@langchain/core logo

@langchain/core

#12 · by LangChain
4.61/ 5.00
trustedBeta
Mar 20, 2026 at 6:30 AM6 signals analysedNo manual reviews · fully automated
Trust Signal Breakdown
high23 sub-signals across 6 dimensions

CVEs, dependency health, and supply chain integrity

3 of 3 sub-signals with data

Known CVEs40%4.4

7 CVE(s) found — 0 unpatched

via OSV.dev

Dependency Health30%5.0

10 dependencies (minimal)

via npm / PyPI

Supply Chain30%4.8

16 transitive CVEs found (penalty: -0.25)

via npm provenance

Uptime, latency, error rates, and incident history

4 of 4 sub-signals with data

Uptime35%5.0

99.90% over 1000 checks

via Health checks

Response Latency25%4.0

p99: 304ms, p50: 126ms

via Health checks

Error Rate20%4.0

0.10% error rate (1/1000)

via Health checks

Incident History20%2.0

5 incidents in last 90 days

via Incidents table

Commit recency, release cadence, issue response, CI/CD

4 of 4 sub-signals with data

Commit Recency30%5.0

via GitHub

Release Cadence25%5.0

via GitHub

Issue Response20%2.0

via GitHub

CI/CD Presence25%5.0

via GitHub Actions

Downloads, stars, dependents, and growth trajectory

3 of 4 sub-signals with data

Download Volume43%5.0

25,620,606 weekly downloads

via npm / PyPI

GitHub Stars36%5.0

17,261 stars

via GitHub

Dependent Packagesno data

Weight redistributed to sub-signals with data

Growth Trend21%5.0

+632.6% week-over-week

via npm

License, documentation, security policy, changelog

4 of 4 sub-signals with data

Open Source30%5.0

Public repo with OSI-approved license (mit)

via GitHub

Documentation25%5.0

Docs site present with comprehensive README (>2000 bytes + examples)

via GitHub

Security Policy20%5.0

SECURITY.md inherited from org .github repo

via GitHub

Changelog25%4.0

Releases exist but no CHANGELOG.md

via GitHub

Track record, org maturity, community standing

4 of 4 sub-signals with data

Track Record30%5.0

Internal: 5.0 (14 services), External: 4.5 (17186 followers, 38583 stars)

via Fabric index

Org Maturity30%4.5

Organization, 3.1 years old

via GitHub

Community Standing20%5.0

230 public repositories

via GitHub

Cross-Platform20%5.0

Present on 3 platform(s): github, npm, pypi

via Registry scan

About this score
Scored across 23 sub-signals in 6 dimensionsScoring engine v1 (beta) — actively being expandedPhase 1: Core sub-signal architecture (live)Phase 2: Permission scope & expanded collection (in progress)
Trust AssessmentAI Assessment

@langchain/core is the foundational framework package from LangChain under MIT license, providing core abstractions for building AI applications with language models. The package shows strong adoption with 25.8M weekly downloads and active maintenance by 12 maintainers, though 7 historical CVEs have been identified. The 10 dependencies and established publisher reputation indicate low risk for production use in AI/ML workflows.

Generated by Fabric AI · Mar 4, 2026 at 10:51 PM

Service Health (30d)
99.90%
p50: 126ms · p99: 304ms
Avg Latency
142ms
averaged across 30d health checks
Weekly Downloads
25.6M+633%
npm + PyPI weekly
Transparency & Compliance5/5 passed
Incidents & Alertslast 90 days
Mar 4Critical CVE detected — patched in v1.2.54.76
Mar 4Trust score increased by 1.524.76
Mar 1Trust score decreased by 1.213.24
Feb 25Trust score increased by 0.954.45
Feb 21@langchain/core added to Trust Index2.67
Showing 5 of 5 events
Score History90 snapshots
5.003.752.501.250.00
Feb 21Feb 28
Community & Ecosystemadoption signals
25.6M
Weekly Downloads
npm + PyPI
10
Releases
on GitHub
Supply Chain & Dependenciestrust chain
@cfworker/json-schema
npm · ^4.0.2
@standard-schema/spec
npm · ^1.1.0
ansi-styles
npm · ^5.0.0 · 1 CVE1L
camelcase
npm · 6
decamelize
npm · 1.2.0 · 1 CVE1H
js-tiktoken
npm · ^1.0.12
Showing 6 of 18 dependencies
Data Sources6 indexed
Version Historyscore per release
VERSIONRELEASEDSCOREDELTA
langchain@1.2.35Mar 18, 20264.45
@langchain/anthropic@1.3.25Mar 18, 20264.45
@langchain/core@1.1.34Mar 18, 20264.45
langchain@1.2.34Mar 17, 20264.45
@langchain/google-webauth@2.1.26Mar 17, 20264.45
@langchain/openrouter@0.1.7Mar 17, 20264.45
Showing 6 of 10 releases

Are you the publisher?

Claim this profile to unlock deeper evaluation, real-time monitoring,
and trust signals that help agents discover your service.

Share this Trust Score

Generate a scorecard image optimised for X, LinkedIn and other social platforms.

⬇ Download Score Card