How Dendra grades
A credit rating for the code you depend on
Dendra gives every package a grade from A to F, built from public evidence: the package registry, published security advisories, and the project's own source repository. Nothing is inferred from private information, and nothing is asked of the maintainer.
The grade rests on nine areas, each scored from 0 to 100. Every score carries the date its evidence was checked — as of 9 July 2026, for example — and is re-checked whenever a new advisory lands.
The nine areas
Each area is scored from 0 to 100 and comes with what it measures and why it matters. The last one is shown for context and does not count.
- 01
Known security problems
- What it measures
- Published advisories that affect this exact version, weighted by severity.
- Why it matters
- This is the risk you already carry today, and the one an attacker can look up too.
- 02
How fast fixes arrive
- What it measures
- How long this project has taken to ship a fix after a problem was reported, on its past advisories.
- Why it matters
- The next problem will be open for about that long.
- 03
Still maintained
- What it measures
- Recent releases, how many people carry the project, and whether the maintainer has marked it deprecated.
- Why it matters
- An unmaintained package never gets its next fix; you will have to replace it instead.
- 04
Releases you can trust
- What it measures
- Whether releases are signed and traceable to the source, and whether the package runs code when it installs.
- Why it matters
- This is how a package gets swapped for a poisoned one without anyone noticing.
- 05
Risk it brings with it
- What it measures
- The worst area across everything this package installs.
- Why it matters
- You inherit its dependencies' problems exactly as if you had chosen them.
- 06
Engineering practice
- What it measures
- Whether the project runs tests and automated checks, protects its main branch, and scans its own code.
- Why it matters
- Projects that do these things ship fewer defects and catch the rest sooner.
- 07
Security policy and reporting
- What it measures
- Whether the project publishes a security policy and a way to report a problem privately, plus licence and funding signals.
- Why it matters
- Without a reporting channel, problems become public before they are fixed.
- 08
Who publishes it
- What it measures
- How long the publisher has been publishing, recent changes of ownership, and whether the name is a near-copy of a popular package.
- Why it matters
- A new or changed publisher, or a look-alike name, is the most common way malicious packages arrive.
- 09
Quality of past fixes — not counted
- What it measures
- Whether past fixes removed the cause or only patched around it.
- Why it matters
- Shown for context only; it does not affect the grade.
The grade scale
The grade is a weighted average of the verified areas, with one rule: a very bad area caps the grade no matter how good the rest look.
A is 85 and above, B 70, C 55, D 40, F below 40. An area scoring under 30 caps the grade at D. A question mark means Dendra has no verified evidence at all.
- A
- Low risk on current evidence. Fine to use in production.
- B
- Acceptable risk. A few things worth tracking, nothing blocking.
- C
- Elevated risk. Use it with the findings below understood and someone responsible for them.
- D
- High risk. Keeping this without fixing it is a decision that should be on the record.
- F
- Severe risk. Most teams would not ship this; plan to replace or isolate it.
- ?
- Unverified. Dendra has no verified evidence for this package yet, so it is treated as a risk, not a pass.
Unknown is not safe
When Dendra can't check an area, it says so and marks the area unverified — treated as a risk, not a pass. It never assumes a package is fine because nobody has looked. A grade tells you how many of its nine areas could not be verified.
What the grades do and don't claim
Grades were tested on packages already known to be bad. They do not predict future problems.
A route shows how a problem could reach you, not that it does. Dendra records that a risky package is in your tree and how it got there; whether the vulnerable code runs in your application is a question only your own analysis can answer.
Where the evidence comes from
Sources: npm registry, GitHub Advisory Database (CC-BY 4.0), OSV, NVD, and public repository signals. The same version always gets the same grade under the same scoring model.