4.19/ 5.00
trustedBeta
Mar 20, 2026 at 6:04 AM6 signals analysedNo manual reviews · fully automated
Trust Signal Breakdown
high23 sub-signals across 6 dimensions

CVEs, dependency health, and supply chain integrity

3 of 3 sub-signals with data

Known CVEs40%5.0

No known CVEs

via OSV.dev

Dependency Health30%5.0

2 dependencies (minimal)

via npm / PyPI

Supply Chain30%4.8

5 transitive CVEs found (penalty: -0.25)

via npm provenance

Uptime, latency, error rates, and incident history

4 of 4 sub-signals with data

Uptime35%5.0

100.00% over 3 checks

via Health checks

Response Latency25%4.0

p99: 334ms, p50: 202ms

via Health checks

Error Rate20%5.0

0.00% error rate (0/3)

via Health checks

Incident History20%4.0

1 incidents in last 90 days

via Incidents table

Commit recency, release cadence, issue response, CI/CD

3 of 4 sub-signals with data

Commit Recency37%5.0

via GitHub

Release Cadence31%2.0

via GitHub

Issue Responseno data

Weight redistributed to sub-signals with data

CI/CD Presence31%5.0

via GitHub Actions

Downloads, stars, dependents, and growth trajectory

3 of 4 sub-signals with data

Download Volume43%3.5

39,138 weekly downloads

via npm / PyPI

GitHub Stars36%3.0

1,320 stars

via GitHub

Dependent Packagesno data

Weight redistributed to sub-signals with data

Growth Trend21%1.0

-31.1% week-over-week

via npm

License, documentation, security policy, changelog

4 of 4 sub-signals with data

Open Source30%5.0

Public repo with OSI-approved license (mit)

via GitHub

Documentation25%4.0

Good README (>2000 bytes with examples)

via GitHub

Security Policy20%5.0

SECURITY.md present

via GitHub

Changelog25%2.0

No CHANGELOG.md and no releases found

via GitHub

Track record, org maturity, community standing

4 of 4 sub-signals with data

Track Record30%4.0

Internal: 4.0 (89 services), External: 3.5 (2180 followers, 7529 stars)

via Fabric index

Org Maturity30%5.0

User account, 10.7 years old

via GitHub

Community Standing20%5.0

161 public repositories

via GitHub

Cross-Platform20%3.0

Present on 2 platform(s): github, npm

via Registry scan

About this score
Scored across 23 sub-signals in 6 dimensionsScoring engine v1 (beta) — actively being expandedPhase 1: Core sub-signal architecture (live)Phase 2: Permission scope & expanded collection (in progress)
Trust AssessmentAI Assessment

@stripe/mcp is a command-line tool published on npm under MIT license by the Stripe organization (via GitHub Actions), providing Model Context Protocol integration for Stripe APIs with minimal dependencies (colors and @modelcontextprotocol/sdk). The package shows clean security posture with no CVEs and 100% operational uptime, though its relatively modest adoption (39K weekly downloads) suggests it is still early in its lifecycle. Despite 63 listed maintainers (likely reflecting Stripe's organizational access structure), the tool should be treated as a credential-handling interface requiring careful API key management and scoped permissions when integrating with Stripe services.

Generated by Fabric AI · Mar 4, 2026 at 4:19 AM

Package Availability (30d)
100.00%
p50: 202ms · p99: 334ms
Avg Latency
196ms
averaged across 30d health checks
Weekly Downloads
no package registry data
Incidents & Alertslast 90 days
Mar 2Trust score increased by 1.034.21
Feb 21@stripe/mcp added to Trust Index2.66
Showing 2 of 2 events
Score History90 snapshots
5.003.752.501.250.00
Feb 21Mar 16
Supply Chain & Dependenciestrust chain
@modelcontextprotocol/sdk
npm · ^1.17.1 · 3 CVEs3H
colors
npm · ^1.4.0 · 2 CVEs2H
Showing 2 of 2 dependencies
Data Sources6 indexed

Are you the publisher?

Claim this profile to unlock deeper evaluation, real-time monitoring,
and trust signals that help agents discover your service.

Share this Trust Score

Generate a scorecard image optimised for X, LinkedIn and other social platforms.

⬇ Download Score Card