Mar 3, 2026 at 7:21 AM 6 signals analysed No manual reviews · fully automatedTrust Signal Breakdown medium 23 sub-signals across 6 dimensions
Vulnerability & Safety ×0.25 0.0 CVEs, dependency health, and supply chain integrity
0 of 3 sub-signals with data
Known CVEs no data —
Weight redistributed to sub-signals with data
Dependency Health no data —
Weight redistributed to sub-signals with data
Supply Chain no data —
Weight redistributed to sub-signals with data
Operational Reliability ×0.15 4.8 Uptime, latency, error rates, and incident history
4 of 4 sub-signals with data
Uptime 35% 5.0
100.00% over 4 checks
via Health checks
Response Latency 25% 5.0
p99: 164ms, p50: 159ms
via Health checks
Error Rate 20% 5.0
0.00% error rate (0/4)
via Health checks
Incident History 20% 4.0
1 incidents in last 90 days
via Incidents table
Maintenance Activity ×0.15 3.4 Commit recency, release cadence, issue response, CI/CD
4 of 4 sub-signals with data
Commit Recency 30% 5.0
via GitHub
Release Cadence 25% 4.0
via GitHub
Issue Response 20% 2.0
via GitHub
CI/CD Presence 25% 2.0
via GitHub Actions
Adoption ×0.15 2.0 Downloads, stars, dependents, and growth trajectory
1 of 4 sub-signals with data
Download Volume no data —
Weight redistributed to sub-signals with data
GitHub Stars 100% 2.0
380 stars
via GitHub
Dependent Packages no data —
Weight redistributed to sub-signals with data
Growth Trend no data —
Weight redistributed to sub-signals with data
Transparency ×0.15 3.0 License, documentation, security policy, changelog
4 of 4 sub-signals with data
Open Source 30% 2.0
Public repo but no license detected
via GitHub
Documentation 25% 4.0
Good README (>2000 bytes with examples)
via GitHub
Security Policy 20% 2.0
No SECURITY.md found
via GitHub
Changelog 25% 4.0
Releases exist but no CHANGELOG.md
via GitHub
Publisher Trust ×0.15 0.0 Track record, org maturity, community standing
0 of 4 sub-signals with data
Track Record no data —
Weight redistributed to sub-signals with data
Org Maturity no data —
Weight redistributed to sub-signals with data
Community Standing no data —
Weight redistributed to sub-signals with data
Cross-Platform no data —
Weight redistributed to sub-signals with data
About this scoreScored across 23 sub-signals in 6 dimensions Scoring engine v1 (beta) — actively being expanded Phase 1: Core sub-signal architecture (live) Phase 2: Permission scope & expanded collection (in progress)
Trust Assessment AI Assessment
EVA is an AI-assisted penetration testing agent that enhances offensive security workflows by providing structured attack guidance, contextual analysis, and multi-backend AI integration.
Package Availability (30d)
100.00%
p50: 159ms · p99: 164ms
Avg Latency
154ms
averaged across 30d health checks
Weekly Downloads
—
no package registry data
Transparency & Compliance 2/5 passed
Incidents & Alerts last 90 days
Score History 5 snapshots
Feb 23 Mar 1
Data Sources 6 indexed
◎
OSV.dev CVE database · vulnerability scanning for npm & PyPI packages
◈
GitHub API Commits, issues, releases, repo metadata, transparency checks
⬡
npm Registry Package metadata, weekly downloads, maintainers, dependencies
⬡
PyPI Package metadata, weekly downloads, dependency tree
△
HTTP Health Checks 15-min pings · uptime, latency, status monitoring
◎
PyPI Stats Download statistics and trends
Version History
VERSION RELEASED
Are you the publisher? Claim this profile to unlock deeper evaluation, real-time monitoring, and trust signals that help agents discover your service.
Claim Provider Report Issue
Share this Trust Score Generate a scorecard image optimised for X, LinkedIn and other social platforms.
⬇ Download Score Card