4.30/ 5.00
trustedBeta
Mar 13, 2026 at 8:04 PM6 signals analysedNo manual reviews · fully automated
Trust Signal Breakdown
high23 sub-signals across 6 dimensions

CVEs, dependency health, and supply chain integrity

3 of 3 sub-signals with data

Known CVEs40%5.0

No known CVEs

via OSV.dev

Dependency Health30%5.0

6 dependencies (minimal)

via npm / PyPI

Supply Chain30%5.0

Supply chain analyzed, no transitive CVEs

via npm provenance

Uptime, latency, error rates, and incident history

4 of 4 sub-signals with data

Uptime35%5.0

100.00% over 6 checks

via Health checks

Response Latency25%4.0

p99: 241ms, p50: 148ms

via Health checks

Error Rate20%5.0

0.00% error rate (0/6)

via Health checks

Incident History20%2.0

4 incidents in last 90 days

via Incidents table

Commit recency, release cadence, issue response, CI/CD

4 of 4 sub-signals with data

Commit Recency30%5.0

via GitHub

Release Cadence25%5.0

via GitHub

Issue Response20%5.0

via GitHub

CI/CD Presence25%5.0

via GitHub Actions

Downloads, stars, dependents, and growth trajectory

3 of 4 sub-signals with data

Download Volume43%3.5

44,089 weekly downloads

via npm / PyPI

GitHub Stars36%5.0

21,791 stars

via GitHub

Dependent Packagesno data

Weight redistributed to sub-signals with data

Growth Trend21%1.0

-30.3% week-over-week

via npm

License, documentation, security policy, changelog

4 of 4 sub-signals with data

Open Source30%3.0

Public repo with non-OSI license (noassertion)

via GitHub

Documentation25%5.0

Docs site present with comprehensive README (>2000 bytes + examples)

via GitHub

Security Policy20%2.0

No SECURITY.md found

via GitHub

Changelog25%4.0

Releases exist but no CHANGELOG.md

via GitHub

Track record, org maturity, community standing

4 of 4 sub-signals with data

Track Record30%3.5

Internal: 3.0 (80 services), External: 3.5 (2183 followers, 7611 stars)

via Fabric index

Org Maturity30%5.0

User account, 10.7 years old

via GitHub

Community Standing20%5.0

161 public repositories

via GitHub

Cross-Platform20%3.0

Present on 2 platform(s): github, npm

via Registry scan

About this score
Scored across 23 sub-signals in 6 dimensionsScoring engine v1 (beta) — actively being expandedPhase 1: Core sub-signal architecture (live)Phase 2: Permission scope & expanded collection (in progress)
Trust AssessmentAI Assessment

The Retrieval-Augmented Generation (RAG) module contains document processing and embedding utilities.

Package Availability (30d)
100.00%
p50: 148ms · p99: 241ms
Avg Latency
150ms
averaged across 30d health checks
Weekly Downloads
no package registry data
Incidents & Alertslast 90 days
Mar 5Trust score increased by 1.344.33
Mar 1Trust score decreased by 0.873.24
Feb 25Trust score increased by 0.904.08
Feb 21@mastra/rag added to Trust Index2.54
Showing 4 of 4 events
Score History90 snapshots
5.003.752.501.250.00
Feb 21Mar 8
Supply Chain & Dependenciestrust chain
@paralleldrive/cuid2
npm · ^2.3.1
big.js
npm · ^7.0.1
js-tiktoken
npm · ^1.0.21
node-html-better-parser
npm · ^1.5.8
pathe
npm · ^2.0.3
zeroentropy
npm · 0.1.0-alpha.7
Showing 6 of 6 dependencies
Data Sources6 indexed
Version Historyscore per release
VERSIONRELEASEDSCOREDELTA
@mastra/core@1.9.0Mar 4, 20264.33+1.09
@mastra/core@1.8.0Mar 2, 20263.24-0.84
@mastra/core@1.7.0Feb 25, 20264.08+1.45
@mastra/core@1.6.0Feb 24, 20262.63
@mastra/core@1.5.0Feb 20, 2026
@mastra/core@1.4.0Feb 16, 2026
Showing 6 of 10 releases

Are you the publisher?

Claim this profile to unlock deeper evaluation, real-time monitoring,
and trust signals that help agents discover your service.

Share this Trust Score

Generate a scorecard image optimised for X, LinkedIn and other social platforms.

⬇ Download Score Card