Transparent Standards

Scoring Methodology & Transparency

Trust cannot be bought. SafeOpenSource calculates objective 0–100 Safety Scores using deterministic algorithms fed by verifiable public data. We do not accept sponsorships, payments, or editorial bias to influence scores.

The 4 Component Dimensions & Weights

Every tool's composite score is computed using the following formula: Score = (Security * 0.35) + (Maintenance * 0.30) + (Community * 0.20) + (Releases * 0.15)

Security Health

35% Weight

Measures defensive hygiene and supply chain integrity directly from the OpenSSF (Open Source Security Foundation) Scorecard evaluation.

  • Main branch protection enforcement (reviews required)
  • Automated dependency vulnerability scanning (Dependabot/Renovate)
  • Static analysis tooling in CI (CodeQL / Clippy / SonarQube)
  • Cryptographically pinned container and CI action hashes

Maintenance Cadence

30% Weight

Evaluates continuous developer attention and operational vitality over the preceding 12 months.

  • Days since latest commit to default branch
  • Average issue resolution and triage turnaround time
  • Ratio of open to closed pull requests
  • Absence of unaddressed critical security advisories

Community & Governance

20% Weight

Assesses long-term organizational viability and resistance to single-maintainer burnout (the "bus factor").

  • Total unique code contributors over project lifetime
  • Governance model (Foundation, cooperative, or single author)
  • Adoption footprint (GitHub stargazers, Docker pulls)
  • Documentation quality, installation clarity, and community forums

Releases & Artifact Hygiene

15% Weight

Verifies predictable packaging, artifact authenticity, and release security.

  • Predictable semantic versioning cadence
  • Cryptographically signed git tags and release assets (Cosign/GPG)
  • Reproducible Docker container builds with multi-arch manifests
  • Published Software Bill of Materials (SBOM)
Specialized Category Weighting55% Security Health Weight

Why AI Agents Weight Security Health at 55%

Autonomous AI agents (category: 'ai-agents') differ fundamentally from static tools: they execute shell commands, manage local filesystems, automate browser workflows, and invoke external APIs with the operator's local privileges and credentials by design. Because an unpatched vulnerability, prompt injection, or sandbox escape represents a direct route to host compromise, SafeOpenSource rebalances the scoring equation for this category:

DimensionStandard Tools WeightAI Agents WeightThreat Model Rationale
Security Health35% – 40%55% (+15-20%)Shell execution, credential exposure, and prompt injection mitigations command absolute priority.
Maintenance Cadence30%25%Critical for rapid CVE patching turnaround when upstream LLM jailbreaks emerge.
Community & Governance20%10%High star counts cannot compensate for loose sandbox perimeters or missing approval gates.
Releases & Provenance15%10%Verifiable container digests ensure agents run inside expected guest sandbox versions.
Learn how to configure rootless containers, credential isolation, and approval gates:How to Run an AI Agent Safely Guide →

Verdict Classifications

HEALTHY (Score 80–100)

Active commit velocity, responsive security disclosure, reproducible builds, and verified supply-chain hygiene. Recommended for production and home lab deployment.

CAUTION (Score 50–79)

Functional software with minor caveats: moderate maintainer backlog, proprietary enterprise license forks, or slower vulnerability turnaround. Deploy with isolated network policies.

RISKY (Score 0–49)

Stagnant or abandoned codebases with months of inactivity, unpatched high-severity CVEs, or failing automated test pipelines. Migration to safer alternatives is strongly advised.

Data Sources & Update Cadence

We pull automated telemetry from four primary upstream repositories:

  • OpenSSF Scorecard API: Automated security heuristics developed by the Linux Foundation.
  • GitHub REST & GraphQL APIs: Public repository metrics, releases, contributors, and push timestamps.
  • OSV (Open Source Vulnerabilities): Distributed vulnerability database for tracking active CVE notices.
  • SPDX License List: Standardized machine-readable license definitions for commercial rights classification.

Update Cadence: Our automated scoring cron runs weekly to recalculate commit ages, pull latest releases, and verify security advisories. If a critical CVE is disclosed, scores are refreshed within 24 hours.

Limitations & Disclaimers

While our scoring model leverages the best automated static analysis and telemetry available, synthetic audits cannot substitute for tailored enterprise penetration tests. A tool with a 95 Safety Score can still be breached if an administrator uses default credentials or exposes private endpoints directly to the public internet without proper TLS reverse proxying. Always follow defense-in-depth security principles.

ADVERTISEMENTReserved Zero-CLS Placement