4.68/ 5.00
trustedBeta
Mar 20, 2026 at 8:45 AM6 signals analysedNo manual reviews · fully automated
Trust Signal Breakdown
high23 sub-signals across 6 dimensions

CVEs, dependency health, and supply chain integrity

2 of 3 sub-signals with data

Known CVEs57%5.0

No known CVEs

via OSV.dev

Dependency Healthno data

Weight redistributed to sub-signals with data

Supply Chain43%4.9

3 transitive CVEs found (penalty: -0.13)

via npm provenance

Uptime, latency, error rates, and incident history

4 of 4 sub-signals with data

Uptime35%5.0

100.00% over 1000 checks

via Health checks

Response Latency25%5.0

p99: 154ms, p50: 53ms

via Health checks

Error Rate20%5.0

0.00% error rate (0/1000)

via Health checks

Incident History20%3.0

2 incidents in last 90 days

via Incidents table

Commit recency, release cadence, issue response, CI/CD

4 of 4 sub-signals with data

Commit Recency30%5.0

via GitHub

Release Cadence25%4.0

via GitHub

Issue Response20%3.0

via GitHub

CI/CD Presence25%5.0

via GitHub Actions

Downloads, stars, dependents, and growth trajectory

3 of 4 sub-signals with data

Download Volume43%5.0

16,436,847 weekly downloads

via npm / PyPI

GitHub Stars36%5.0

99,300 stars

via GitHub

Dependent Packagesno data

Weight redistributed to sub-signals with data

Growth Trend21%4.0

+8.5% week-over-week

via npm

License, documentation, security policy, changelog

4 of 4 sub-signals with data

Open Source30%5.0

Public repo with OSI-approved license (apache-2.0)

via GitHub

Documentation25%4.0

Good README (>2000 bytes with examples)

via GitHub

Security Policy20%5.0

SECURITY.md present

via GitHub

Changelog25%4.0

Releases exist but no CHANGELOG.md

via GitHub

Track record, org maturity, community standing

4 of 4 sub-signals with data

Track Record30%4.0

Internal: 1.0 (0 services), External: 4.0 (9180 followers, 16902 stars)

via Fabric index

Org Maturity30%5.0

Organization, 6.6 years old

via GitHub

Community Standing20%5.0

146 public repositories

via GitHub

Cross-Platform20%5.0

Present on 3 platform(s): github, npm, pypi

via Registry scan

About this score
Scored across 23 sub-signals in 6 dimensionsScoring engine v1 (beta) — actively being expandedPhase 1: Core sub-signal architecture (live)Phase 2: Permission scope & expanded collection (in progress)
Trust AssessmentAI Assessment

The open source Firebase alternative providing a Postgres database, auth, realtime subscriptions, edge functions, and storage.

Service Health (30d)
100.00%
p50: 53ms · p99: 154ms
Avg Latency
60ms
averaged across 30d health checks
Weekly Downloads
16.4M+8%
npm + PyPI weekly
Transparency & Compliance4/5 passed
Incidents & Alertslast 90 days
Feb 24Trust score increased by 2.164.68
Feb 23Supabase added to Trust Index4.72
Showing 2 of 2 events
Score History90 snapshots
5.003.752.501.250.00
Feb 23Mar 5
Community & Ecosystemadoption signals
16.4M
Weekly Downloads
npm + PyPI
Supply Chain & Dependenciestrust chain
@supabase/auth-js
npm · 2.99.3 · 1 CVE1L
@supabase/functions-js
npm · 2.99.3
@supabase/postgrest-js
npm · 2.99.3
@supabase/realtime-js
npm · 2.99.3
@supabase/storage-js
npm · 2.99.3
httpx
pypi · <0.29,>=0.26 · 2 CVEs1L1C
Showing 6 of 12 dependencies
Data Sources6 indexed
Version Historyscore per release
VERSIONRELEASEDSCOREDELTA
v1.26.03Mar 5, 20264.63
v1.26.02Feb 5, 2026
v1.26.01Jan 8, 2026
1.25.12Dec 10, 2025
1.25.04May 7, 2025
1.25.03Apr 8, 2025
Showing 6 of 10 releases

Are you the publisher?

Claim this profile to unlock deeper evaluation, real-time monitoring,
and trust signals that help agents discover your service.

Share this Trust Score

Generate a scorecard image optimised for X, LinkedIn and other social platforms.

⬇ Download Score Card