Description
TrustOSS is a free web tool for searching, comparing, and analyzing open-source GitHub libraries so you can evaluate a dependency before you install it. It scores any public repository from 0 to 100, audits whether its stars are organic, scans for known vulnerabilities, and lets you compare up to four candidate libraries side by side.
The overall health score combines five weighted dimensions computed from public GitHub data: activity (last push, commit frequency, release cadence), maintenance (issue close time, open-issue pressure, archived status), community (stars, forks, contributors), documentation (README, license, contributing guide), and maturity (project age and release history). A fake-star audit plots the star growth curve and profiles recent stargazers by account age, followers, and repository count to flag bought popularity using the same signals as academic fake-star research.
A deep scan probes real capability with OSV vulnerability data, real dependents from deps.dev, bus factor from commit concentration, CI pass rate, PR merge rate, and docs-only detection, reporting OK, WARN, or RISK findings with evidence. Every analyzed repo gets a shareable report URL and an embeddable SVG README badge. A trustoss-cli package brings analyze, deep-scan, and star-audit to the terminal and installs a skill so AI coding agents can vet dependencies automatically. Searching, analyzing, comparing, and badges are free with no account; signing in with GitHub is only needed for the maintainer dashboard.
TrustOSS's Core Features
0-100 repository health score across five weighted dimensions
Fake-star audit with stargazer profiling
Deep scan for OSV vulnerabilities, bus factor, and CI health
Real adoption analysis from dependent packages
Side-by-side comparison of up to four libraries
Embeddable README score badges
trustoss-cli for terminal and AI coding agents
Shareable report URLs, no account required
How to use TrustOSS?
Search or paste a repo: Type keywords to rank candidates or paste an owner/repo or GitHub URL.
Read the health report: Review the overall score and five dimension breakdowns.
Run deeper checks: Trigger the deep scan and fake-star audit for vulnerabilities and star authenticity.
Compare finalists: Add up to four libraries for a side-by-side radar chart and score table.
Share or badge it: Share the report URL or paste the SVG badge into your README.
TrustOSS's Use Cases
- Vet a dependency
- Detect fake stars
- Compare libraries
- Showcase repo health
- Automate agent vetting






