88
/100
A
◐ Assessed 3⁄3
depguard
Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory Database), AI hallucination guard, and CycloneDX 1.6 SBOM generation with VEX. 12 MCP tools. Zero runtime dependencies — the SBOM serializer is implemented natively against the public CycloneDX schema.
GitHub
npm
Assessed visibility
— 3/3 applicable dimensions scored
✓ Schema Quality
— Protocol
— Reliability
✓ Docs & Maintenance
✓ Security Hygiene
— Schema Interpretability
Schema Quality
90
42% weight
Protocol Compliance
N/A
Local server
Reliability
N/A
Local server
Docs & Maintenance
76
25% weight
Security Hygiene
95
33% weight
Score History
Category Trends
Static Analysis
| Metric | Score | Rating |
|---|---|---|
| Schema Completeness | 90 | Good |
| Description Quality | 90 | Good |
| Documentation Coverage | 62 | Fair |
| Maintenance Pulse | 76 | Good |
| Dependency Health | 75 | Good |
| License Clarity | 100 | Good |
| Version Hygiene | 90 | Good |
Analyzed 1 month ago