Skip to content

Dendra

How Dendra grades

A credit rating for the code you depend on

Dendra gives every package a grade from A to F, built from public evidence: the package registry, published security advisories, and the project's own source repository. Nothing is inferred from private information, and nothing is asked of the maintainer.

The grade rests on nine areas, each scored from 0 to 100. Every score carries the date its evidence was checked — as of 9 July 2026, for example — and is re-checked whenever a new advisory lands.

The nine areas

Each area is scored from 0 to 100 and comes with what it measures and why it matters. The last one is shown for context and does not count.

  1. 01

    Known security problems

    What it measures
    Published advisories that affect this exact version, weighted by severity.
    Why it matters
    This is the risk you already carry today, and the one an attacker can look up too.
  2. 02

    How fast fixes arrive

    What it measures
    How long this project has taken to ship a fix after a problem was reported, on its past advisories.
    Why it matters
    The next problem will be open for about that long.
  3. 03

    Still maintained

    What it measures
    Recent releases, how many people carry the project, and whether the maintainer has marked it deprecated.
    Why it matters
    An unmaintained package never gets its next fix; you will have to replace it instead.
  4. 04

    Releases you can trust

    What it measures
    Whether releases are signed and traceable to the source, and whether the package runs code when it installs.
    Why it matters
    This is how a package gets swapped for a poisoned one without anyone noticing.
  5. 05

    Risk it brings with it

    What it measures
    The worst area across everything this package installs.
    Why it matters
    You inherit its dependencies' problems exactly as if you had chosen them.
  6. 06

    Engineering practice

    What it measures
    Whether the project runs tests and automated checks, protects its main branch, and scans its own code.
    Why it matters
    Projects that do these things ship fewer defects and catch the rest sooner.
  7. 07

    Security policy and reporting

    What it measures
    Whether the project publishes a security policy and a way to report a problem privately, plus licence and funding signals.
    Why it matters
    Without a reporting channel, problems become public before they are fixed.
  8. 08

    Who publishes it

    What it measures
    How long the publisher has been publishing, recent changes of ownership, and whether the name is a near-copy of a popular package.
    Why it matters
    A new or changed publisher, or a look-alike name, is the most common way malicious packages arrive.
  9. 09

    Quality of past fixes — not counted

    What it measures
    Whether past fixes removed the cause or only patched around it.
    Why it matters
    Shown for context only; it does not affect the grade.

The grade scale

The grade is a weighted average of the verified areas, with one rule: a very bad area caps the grade no matter how good the rest look.

A is 85 and above, B 70, C 55, D 40, F below 40. An area scoring under 30 caps the grade at D. A question mark means Dendra has no verified evidence at all.

A
Low risk on current evidence. Fine to use in production.
B
Acceptable risk. A few things worth tracking, nothing blocking.
C
Elevated risk. Use it with the findings below understood and someone responsible for them.
D
High risk. Keeping this without fixing it is a decision that should be on the record.
F
Severe risk. Most teams would not ship this; plan to replace or isolate it.
?
Unverified. Dendra has no verified evidence for this package yet, so it is treated as a risk, not a pass.

Unknown is not safe

When Dendra can't check an area, it says so and marks the area unverified — treated as a risk, not a pass. It never assumes a package is fine because nobody has looked. A grade tells you how many of its nine areas could not be verified.

What the grades do and don't claim

Grades were tested on packages already known to be bad. They do not predict future problems.

A route shows how a problem could reach you, not that it does. Dendra records that a risky package is in your tree and how it got there; whether the vulnerable code runs in your application is a question only your own analysis can answer.

Where the evidence comes from

Sources: npm registry, GitHub Advisory Database (CC-BY 4.0), OSV, NVD, and public repository signals. The same version always gets the same grade under the same scoring model.

Back to Dendra