Before you depend on a project, know how far to trust it.
Secure, well-governed, and still maintained next year? Check any repo before you take on the dependency.
Maintaining your own project instead? TrustScope for maintainers
- Made in Germany
- GDPR-clean
- No tracking
- No sign-in
- Open source
Who does what — and why
Evaluating a third-party library, framework or tool before you take on the dependency.
Runs the full OpenSSF Scorecard and reads three pillars separately — never averaging the trade-offs away.
Adopt, proceed with caution, or avoid — and file constructive fixes upstream, as yourself.
How TrustScope helps
Three questions, answered separately — so the trade-off you're weighing stays visible instead of collapsing into one grade.
Security & Supply Chain
The full OpenSSF Scorecard — where the xz pattern hides.
Trust & Governance
Ownership, licensing & security policy.
Community & Sustainability
Activity & contributor lifecycle.
No single aggregate score. A verdict per pillar — the decision stays yours.