Public record
Software health reportschema 0.30.0 ยท metrics 2.5.0 ยท 2026-08-04 02:36 UTC

Null-Square / Null-CLi

Open-source AI pentest and compliance-readiness CLI by NullSquare.

TypeScript ยท JavaScriptCustom licenseโ˜… 81 starsโ‘‚ 1 forksince Sep 2025View on GitHub โ†—
KindCommand-line toolLibraryhow this is determined

Null-Square/Null-CLi holds a health index of 77 out of 100, placing it in the Good band. It scores highest on Engineering Quality (77/100) and lowest on AI Readiness (46/100). It was last updated 31 days ago. 10 contributors account for most of its recent work.

77
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1โ€“100 scale. Overall starts as their weighted mean, calibrated against the distribution of the public record so bands carry percentile meaning; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At Risk ceiling of 34.

77
Exceptional93-100The record's top tier (โ‰ˆ top 5%); essentially all checked criteria met
Excellent80-92Strong across the board; minor gaps
Good65-79Healthy; gaps are limited and manageable
Moderate50-64Acceptable with notable gaps; review recommended
Weak35-49Material weaknesses across several areas
At Risk20-34Significant weaknesses; adoption warrants caution
Critical1-19Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average โ€” a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

The weighted overall 66 is calibrated to 77 on the published index scale (record calibration 2026-08-02).

Ownership

Null SquareOrganization
2 followers3 public repossince Sep 2025

This repository is backed by an organization โ€” shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publishTags
npm@nullsquare/null-cli0.3.0147631 days agosecuritypentestpenetration-testingappsecai-agentcomplianceowaspsarifnucleisemgreptrivyclinullsquare

Metrics by category

Vitality

Is the project alive โ€” is code being written and are releases shipping?

71Good ยท 21% of overall
How it's scored
18/36Push recency โ€” last push 31 days ago
4.8/36Commit cadence โ€” 7/52 weeks with commits
18/18Commit volume โ€” 387 commits in the last year
10/10OpenSSF Scorecard: Maintained โ€” 12 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year387
human_commit_share1
days_since_last_push31
active_weeks_last_year7

Release discipline

100Exceptional
How it's scored
27/27Ships releases โ€” 4 releases published
36/36Release recency โ€” latest release 31 days ago
27/27Release cadence โ€” a release every ~0.7 days
0/10OpenSSF Scorecard: Signed-Releases โ€” no data
Inputs used
releases_count4
latest_release_tagv0.3.0
releases_from_tagsno
days_since_latest_release31
mean_days_between_releases0.7
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

52Moderate ยท 17% of overall
How it's scored
30.9/60Stars โ€” 81 stars
0/25Forks โ€” 1 forks
0/15Watchers โ€” 1 watchers
Inputs used
forks1
stars81
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

86Excellent
How it's scored
22.5/22.5README
16.9/22.5License โ€” license file present, not a recognized license
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
readme_badges7
has_contributingyes
has_issue_templateno
has_code_of_conductyes
readme_badge_servicesgithub.com, shields.io
has_pull_request_templateyes
How it's scored
28.9/80Monthly downloads โ€” 147 downloads/month across npm
0/20Registry dependents โ€” not reported by this ecosystem
Inputs used
packages@nullsquare/null-cli
dependentsโ€”
ecosystemsnpm
total_downloadsโ€”
monthly_downloads147
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people โ€” bus factor, responsiveness, who backs it, and package upkeep?

68Good ยท 23% of overall
How it's scored
54/54Bus factor โ€” 10 contributor(s) cover half of all commits
20/22.5Commit distribution โ€” top contributor authored 11% of commits
13.5/13.5Contributor breadth โ€” 98 contributors
10/10OpenSSF Scorecard: Contributors โ€” project has 16 contributing companies or organizations
Inputs used
bus_factor10
contributors_sampled98
top_contributor_share0.11
How it's scored
0/42Issue resolution โ€” no issues or no data
15/30PR acceptance โ€” 7/14 decided PRs merged
0/13Newcomer PR acceptance โ€” no first-time contributor's PR decided in 30d
0/15OpenSSF Scorecard: Code-Review โ€” Found 0/16 approved changesets -- score normalized to 0
Inputs used
merged_prs7
open_issues0
closed_issues0
prs_merged_7d0
prs_decided_7d0
prs_merged_30d0
prs_decided_30d0
issue_closed_ratioโ€”
closed_unmerged_prs7
first_time_authors_30d0
first_time_prs_merged_30d0
first_time_prs_decided_30d0
Excluded from scoring (no data or not applicable): Issue resolution, newcomer_pr_acceptance. Remaining weights renormalized.
How it's scored
30/30Ownership backing โ€” organization-owned
0/20Verified domain
3.4/25Owner reach โ€” 2 followers of Null-Square
6.2/25Track record โ€” 3 public repos, account ~0 yr old
Inputs used
followers2
owner_typeOrganization
is_verifiedโ€”
owner_loginNull-Square
public_repos3
account_age_days328

Package maintenance

100Exceptional
How it's scored
25/25Published & resolvable โ€” 1 package(s) on npm
35/35Publish recency โ€” latest publish 31 days ago
20/20Version history โ€” 6 published versions
20/20Not deprecated โ€” active, not deprecated or yanked
Inputs used
packages@nullsquare/null-cli
ecosystemsnpm
any_deprecatedno
min_days_since_publish31

Engineering Quality

Are baseline engineering and documentation practices in place?

77Good ยท 19% of overall
How it's scored
24/24CI workflows โ€” 3 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests โ€” 2 out of 2 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site โ€” https://nullsquare.net
10/10Repository description
10/10Topics โ€” 17 topics
0/10Wiki
Inputs used
topicsiso27001, nist, owasp, pentesting, ai-agent, ai-security, appsec, cli, compliance, docker, offensive-security, pci-dss, sarif, security-tools, typescript, nullsquare, pentest
has_wikino
homepagehttps://nullsquare.net
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

65Good ยท 16% of overall
How it's scored
7.5/7.5Binary-Artifacts โ€” no binaries found in the repo
0/7.5Branch-Protection โ€” branch protection not enabled on development/release branches
2.5/2.5CI-Tests โ€” 2 out of 2 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices โ€” no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review โ€” Found 0/16 approved changesets -- score normalized to 0
2.5/2.5Contributors โ€” project has 16 contributing companies or organizations
10/10Dangerous-Workflow โ€” no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool โ€” update tool detected
0/5Fuzzing โ€” project is not fuzzed
2.2/2.5License โ€” license file detected
7.5/7.5Maintained โ€” 12 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging โ€” packaging workflow detected
0.5/5Pinned-Dependencies โ€” dependency not pinned by hash detected -- score normalized to 1
0/5SAST โ€” SAST tool is not run on all commits -- score normalized to 0
1.5/5Security-Policy โ€” security policy file detected
0/7.5Signed-Releases โ€” no data
0/7.5Token-Permissions โ€” detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities โ€” 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5.6
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.

Dependency advisories

100Exceptional
How it's scored
35/35Direct dependencies free of known advisories โ€” no direct dependency carries a known advisory
25/25Indirect dependencies free of known advisories โ€” no indirect dependency carries a known advisory
0/40No advisories left outstanding โ€” no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages32
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@nullsquare/null-cli@0.3.0 runtime dependency closure โ€” what installing the published package pulls in โ€” 32 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight (4%): agent tooling is a real maintenance signal, but a repository with none can still reach 100/100.

46Weak ยท 4% of overall
How it's scored
0/45Agent instructions โ€” no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
26.1/40Legible commit history โ€” 49 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.49
agent_instruction_filesโ€”
agent_instruction_max_bytesโ€”
How it's scored
0/18One-command bootstrap
22/22Automated tests
0/11Lint / format config
11/11Static type checking โ€” tsconfig.json
10/10Reproducible environment โ€” Dockerfile, lockfile
0/10Demonstrated agent practice โ€” no agent-authored commits among the last 100
0/8Automated maintenance โ€” no automated dependency updates observed
1/10OpenSSF Scorecard: Pinned-Dependencies โ€” dependency not pinned by hash detected -- score normalized to 1
Inputs used
has_nixno
has_testsyes
lockfilespackage-lock.json
has_dockerfileyes
typed_languageyes
bootstrap_filesโ€”
has_devcontainerno
has_linter_configno
typecheck_configstsconfig.json
agent_commit_share0
toolchain_manifestsโ€”
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code โ€” TypeScript (statically typed)
55/55Manageable file sizes โ€” 0/44 source files over 60KB
Inputs used
primary_languageTypeScript
largest_source_bytes58,030
source_files_sampled44
oversized_source_files0
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples โ€” examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_filesโ€”

Key facts

81GitHub stars
98contributors
387commits, last 12 months
31days since last push
4releases
10bus factor
0open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

OpenSSF Scorecard 5.6 / 10
5.6aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 ยท 2026-08-04 02:35 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests2 out of 2 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/16 approved changesets -- score normalized to 0
10Contributorsproject has 16 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
9Licenselicense file detected
10Maintained12 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
1Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 1
0SASTSAST tool is not run on all commits -- score normalized to 0
3Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 1
RegistryPackageVersion constraintManifest
npm@inquirer/prompts^7.10.1package.json
All dependencies 36

Full resolved dependency set from the GitHub dependency graph: 1 direct and 35 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
npm@inquirer/prompts7.10.1direct
npm@inquirer/ansi1.0.2indirect
npm@inquirer/checkbox4.3.2indirect
npm@inquirer/confirm5.1.21indirect
npm@inquirer/core10.3.2indirect
npm@inquirer/editor4.2.23indirect
npm@inquirer/expand4.0.23indirect
npm@inquirer/external-editor1.0.3indirect
npm@inquirer/figures1.0.15indirect
npm@inquirer/input4.3.1indirect
npm@inquirer/number3.0.23indirect
npm@inquirer/password4.0.23indirect
npm@inquirer/rawlist4.1.11indirect
npm@inquirer/search3.2.2indirect
npm@inquirer/select4.4.2indirect
npm@inquirer/testing2.1.53indirect
npm@inquirer/type3.0.10indirect
npm@types/node20.19.43indirect
npmansi-regex5.0.1indirect
npmansi-styles4.3.0indirect
npmchardet2.2.0indirect
npmcli-width4.1.0indirect
npmcolor-convert2.0.1indirect
npmcolor-name1.1.4indirect
npmemoji-regex8.0.0indirect
npmiconv-lite0.7.2indirect
npmis-fullwidth-code-point3.0.0indirect
npmmute-stream2.0.0indirect
npmsafer-buffer2.1.2indirect
npmsignal-exit4.1.0indirect
npmstring-width4.2.3indirect
npmstrip-ansi6.0.1indirect
npmtypescript5.9.3indirect
npmundici-types6.21.0indirect
npmwrap-ansi6.2.0indirect
npmyoctocolors-cjs2.1.3indirect
Dependency advisories 0

Installing npm:@nullsquare/null-cli@0.3.0 pulls in 32 packages, direct and transitive: 0 carry known advisories, of which 0 are direct dependencies.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisoryโ€™s affected range. Reachability is not analysed, and the graph includes development and test pins โ€” a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable

Scores are signals, not warranties. They reflect publicly visible practices on GitHub โ€” not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v2.5.0, schema v0.30.0 โ€” full methodology ยท metrics wiki.

How one result sits in the wider record: aggregate statistics โ€” npm.