
The credit score for npm packages. Analyze package reputation, maintenance, security, publisher trust, and ecosystem health before you install any package.
The credit score for npm packages.
Revera helps you decide whether a package is worth installing before you run npm install. It analyzes package quality, maintenance, security, ecosystem health, and publisher trust — and now propagates risk transitively across your entire dependency graph — then produces an explainable, Bayesian reputation report.
Watch revera check and explain packages in real time.
Run revera instantly without installation:
npx revera check react
Checking a package like request (which was deprecated in 2020) immediately warns you with specific reasons:
$ revera why request
▲ revera EXPLAIN
──────────────────────────────────────────────────
Package: [email protected]
Overall: 38/100 Not Recommended
Score Breakdown
Maintenance 15/100 ███░░░░░░░░░░░░░░░░░
Release cadence, commit activity, issue responsiveness, maintainer count
Stability 90/100 ██████████████████░░
SemVer compliance, major version history, API volatility over time
Security 100/100 ████████████████████
Known CVEs, install scripts, repository transparency
Package Quality 40/100 ████████░░░░░░░░░░░░
README completeness, license, test coverage indicators, exports
Ecosystem 100/100 ████████████████████
Weekly download volume, GitHub stars, community forks
Documentation 90/100 ██████████████████░░
README length, code examples, API references, external docs presence
Developer Experience 40/100 ████████░░░░░░░░░░░░
TypeScript support, ESM compatibility, CLI tooling
Publisher Trust 100/100 ████████████████████
Known malicious releases, protestware history, supply-chain incidents
Why it scores well
+ Stable API (v1.0.0+)
+ Low API volatility
+ Zero known vulnerabilities
+ Permissive open-source license
+ Code examples in README
+ Structured API documentation
+ No known publisher trust incidents
Minor deductions
- Last release was 59 months ago
- Single maintainer (bus factor of 1)
- Missing native type definitions
- Legacy CommonJS only
- No native typings (bad TypeScript DX)
Warnings
! Last release: 59 months ago. No recent updates detected. This may be normal for mature, stable libraries.
! Package has been officially marked as deprecated by the maintainer.
Verdict
Request has low confidence. revera recommends looking for alternatives due to security, activity, or stability concerns.
Install globally to access the executable from any directory:
npm install -g @aaravmaloo/revera
Analyze a package and get a high-level summary report:
revera check lodash
Run in offline mode using cached files:
revera check express --offline
Get a deep-dive breakdown of the score, positive signals, and deductions:
revera why node-ipc
Screens packages before installation and warns when reputation falls below your configured threshold:
revera add express
You can pass flags directly to your package manager:
revera add typescript --save-dev
Audit all packages in the current project (includes transitive dependencies) and calculate an overall project health score:
revera audit
Audit production dependencies only:
revera audit --prod
Audit direct dependencies only, skipping transitive dependencies:
revera audit --direct
Authenticate with GitHub to increase API rate limits (60/hour anonymous vs 5,000/hour authenticated). You can choose between browser-based OAuth2 or manually entering a Personal Access Token. Once authorized, revera securely encrypts and stores the token in your OS keyring (Windows DPAPI, macOS Keychain, or Linux Secret Service):
revera login
Manage local settings saved in ~/.revera/config.json:
revera config
revera config set minScoreThreshold 75
revera config get minScoreThreshold
Verify environment settings, API status, and network connection latencies:
revera doctor
Inspect or clear local metadata cache:
revera cache
revera cache clear
Verify if you are running the latest version of the revera engine:
revera update
| Feature | npm audit | osv-scanner | Socket | revera |
|---|---|---|---|---|
| CVE Vulnerabilities | ✔ | ✔ | ✔ | ✔ |
| Multiple Vuln DBs | ✖ | Partial | ✔ | ✔ |
| Ecosystem Reputation | ✖ | ✖ | Partial | ✔ |
| Explainable Scoring | ✖ | ✖ | Partial | ✔ |
| Publisher Trust Check | ✖ | ✖ | Partial | ✔ |
| Typosquat Detection | ✖ | ✖ | Partial | ✔ |
| Transitive Risk Propagation | ✖ | ✖ | ✖ | ✔ |
| Bayesian Confidence Intervals | ✖ | ✖ | ✖ | ✔ |
Revera v2 replaced the legacy flat weighted-sum model with a four-stage Bayesian DAG pipeline.
All dependencies in the project are resolved into a directed acyclic graph. Each node tracks its full transitive dependent set so that later stages can compute accurate blast radii.
lodash ──► your-app
express ──► your-app
axios ──► some-lib ──► your-app ← transitive
Each of the 8 scoring categories starts from an archetype-specific prior (framework, cli, types-only, utility) rather than a flat uninformed baseline. Observed signals update a Beta distribution posterior — meaning a timeout or missing data widens the credible interval rather than silently defaulting to "clean".