Mar 18, 2026 at 4:01 AM 6 signals analysed No manual reviews · fully automatedTrust Signal Breakdown high 23 sub-signals across 6 dimensions
Vulnerability & Safety ×0.25 4.3 CVEs, dependency health, and supply chain integrity
3 of 3 sub-signals with data
Known CVEs 40% 3.5
22 CVE(s) found — 0 unpatched
via OSV.dev
Dependency Health 30% 5.0
5 dependencies (minimal)
via npm / PyPI
Supply Chain 30% 4.8
21 transitive CVEs found (penalty: -0.25)
via npm provenance
Operational Reliability ×0.15 3.8 Uptime, latency, error rates, and incident history
4 of 4 sub-signals with data
Uptime 35% 5.0
99.90% over 1000 checks
via Health checks
Response Latency 25% 4.0
p99: 340ms, p50: 122ms
via Health checks
Error Rate 20% 4.0
0.10% error rate (1/1000)
via Health checks
Incident History 20% 1.0
30 incidents in last 90 days
via Incidents table
Maintenance Activity ×0.15 5.0 Commit recency, release cadence, issue response, CI/CD
3 of 4 sub-signals with data
Commit Recency 37% 5.0
via GitHub
Release Cadence 31% 5.0
via GitHub
Issue Response no data —
Weight redistributed to sub-signals with data
CI/CD Presence 31% 5.0
via GitHub Actions
Adoption ×0.15 5.0 Downloads, stars, dependents, and growth trajectory
3 of 4 sub-signals with data
Download Volume 43% 5.0
53,994,880 weekly downloads
via npm / PyPI
GitHub Stars 36% 5.0
129,950 stars
via GitHub
Dependent Packages no data —
Weight redistributed to sub-signals with data
Growth Trend 21% 5.0
+2474.2% week-over-week
via npm
Transparency ×0.15 4.5 License, documentation, security policy, changelog
4 of 4 sub-signals with data
Open Source 30% 5.0
Public repo with OSI-approved license (mit)
via GitHub
Documentation 25% 4.0
Good README (>2000 bytes with examples)
via GitHub
Security Policy 20% 5.0
SECURITY.md inherited from org .github repo
via GitHub
Changelog 25% 4.0
Releases exist but no CHANGELOG.md
via GitHub
Publisher Trust ×0.15 4.8 Track record, org maturity, community standing
4 of 4 sub-signals with data
Track Record 30% 5.0
Internal: 5.0 (14 services), External: 4.5 (17065 followers, 35633 stars)
via Fabric index
Org Maturity 30% 4.5
Organization, 3.0 years old
via GitHub
Community Standing 20% 5.0
229 public repositories
via GitHub
Cross-Platform 20% 5.0
Present on 3 platform(s): github, npm, pypi
via Registry scan
About this scoreScored across 23 sub-signals in 6 dimensions Scoring engine v1 (beta) — actively being expanded Phase 1: Core sub-signal architecture (live) Phase 2: Permission scope & expanded collection (in progress)
Trust Assessment AI Assessment
LangChain is a TypeScript framework published by LangChain under MIT license for building LLM-powered applications through composable components and third-party integrations. The package shows strong adoption with 54.2M weekly downloads and active maintenance from 8 maintainers, though 22 historical CVEs indicate the framework has required ongoing security attention. The minimal dependency footprint of 5 packages reduces supply chain exposure, making this a widely-trusted choice for AI application development.
Generated by Fabric AI · Mar 4, 2026 at 10:50 PM
Service Health (30d)
99.90%
p50: 122ms · p99: 340ms
Avg Latency
137ms
averaged across 30d health checks
Weekly Downloads
54.0M+999%
npm + PyPI weekly
Transparency & Compliance 4/5 passed
Incidents & Alerts last 90 days
Showing 6 of 20 events Show more →
Score History 90 snapshots
Feb 21 Mar 5
Community & Ecosystem adoption signals
54.0M
Weekly Downloads
npm + PyPI
Supply Chain & Dependencies trust chain
Showing 6 of 24 dependencies Show more →
Data Sources 6 indexed
◎
OSV.dev CVE database · vulnerability scanning for npm & PyPI packages
◈
GitHub API Commits, issues, releases, repo metadata, transparency checks
⬡
npm Registry Package metadata, weekly downloads, maintainers, dependencies
⬡
PyPI Package metadata, weekly downloads, dependency tree
△
HTTP Health Checks 15-min pings · uptime, latency, status monitoring
◎
PyPI Stats Download statistics and trends
Version History score per release
VERSION RELEASED SCORE DELTA
Showing 6 of 10 releases Show more →
Are you the publisher? Claim this profile to unlock deeper evaluation, real-time monitoring, and trust signals that help agents discover your service.
Claim Provider Report Issue
Share this Trust Score Generate a scorecard image optimised for X, LinkedIn and other social platforms.
⬇ Download Score Card