3.24/ 5.00
trustedBeta
Mar 3, 2026 at 7:21 AM6 signals analysed100 commits (90d)No manual reviews · fully automated
Trust Signal Breakdown
high3 sub-signals across 6 dimensions

CVEs, dependency health, and supply chain integrity

3 of 3 sub-signals with data

Known CVEs40%5.0

No known CVEs

via OSV.dev

Dependency Health30%4.0

23 dependencies (low)

via npm / PyPI

Supply Chain30%5.0

Supply chain analyzed, no transitive CVEs

via npm provenance

Uptime, latency, error rates, and incident history

0 of 0 sub-signals with data

Commit recency, release cadence, issue response, CI/CD

0 of 0 sub-signals with data

Downloads, stars, dependents, and growth trajectory

0 of 0 sub-signals with data

License, documentation, security policy, changelog

0 of 0 sub-signals with data

Track record, org maturity, community standing

0 of 0 sub-signals with data

About this score
Scored across 3 sub-signals in 6 dimensionsScoring engine v1 (beta) — actively being expandedPhase 1: Core sub-signal architecture (live)Phase 2: Permission scope & expanded collection (in progress)
Trust AssessmentAI Assessment

Mastra is a framework for building AI-powered applications and agents with a modern TypeScript stack.

Package Availability (30d)
100.00%
p50: 186ms · p99: 223ms
Avg Latency
187ms
averaged across 30d health checks
Weekly Downloads
457.4k-11%
npm weekly
Transparency & Compliance3/6 passed
Open Source CodePublic repository on GitHub
OSI LicenseNo recognized open-source license
DocumentationREADME with examples/code blocks
SECURITY.mdNo security policy found
API DocumentationOpenAPI spec or docs directory found
Model / System CardNo model card found
Incidents & Alertslast 90 days
Mar 1Trust score decreased by 0.903.24
Feb 25Trust score increased by 0.964.14
Feb 21@mastra/core added to Trust Index2.66
Showing 3 of 3 events
Score History11 snapshots
5.003.752.501.250.00
Feb 21Mar 1
Community & Ecosystemadoption signals
457.4k
Weekly Downloads
npm
100
Commits (90d)
mastra
10
Releases
avg 5d apart
Supply Chain & Dependenciestrust chain
@a2a-js/sdk
npm · ~0.2.4
@ai-sdk/provider-utils-v5
npm · npm:@ai-sdk/provider-utils@3.0.20
@ai-sdk/provider-utils-v6
npm · npm:@ai-sdk/provider-utils@4.0.0
@ai-sdk/provider-v5
npm · npm:@ai-sdk/provider@2.0.0
@ai-sdk/provider-v6
npm · npm:@ai-sdk/provider@3.0.0
@ai-sdk/ui-utils-v5
npm · npm:@ai-sdk/ui-utils@1.2.11
Showing 6 of 23 dependencies
Data Sources6 indexed
Version Historyscore per release
VERSIONRELEASEDSCOREDELTA
@mastra/core@1.7.0Feb 25, 20264.14
@mastra/core@1.6.0Feb 24, 20264.14
@mastra/core@1.5.0Feb 20, 20264.14
@mastra/core@1.4.0Feb 16, 20264.14
mastra@1.3.0Feb 11, 20264.14
mastra@1.2.0Feb 4, 20264.14
Showing 6 of 10 releases

Are you the publisher?

Claim this profile to unlock deeper evaluation, real-time monitoring,
and trust signals that help agents discover your service.

Share this Trust Score

Generate a scorecard image optimised for X, LinkedIn and other social platforms.

⬇ Download Score Card