Score capped to 0.99 (raw score: 2.98) — critical/high CVE detected with no known fix. Status blocked until the vulnerability is patched.
Mar 4, 2026 at 4:53 AM 6 signals analysed No manual reviews · fully automatedTrust Signal Breakdown high 23 sub-signals across 6 dimensions
Vulnerability & Safety ×0.25 0.0 CVEs, dependency health, and supply chain integrity
2 of 3 sub-signals with data
Known CVEs 57% 0.0
22 CVE(s) found — 4 unpatched
via OSV.dev
Dependency Health no data —
Weight redistributed to sub-signals with data
Supply Chain 43% 4.8
583 transitive CVEs found (penalty: -0.25)
via npm provenance
Operational Reliability ×0.15 4.0 Uptime, latency, error rates, and incident history
4 of 4 sub-signals with data
Uptime 35% 5.0
100.00% over 2 checks
via Health checks
Response Latency 25% 5.0
p99: 23ms, p50: 23ms
via Health checks
Error Rate 20% 1.0
50.00% error rate (1/2)
via Health checks
Incident History 20% 4.0
1 incidents in last 90 days
via Incidents table
Maintenance Activity ×0.15 4.2 Commit recency, release cadence, issue response, CI/CD
4 of 4 sub-signals with data
Commit Recency 30% 5.0
via GitHub
Release Cadence 25% 5.0
via GitHub
Issue Response 20% 1.0
via GitHub
CI/CD Presence 25% 5.0
via GitHub Actions
Adoption ×0.15 3.9 Downloads, stars, dependents, and growth trajectory
2 of 4 sub-signals with data
Download Volume 55% 3.0
5,129 weekly downloads
via npm / PyPI
GitHub Stars 45% 5.0
38,614 stars
via GitHub
Dependent Packages no data —
Weight redistributed to sub-signals with data
Growth Trend no data —
Weight redistributed to sub-signals with data
Transparency ×0.15 3.6 License, documentation, security policy, changelog
4 of 4 sub-signals with data
Open Source 30% 3.0
Public repo with non-OSI license (noassertion)
via GitHub
Documentation 25% 5.0
Docs site present with comprehensive README (>2000 bytes + examples)
via GitHub
Security Policy 20% 5.0
SECURITY.md present
via GitHub
Changelog 25% 2.0
No CHANGELOG.md and no releases found
via GitHub
Publisher Trust ×0.15 4.1 Track record, org maturity, community standing
4 of 4 sub-signals with data
Track Record 30% 4.0
Internal: 1.0 (0 services), External: 4.0 (1346 followers, 39808 stars)
via Fabric index
Org Maturity 30% 5.0
Organization, 8.5 years old
via GitHub
Community Standing 20% 4.0
50 public repositories
via GitHub
Cross-Platform 20% 3.0
Present on 2 platform(s): github, pypi
via Registry scan
About this scoreScored across 23 sub-signals in 6 dimensions Scoring engine v1 (beta) — actively being expanded Phase 1: Core sub-signal architecture (live) Phase 2: Permission scope & expanded collection (in progress)
Trust Assessment AI Assessment
MindsDB is a federated query engine for AI published by mindsdb under a NOASSERTION license, positioning itself as a comprehensive MCP server solution. The service is blocked due to 22 known CVEs including critical unpatched vulnerabilities, making it not recommended for production use despite reasonable operational uptime. The lack of a standard open-source license combined with severe unaddressed security issues represents a significant deployment risk.
Generated by Fabric AI · Mar 4, 2026 at 4:53 AM
Package Availability (30d)
100.00%
p50: 23ms · p99: 23ms
Avg Latency
18ms
averaged across 30d health checks
Weekly Downloads
5.1k
PyPI weekly
Transparency & Compliance 4/5 passed
Incidents & Alerts last 90 days
Score History 13 snapshots
Feb 23 Mar 3
Community & Ecosystem adoption signals
Supply Chain & Dependencies trust chain
Showing 6 of 240 dependencies Show more →
Data Sources 6 indexed
◎
OSV.dev CVE database · vulnerability scanning for npm & PyPI packages
◈
GitHub API Commits, issues, releases, repo metadata, transparency checks
⬡
npm Registry Package metadata, weekly downloads, maintainers, dependencies
⬡
PyPI Package metadata, weekly downloads, dependency tree
△
HTTP Health Checks 15-min pings · uptime, latency, status monitoring
◎
PyPI Stats Download statistics and trends
Version History score per release
VERSION RELEASED SCORE DELTA
Showing 6 of 10 releases Show more →
Are you the publisher? Claim this profile to unlock deeper evaluation, real-time monitoring, and trust signals that help agents discover your service.
Claim Provider Report Issue
Share this Trust Score Generate a scorecard image optimised for X, LinkedIn and other social platforms.
⬇ Download Score Card