
  • change: devops(docker): route apt through the Azure Debian mirror (#1759)
  • change: devops(docker): warn instead of fail on a non-tag stable build (#1761)
  • change: devops: drop scheduled @next publishing (#1728)
  • change: devops: publish all npm versions via ESRP pipeline (#1727)
  • change: devops: restore npm publishing from GitHub Actions (#1734)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

microsoft/playwright-mcp was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e87bb897e15a6f2af402afb0f10b45eced9e1f9b — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-24a00d372a4b.