4.12/ 5.00
trustedBeta
Mar 5, 2026 at 7:04 AM6 signals analysedNo manual reviews · fully automated
Trust Signal Breakdown
high23 sub-signals across 6 dimensions

CVEs, dependency health, and supply chain integrity

2 of 3 sub-signals with data

Known CVEs57%5.0

No known CVEs

via OSV.dev

Dependency Healthno data

Weight redistributed to sub-signals with data

Supply Chain43%4.9

4 transitive CVEs found (penalty: -0.10)

via npm provenance

Uptime, latency, error rates, and incident history

4 of 4 sub-signals with data

Uptime35%5.0

100.00% over 3 checks

via Health checks

Response Latency25%5.0

p99: 146ms, p50: 115ms

via Health checks

Error Rate20%1.0

33.33% error rate (1/3)

via Health checks

Incident History20%3.0

2 incidents in last 90 days

via Incidents table

Commit recency, release cadence, issue response, CI/CD

4 of 4 sub-signals with data

Commit Recency30%5.0

via GitHub

Release Cadence25%5.0

via GitHub

Issue Response20%3.0

via GitHub

CI/CD Presence25%5.0

via GitHub Actions

Downloads, stars, dependents, and growth trajectory

3 of 4 sub-signals with data

Download Volume43%3.0

1,964 weekly downloads

via npm / PyPI

GitHub Stars36%4.0

5,592 stars

via GitHub

Dependent Packagesno data

Weight redistributed to sub-signals with data

Growth Trend21%5.0

+48.1% week-over-week

via npm

License, documentation, security policy, changelog

4 of 4 sub-signals with data

Open Source30%5.0

Public repo with OSI-approved license (mit)

via GitHub

Documentation25%5.0

Docs site present with comprehensive README (>2000 bytes + examples)

via GitHub

Security Policy20%2.0

No SECURITY.md found

via GitHub

Changelog25%5.0

CHANGELOG.md present and releases exist

via GitHub

Track record, org maturity, community standing

4 of 4 sub-signals with data

Track Record30%2.5

Internal: 1.0 (0 services), External: 2.5 (29 followers, 5594 stars)

via Fabric index

Org Maturity30%3.5

Organization, 1.5 years old

via GitHub

Community Standing20%1.0

2 public repositories

via GitHub

Cross-Platform20%3.0

Present on 2 platform(s): github, npm

via Registry scan

About this score
Scored across 23 sub-signals in 6 dimensionsScoring engine v1 (beta) — actively being expandedPhase 1: Core sub-signal architecture (live)Phase 2: Permission scope & expanded collection (in progress)
Trust AssessmentAI Assessment

Zero-Config Code Flow for Claude code & Codex

Package Availability (30d)
100.00%
p50: 115ms · p99: 146ms
Avg Latency
92ms
averaged across 30d health checks
Weekly Downloads
2.0k+48%
npm weekly
Transparency & Compliance4/5 passed
Incidents & Alertslast 90 days
Mar 2Trust score increased by 1.164.01
Feb 23zcf added to Trust Index2.52
Showing 2 of 2 events
Score History14 snapshots
5.003.752.501.250.00
Feb 23Mar 5
Community & Ecosystemadoption signals
2.0k
Weekly Downloads
npm
10
Releases
on GitHub
Supply Chain & Dependenciestrust chain
@rainbowatcher/toml-edit-js
npm · ^0.6.4
@types/semver
npm · ^7.7.1
ansis
npm · ^4.1.0
cac
npm · ^6.7.14
dayjs
npm · ^1.11.18
find-up-simple
npm · ^1.0.1
Showing 6 of 16 dependencies
Data Sources6 indexed
Version Historyscore per release
VERSIONRELEASEDSCOREDELTA
zcf@3.6.2Mar 4, 20264.00
zcf@3.6.1Jan 30, 2026
zcf@3.6.0Jan 26, 2026
zcf@3.5.1Jan 12, 2026
zcf@3.5.0Dec 25, 2025
zcf@3.4.3Dec 13, 2025
Showing 6 of 10 releases

Are you the publisher?

Claim this profile to unlock deeper evaluation, real-time monitoring,
and trust signals that help agents discover your service.

Share this Trust Score

Generate a scorecard image optimised for X, LinkedIn and other social platforms.

⬇ Download Score Card