Bodo, the TrustScope mascotTrustScope
Maintainer

Before you publish, see your project the way evaluators will.

The same three-pillar report an adopter gets on your repo — plus a friendly, concrete list of what to harden.

Evaluating someone else's code instead? TrustScope for adopters

  • Made in Germany
  • GDPR-clean
  • No tracking
  • No sign-in
  • Open source

Who does what — and why

Youthe maintainer

You maintain your own project and want people to trust it — without guessing what evaluators look for.

TrustScopemirrors your repo

Shows the same three-pillar report an adopter would see — nothing about how you're perceived is a surprise.

Youharden, then file

Every finding comes with a constructive, rule-based fix you can file as an issue on your own project.

How TrustScope helps

The three questions evaluators actually ask — each answered separately, so you know exactly what to harden.

Pillar 1

Security & Supply Chain

Is it built securely?

The full OpenSSF Scorecard — the surface adopters scrutinise most.

Pillar 2

Trust & Governance

Can they trust the project behind it?

Ownership, licensing & security policy.

Pillar 3

Community & Sustainability

Will it be here in a year?

Activity & contributor lifecycle.

No single aggregate score — and never a badge. A verdict per pillar.

AdoptProceedAvoid

The verdict an adopter reaches on your repo — close the gaps before they do.

Frequently asked

What does TrustScope do for maintainers?+
It shows the same three-pillar report an adopter sees on your repo — Security & Supply Chain, Trust & Governance, and Community & Sustainability — plus a constructive fix-list you can file as issues.
Will TrustScope give my project a badge or score?+
No. No badge, no single score. It is a mirror and a hardening guide — findings with fixes, never a grade.
What do evaluators actually look for?+
The three pillars — the full OpenSSF Scorecard plus governance and community signals. TrustScope makes each one legible so nothing is a surprise.
How do I fix a finding?+
Every finding carries a constructive, rule-based fix you can file as an issue on your own project, as yourself — carrying a "via TrustScope" attribution footer.