Public record
Software health reportschema 0.31.0 · metrics 2.10.0 · 2026-08-05 00:47 UTC

rapid7 / metasploit-framework

Metasploit Framework

RubyCustom license★ 38,739 stars⑂ 14,929 forkssince Aug 2011View on GitHub ↗
KindLibraryNetwork serviceCommand-line toolPluginhow this is determined

rapid7/metasploit-framework holds a health index of 98 out of 100, placing it in the Exceptional band. It scores highest on Vitality (95/100) and lowest on Security (62/100). It was last updated today. 5 contributors account for most of its recent work.

98
overall / 100
Exceptional

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean, calibrated against the distribution of the public record so bands carry percentile meaning; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At Risk ceiling of 34.

98
Exceptional93-100The record's top tier (≈ top 5%); essentially all checked criteria met
Excellent80-92Strong across the board; minor gaps
Good65-79Healthy; gaps are limited and manageable
Moderate50-64Acceptable with notable gaps; review recommended
Weak35-49Material weaknesses across several areas
At Risk20-34Significant weaknesses; adoption warrants caution
Critical1-19Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

The weighted overall 86 is calibrated to 98 on the published index scale (record calibration 2026-08-02).

Ownership

Rapid7Organization
3,197 followers309 public repossince Aug 2011

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
RubyGemsmetasploit-frameworkpoints to another repo — not scored6.0.33-11922 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

95Exceptional · 21% of overall

Development activity

100Exceptional
How it's scored
36/36Push recencylast push 0 days ago
36/36Commit cadence52/52 weeks with commits
18/18Commit volume4,023 commits in the last year
10/10OpenSSF Scorecard: Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year4,023
human_commit_share1
days_since_last_push0
active_weeks_last_year52
How it's scored
16.2/27Ships releases100 version tags (no GitHub releases)
36/36Release recencylatest release 5 days ago
27/27Release cadencea release every ~5.1 days
0/10OpenSSF Scorecard: Signed-Releasesno data
Inputs used
releases_count100
latest_release_tag6.5.0
releases_from_tagsyes
days_since_latest_release5
mean_days_between_releases5.1
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

93Exceptional · 17% of overall

Popularity & adoption

100Exceptional
How it's scored
60/60Stars38,739 stars
25/25Forks14,929 forks
15/15Watchers2,060 watchers
Inputs used
forks14,929
stars38,739
watchers2,060
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

86Excellent
How it's scored
22.5/22.5README
16.9/22.5Licenselicense file present, not a recognized license
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
readme_badges0
has_contributingyes
has_issue_templateno
has_code_of_conductyes
readme_badge_services
has_pull_request_templateyes

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

89Excellent · 23% of overall
How it's scored
45.9/54Bus factor5 contributor(s) cover half of all commits
18.6/22.5Commit distributiontop contributor authored 18% of commits
13.5/13.5Contributor breadth100 contributors
10/10OpenSSF Scorecard: Contributorsproject has 14 contributing companies or organizations
Inputs used
bus_factor5
contributors_sampled100
top_contributor_share0.175
How it's scored
38.9/42Issue resolution92% of issues closed
24.8/30PR acceptance11,963/14,483 decided PRs merged
8.7/13Newcomer PR acceptance2/3 first-time contributors' PRs merged in 30d
7.5/15OpenSSF Scorecard: Code-ReviewFound 8/14 approved changesets -- score normalized to 5
Inputs used
merged_prs11,963
open_issues494
closed_issues6,080
prs_merged_7d17
prs_decided_7d17
prs_merged_30d51
prs_decided_30d57
issue_closed_ratio0.925
closed_unmerged_prs2,520
first_time_authors_30d3
first_time_prs_merged_30d2
first_time_prs_decided_30d3
How it's scored
30/30Ownership backingorganization-owned
0/20Verified domainverified-domain status not read for this organization
25/25Owner reach3,197 followers of rapid7
25/25Track record309 public repos, account ~14 yr old
Inputs used
followers3,197
owner_typeOrganization
is_verified
owner_loginrapid7
public_repos309
account_age_days5,453
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.

Engineering Quality

Are baseline engineering and documentation practices in place?

90Excellent · 19% of overall
How it's scored
24/24CI workflows21 workflow(s)
24/24Tests present
16/16Linter config.rubocop.yml
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests8 out of 8 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno

Documentation

100Exceptional
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage sitehttps://www.metasploit.com/
10/10Repository description
10/10Topics1 topics
10/10Wiki
Inputs used
topicshacktoberfest
has_wikiyes
homepagehttps://www.metasploit.com/
docs_sitehttps://www.metasploit.com/
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

62Moderate · 16% of overall
How it's scored
0/7.5Binary-Artifactsbinaries present in source code
0/7.5Branch-Protectionno data
2.5/2.5CI-Tests8 out of 8 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
3.8/7.5Code-ReviewFound 8/14 approved changesets -- score normalized to 5
2.5/2.5Contributorsproject has 14 contributing companies or organizations
10/10Dangerous-Workflowno dangerous workflow patterns detected
7.5/7.5Dependency-Update-Toolupdate tool detected
0/5Fuzzingproject is not fuzzed
2.2/2.5Licenselicense file detected
7.5/7.5Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packagingpackaging workflow detected
0.5/5Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 1
0/5SASTSAST tool is not run on all commits -- score normalized to 0
5/5Security-Policysecurity policy file detected
0/7.5Signed-Releasesno data
0/7.5Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities51 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate5.2
Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.

Dependency advisories

100Exceptional
How it's scored
35/35Direct dependencies free of known advisoriesno direct dependency carries a known advisory
0/25Indirect dependencies free of known advisoriestransitive set not separable from development and test dependencies in this scope
0/40No advisories left outstandingno advisory carries a publication date
Inputs used
sourceosv
advisories84
affected_packages19
assessed_packages279
unassessed_packages102
affected_by_severitycritical 1, high 9, moderate 8, low 1
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 279 resolved dependencies against OSV. 102 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight (4%): agent tooling is a real maintenance signal, but a repository with none can still reach 100/100.

72Good · 4% of overall
How it's scored
45/45Agent instructions.github/copilot-instructions.md, AGENTS.md
0/15Machine-readable docs (llms.txt)
22.4/40Legible commit history42 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
llms_txt_url
legible_history_share0.42
agent_instruction_files.github/copilot-instructions.md, AGENTS.md
agent_instruction_max_bytes9,155
How it's scored
18/18One-command bootstrapdata/exploits/CVE-2019-13272/Makefile, data/exploits/CVE-2021-22204/Makefile, data/exploits/CVE-2022-0847/Makefile, data/exploits/osx/dump_keychain/Makefile, data/exploits/redis/Makefile, data/exploits/redis/exp/Makefile, data/exploits/redis/rmutil/Makefile, external/source/byakugan/detours/Makefile, external/source/byakugan/injectsu/makefile, external/source/byakugan/makefile, external/source/cmdstager/debug_asm/Makefile, external/source/exploits/CVE-2008-5353/Makefile, external/source/exploits/CVE-2012-0507/Makefile, external/source/exploits/CVE-2012-1723/Makefile, external/source/exploits/CVE-2013-2171/Makefile, external/source/exploits/CVE-2013-2465/Makefile, external/source/exploits/CVE-2013-6282/Makefile, external/source/exploits/CVE-2014-3153/Makefile, external/source/exploits/CVE-2014-4404/Makefile, external/source/exploits/CVE-2016-4655/Makefile, external/source/exploits/CVE-2016-4669/Makefile, external/source/exploits/CVE-2017-13861/Makefile, external/source/exploits/CVE-2018-4237/Makefile, external/source/exploits/CVE-2018-4237/ssudo/Makefile, external/source/exploits/CVE-2018-4404/Makefile, external/source/exploits/CVE-2018-4404/stage1/Makefile, external/source/exploits/CVE-2018-4404/stage2/Makefile, external/source/exploits/CVE-2019-0808/Makefile, external/source/exploits/CVE-2019-1458/Makefile, external/source/exploits/CVE-2019-2215/Makefile, external/source/exploits/CVE-2019-8513/Makefile, external/source/exploits/CVE-2019-8565/Makefile, external/source/exploits/CVE-2020-1054/Makefile, external/source/exploits/CVE-2020-9839/Makefile, external/source/exploits/CVE-2020-9850/Makefile, external/source/exploits/CVE-2020-9850/payload/loader/Makefile, external/source/exploits/CVE-2020-9850/payload/sbx/Makefile, external/source/exploits/CVE-2020-9850/payload/sbx/root/Makefile, external/source/exploits/CVE-2021-22555/Makefile, external/source/exploits/CVE-2021-3490/Linux_LPE_eBPF_CVE-2021-3490/Makefile, external/source/exploits/CVE-2022-34918/Makefile, external/source/exploits/CVE-2022-46689/Makefile, external/source/exploits/cve-2012-5076/Makefile, external/source/exploits/cve-2012-5076_2/Makefile, external/source/exploits/cve-2012-5088/Makefile, external/source/exploits/cve-2013-0422/Makefile, external/source/exploits/cve-2013-0431/Makefile, external/source/exploits/cve-2013-1488/Makefile, external/source/exploits/cve-2013-1493/Makefile, external/source/exploits/cve-2013-2460/Makefile, external/source/exploits/jre17u17/Makefile, external/source/exploits/tpwn/Makefile, external/source/ipwn/Makefile, external/source/metsvc/src/Makefile, external/source/osx/isight/Makefile, external/source/osx/x86/Makefile, external/source/osx/x86/src/test/Makefile, external/source/shellcode/Makefile, external/source/shellcode/bsd/ia32/Makefile, external/source/shellcode/bsdi/ia32/Makefile, external/source/shellcode/linux/ia32/Makefile, external/source/shellcode/osx/stager/Makefile, external/source/shellcode/osx/template/Makefile, external/source/vncdll/winvnc/zlib/Makefile, kubernetes/Makefile, test/kubernetes/Makefile, tools/context/Makefile
22/22Automated tests
11/11Lint / format config.rubocop.yml
11/11Static type checkingdata/exploits/react2shell_unauth_rce_cve_2025_55182/tsconfig.json
10/10Reproducible environmentDockerfile, lockfile
4/10Demonstrated agent practice2 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenanceno automated dependency updates observed
1/10OpenSSF Scorecard: Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 1
Inputs used
has_nixno
has_testsyes
lockfilesGemfile.lock
has_dockerfileyes
typed_languageno
bootstrap_filesdata/exploits/CVE-2019-13272/Makefile, data/exploits/CVE-2021-22204/Makefile, data/exploits/CVE-2022-0847/Makefile, data/exploits/osx/dump_keychain/Makefile, data/exploits/redis/Makefile, data/exploits/redis/exp/Makefile, data/exploits/redis/rmutil/Makefile, external/source/byakugan/detours/Makefile, external/source/byakugan/injectsu/makefile, external/source/byakugan/makefile, external/source/cmdstager/debug_asm/Makefile, external/source/exploits/CVE-2008-5353/Makefile, external/source/exploits/CVE-2012-0507/Makefile, external/source/exploits/CVE-2012-1723/Makefile, external/source/exploits/CVE-2013-2171/Makefile, external/source/exploits/CVE-2013-2465/Makefile, external/source/exploits/CVE-2013-6282/Makefile, external/source/exploits/CVE-2014-3153/Makefile, external/source/exploits/CVE-2014-4404/Makefile, external/source/exploits/CVE-2016-4655/Makefile, external/source/exploits/CVE-2016-4669/Makefile, external/source/exploits/CVE-2017-13861/Makefile, external/source/exploits/CVE-2018-4237/Makefile, external/source/exploits/CVE-2018-4237/ssudo/Makefile, external/source/exploits/CVE-2018-4404/Makefile, external/source/exploits/CVE-2018-4404/stage1/Makefile, external/source/exploits/CVE-2018-4404/stage2/Makefile, external/source/exploits/CVE-2019-0808/Makefile, external/source/exploits/CVE-2019-1458/Makefile, external/source/exploits/CVE-2019-2215/Makefile, external/source/exploits/CVE-2019-8513/Makefile, external/source/exploits/CVE-2019-8565/Makefile, external/source/exploits/CVE-2020-1054/Makefile, external/source/exploits/CVE-2020-9839/Makefile, external/source/exploits/CVE-2020-9850/Makefile, external/source/exploits/CVE-2020-9850/payload/loader/Makefile, external/source/exploits/CVE-2020-9850/payload/sbx/Makefile, external/source/exploits/CVE-2020-9850/payload/sbx/root/Makefile, external/source/exploits/CVE-2021-22555/Makefile, external/source/exploits/CVE-2021-3490/Linux_LPE_eBPF_CVE-2021-3490/Makefile, external/source/exploits/CVE-2022-34918/Makefile, external/source/exploits/CVE-2022-46689/Makefile, external/source/exploits/cve-2012-5076/Makefile, external/source/exploits/cve-2012-5076_2/Makefile, external/source/exploits/cve-2012-5088/Makefile, external/source/exploits/cve-2013-0422/Makefile, external/source/exploits/cve-2013-0431/Makefile, external/source/exploits/cve-2013-1488/Makefile, external/source/exploits/cve-2013-1493/Makefile, external/source/exploits/cve-2013-2460/Makefile, external/source/exploits/jre17u17/Makefile, external/source/exploits/tpwn/Makefile, external/source/ipwn/Makefile, external/source/metsvc/src/Makefile, external/source/osx/isight/Makefile, external/source/osx/x86/Makefile, external/source/osx/x86/src/test/Makefile, external/source/shellcode/Makefile, external/source/shellcode/bsd/ia32/Makefile, external/source/shellcode/bsdi/ia32/Makefile, external/source/shellcode/linux/ia32/Makefile, external/source/shellcode/osx/stager/Makefile, external/source/shellcode/osx/template/Makefile, external/source/vncdll/winvnc/zlib/Makefile, kubernetes/Makefile, test/kubernetes/Makefile, tools/context/Makefile
has_devcontainerno
has_linter_configyes
typecheck_configsdata/exploits/react2shell_unauth_rce_cve_2025_55182/tsconfig.json
agent_commit_share0.02
toolchain_manifestsdata/exploits/burp_extension/build.gradle, external/source/exploits/CVE-2020-17136/POC_CloudFilter_ArbitraryFile_EoP/POC_CloudFilter_ArbitraryFile_EoP.csproj, external/source/exploits/cve-2013-0074/SilverApp1/SilverApp1.csproj
dependency_bot_commit_share0
How it's scored
27/45Type-checkable codeRuby with type-check config (data/exploits/react2shell_unauth_rce_cve_2025_55182/tsconfig.json)
54.8/55Manageable file sizes41/9,544 source files over 60KB
Inputs used
primary_languageRuby
largest_source_bytes4,907,558
source_files_sampled9,544
oversized_source_files41
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
20/20MCP server
40/40Runnable examplesexamples
Inputs used
example_dirsexamples
has_mcp_signalyes
api_schema_files
interfaces_expected_ofnetwork-service

Key facts

38,739GitHub stars
100contributors
4,023commits, last 12 months
0days since last push
100releases
5bus factor
494open issues
RubyGemspackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • First-time contributor figures cover 12 of 25 authors (cap 12)
  • rubygems package 'metasploit-framework' points at a different repository (https://www.metasploit.com); excluded from ecosystem scoring

More detail

Star and fork history 0 ★ / 14,929 ⇿
0Stars
14,929Forks
83Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

Only the most recent history is shown — this repository exceeds the collection window, so the earliest history is not captured.

13,50014,00014,50015,00014,929142025-052025-122026-08
Major 0Minor 1Patch 82

Each point covers 2 days.

OpenSSF Scorecard 5.2 / 10
5.2aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-08-05 00:46 UTC

0Binary-Artifactsbinaries present in source code
n/aBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests8 out of 8 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
5Code-ReviewFound 8/14 approved changesets -- score normalized to 5
10Contributorsproject has 14 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
9Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
1Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 1
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities51 existing vulnerabilities detected
Direct dependencies 1
RegistryPackageVersion constraintManifest
RubyGemssimplecov0.18.2Gemfile
All dependencies 381

Full resolved dependency set from the GitHub dependency graph: 1 direct and 380 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
RubyGemssimplecov0.18.2direct
npm@types/node^20indirect
npm@types/react^18indirect
npm@types/react-dom^18indirect
npmnext15.0.4indirect
npmreact19.0.0indirect
npmreact-dom19.0.0indirect
npmtypescript^5indirect
RubyGemsaarch64indirect
RubyGemsaarch642.1.0indirect
RubyGemsabbrev0.1.2indirect
RubyGemsactionpack8.0.5indirect
RubyGemsactionview8.0.5indirect
RubyGemsactivemodel8.0.5indirect
RubyGemsactiverecord8.0.5indirect
RubyGemsactivesupport8.0.5indirect
RubyGemsaddressable2.8.7indirect
RubyGemsafm0.2.2indirect
RubyGemsallure-rspec2.27.0indirect
RubyGemsallure-ruby-commons2.27.0indirect
RubyGemsarel-helpers2.16.0indirect
RubyGemsAscii852.0.1indirect
RubyGemsast2.4.3indirect
RubyGemsaws-eventstream1.3.2indirect
RubyGemsaws-partitions1.1065.0indirect
RubyGemsaws-sdk-core3.220.1indirect
RubyGemsaws-sdk-ec2indirect
RubyGemsaws-sdk-ec21.511.0indirect
RubyGemsaws-sdk-ec2instanceconnectindirect
RubyGemsaws-sdk-ec2instanceconnect1.55.0indirect
RubyGemsaws-sdk-iamindirect
RubyGemsaws-sdk-iam1.119.0indirect
RubyGemsaws-sdk-kms1.99.0indirect
RubyGemsaws-sdk-s3indirect
RubyGemsaws-sdk-s31.182.0indirect
RubyGemsaws-sdk-ssmindirect
RubyGemsaws-sdk-ssm1.191.0indirect
RubyGemsaws-sigv41.11.0indirect
RubyGemsbase640.3.0indirect
RubyGemsbcryptindirect
RubyGemsbcrypt3.1.20indirect
RubyGemsbcrypt_pbkdfindirect
RubyGemsbcrypt_pbkdf1.1.1indirect
RubyGemsbenchmark0.4.1indirect
RubyGemsbigdecimal3.3.1indirect
RubyGemsbindata2.4.15indirect
RubyGemsbootsnapindirect
RubyGemsbootsnap1.18.4indirect
RubyGemsbsonindirect
RubyGemsbson5.1.1indirect
RubyGemsbuilder3.3.0indirect
RubyGemsbyebug11.1.3indirect
RubyGemsbyebug12.0.0indirect
RubyGemschunky_pngindirect
RubyGemschunky_png1.4.0indirect
RubyGemscoderay1.1.3indirect
RubyGemscolorator1.1.0indirect
RubyGemsconcurrent-ruby1.3.5indirect
RubyGemsconnection_pool2.5.4indirect
RubyGemscookiejar0.3.4indirect
RubyGemscrack1.0.1indirect
RubyGemscrass1.0.6indirect
RubyGemscsv3.3.5indirect
RubyGemsdaemons1.4.1indirect
RubyGemsdate3.4.1indirect
RubyGemsdebug1.11.0indirect
RubyGemsdiff-lcs1.6.2indirect
RubyGemsdnsrubyindirect
RubyGemsdnsruby1.74.0indirect
RubyGemsdocile1.4.1indirect
RubyGemsdomain_name0.6.20240107indirect
RubyGemsdrb2.2.3indirect
RubyGemsed25519indirect
RubyGemsed255191.4.0indirect
RubyGemselftoolsindirect
RubyGemselftools1.3.1indirect
RubyGemsem-http-requestindirect
RubyGemsem-http-request1.1.7indirect
RubyGemsem-socksify0.3.3indirect
RubyGemsem-websocket0.5.3indirect
RubyGemserb5.0.3indirect
RubyGemserubi1.13.1indirect
RubyGemseventmachineindirect
RubyGemseventmachine1.2.7indirect
RubyGemsfactory_bot6.5.5indirect
RubyGemsfactory_bot_rails6.5.1indirect
RubyGemsfakerindirect
RubyGemsfaker3.5.1indirect
RubyGemsfaradayindirect
RubyGemsfaraday2.7.11indirect
RubyGemsfaraday-net_http3.0.2indirect
RubyGemsfaraday-retryindirect
RubyGemsfaraday-retry2.2.1indirect
RubyGemsfaye-websocketindirect
RubyGemsfaye-websocket0.11.3indirect
RubyGemsffiindirect
RubyGemsffi1.16.3indirect
RubyGemsffi1.17.1indirect
RubyGemsfiddle1.1.6indirect
RubyGemsfilesizeindirect
RubyGemsfilesize0.2.0indirect
RubyGemsfivemat1.3.7indirect
RubyGemsforwardable1.3.3indirect
RubyGemsforwardable-extended2.6.0indirect
RubyGemsgetoptlong0.2.1indirect
RubyGemsgssapi1.3.1indirect
RubyGemsgyoku1.4.0indirect
RubyGemshashdiff1.2.1indirect
RubyGemshashery2.1.2indirect
RubyGemshrr_rb_ssh0.4.2indirect
RubyGemshrr_rb_ssh-ed25519indirect
RubyGemshrr_rb_ssh-ed255190.4.2indirect
RubyGemshttp-accept1.7.0indirect
RubyGemshttp-cookieindirect
RubyGemshttp-cookie1.0.8indirect
RubyGemshttp_parser.rb0.8.0indirect
RubyGemshttpclient2.9.0indirect
RubyGemsi18n1.14.7indirect
RubyGemsio-console0.8.1indirect
RubyGemsipaddr1.2.7indirect
RubyGemsirbindirect
RubyGemsirb1.15.2indirect
RubyGemsjekyll4.3.4indirect
RubyGemsjekyll-include-cache0.2.1indirect
RubyGemsjekyll-sass-converter2.2.0indirect
RubyGemsjekyll-seo-tag2.8.0indirect
RubyGemsjekyll-sitemap1.4.0indirect
RubyGemsjekyll-watch2.2.1indirect
RubyGemsjmespath1.6.2indirect
RubyGemsjsobfuindirect
RubyGemsjsobfu0.4.2indirect
RubyGemsjsonindirect
RubyGemsjson2.15.1indirect
RubyGemsjson-schema6.2.0indirect
RubyGemskramdown2.5.1indirect
RubyGemskramdown-parser-gfm1.1.0indirect
RubyGemslanguage_server-protocol3.17.0.5indirect
RubyGemslint_roller1.1.0indirect
RubyGemsliquid4.0.4indirect
RubyGemslisten3.9.0indirect
RubyGemslittle-plugger1.1.4indirect
RubyGemslogger1.7.0indirect
RubyGemslogging2.4.0indirect
RubyGemsloofah2.24.1indirect
RubyGemslru_reduxindirect
RubyGemslru_redux1.1.0indirect
RubyGemsmcp0.13.0indirect
RubyGemsmemory_profiler1.1.0indirect
RubyGemsmercenary0.4.0indirect
RubyGemsmetasmindirect
RubyGemsmetasm1.0.6indirect
RubyGemsmetasploit-concernindirect
RubyGemsmetasploit-concern5.0.6indirect
RubyGemsmetasploit-credentialindirect
RubyGemsmetasploit-credential6.0.25indirect
RubyGemsmetasploit-modelindirect
RubyGemsmetasploit-model5.0.5indirect
RubyGemsmetasploit-payloads2.0.247indirect
RubyGemsmetasploit_data_modelsindirect
RubyGemsmetasploit_data_models6.0.18indirect
RubyGemsmetasploit_payloads-mettle1.0.48indirect
RubyGemsmethod_source1.1.0indirect
RubyGemsmime-types3.7.0indirect
RubyGemsmime-types-data3.2025.0924indirect
RubyGemsmini_portile22.8.9indirect
RubyGemsminitest5.25.5indirect
RubyGemsmqttindirect
RubyGemsmqtt0.7.0indirect
RubyGemsmsgpackindirect
RubyGemsmsgpack1.6.1indirect
RubyGemsmulti_json1.15.0indirect
RubyGemsmustermann3.0.3indirect
RubyGemsmutex_m0.3.0indirect
RubyGemsnessus_restindirect
RubyGemsnessus_rest0.1.6indirect
RubyGemsnet-imapindirect
RubyGemsnet-imap0.5.6indirect
RubyGemsnet-ldapindirect
RubyGemsnet-ldap0.20.0indirect
RubyGemsnet-protocol0.2.2indirect
RubyGemsnet-sftpindirect
RubyGemsnet-sftp4.0.0indirect
RubyGemsnet-smtpindirect
RubyGemsnet-smtp0.5.1indirect
RubyGemsnet-sshindirect
RubyGemsnet-ssh7.3.0indirect
RubyGemsnetrc0.11.0indirect
RubyGemsnetwork_interfaceindirect
RubyGemsnetwork_interface0.0.4indirect
RubyGemsnexposeindirect
RubyGemsnexpose7.3.0indirect
RubyGemsnio4r2.7.4indirect
RubyGemsnokogiriindirect
RubyGemsnokogiri1.18.10indirect
RubyGemsnori2.7.1indirect
RubyGemsoctokitindirect
RubyGemsoctokit10.0.0indirect
RubyGemsopenssl-ccmindirect
RubyGemsopenssl-ccm1.2.3indirect
RubyGemsopenssl-cmac2.0.2indirect
RubyGemsopenvas-ompindirect
RubyGemsopenvas-omp0.0.4indirect
RubyGemsostruct0.6.1indirect
RubyGemspacketfuindirect
RubyGemspacketfu2.0.0indirect
RubyGemsparallelindirect
RubyGemsparallel1.27.0indirect
RubyGemsparser3.3.9.0indirect
RubyGemspatch_finderindirect
RubyGemspatch_finder1.0.2indirect
RubyGemspathutil0.16.2indirect
RubyGemspcaprubindirect
RubyGemspcaprub0.13.3indirect
RubyGemspdf-readerindirect
RubyGemspdf-reader2.14.1indirect
RubyGemspgindirect
RubyGemspg1.5.9indirect
RubyGemspp0.6.3indirect
RubyGemsprettyprint0.2.0indirect
RubyGemsprism1.5.1indirect
RubyGemspry0.14.2indirect
RubyGemspry0.15.2indirect
RubyGemspry-byebug3.10.1indirect
RubyGemspry-byebug3.11.0indirect
RubyGemspsych5.3.1indirect
RubyGemspublic_suffix6.0.1indirect
RubyGemspublic_suffix6.0.2indirect
RubyGemspumaindirect
RubyGemspuma6.6.0indirect
RubyGemsracc1.8.1indirect
RubyGemsrackindirect
RubyGemsrack3.1.21indirect
RubyGemsrack-protection4.2.1indirect
RubyGemsrack-session2.1.2indirect
RubyGemsrack-test2.2.0indirect
RubyGemsrackup2.3.1indirect
RubyGemsrails-dom-testing2.3.0indirect
RubyGemsrails-html-sanitizer1.6.2indirect
RubyGemsrailties8.0.5indirect
RubyGemsrainbow3.1.1indirect
RubyGemsrake13.2.1indirect
RubyGemsrake13.3.0indirect
RubyGemsrasn10.14.0indirect
RubyGemsrb-fsevent0.11.2indirect
RubyGemsrb-inotify0.11.1indirect
RubyGemsrb-readlineindirect
RubyGemsrb-readline0.5.5indirect
RubyGemsrdoc6.15.0indirect
RubyGemsrecogindirect
RubyGemsrecog3.1.14indirect
RubyGemsredcarpetindirect
RubyGemsredcarpet3.6.1indirect
RubyGemsregexp_parser2.11.3indirect
RubyGemsrelineindirect
RubyGemsreline0.6.2indirect
RubyGemsrequire_all3.0.0indirect
RubyGemsrest-clientindirect
RubyGemsrest-client2.1.0indirect
RubyGemsrex-archindirect
RubyGemsrex-arch0.1.20indirect
RubyGemsrex-bin_toolsindirect
RubyGemsrex-bin_tools0.1.16indirect
RubyGemsrex-coreindirect
RubyGemsrex-core0.1.36indirect
RubyGemsrex-encoderindirect
RubyGemsrex-encoder0.1.10indirect
RubyGemsrex-exploitationindirect
RubyGemsrex-exploitation0.1.44indirect
RubyGemsrex-javaindirect
RubyGemsrex-java0.1.8indirect
RubyGemsrex-mimeindirect
RubyGemsrex-mime0.1.11indirect
RubyGemsrex-nopindirect
RubyGemsrex-nop0.1.4indirect
RubyGemsrex-oleindirect
RubyGemsrex-ole0.1.9indirect
RubyGemsrex-powershellindirect
RubyGemsrex-powershell0.1.103indirect
RubyGemsrex-random_identifierindirect
RubyGemsrex-random_identifier0.1.21indirect
RubyGemsrex-registryindirect
RubyGemsrex-registry0.1.6indirect
RubyGemsrex-rop_builderindirect
RubyGemsrex-rop_builder0.1.6indirect
RubyGemsrex-socketindirect
RubyGemsrex-socket0.1.71indirect
RubyGemsrex-sslscanindirect
RubyGemsrex-sslscan0.1.13indirect
RubyGemsrex-struct2indirect
RubyGemsrex-struct20.1.5indirect
RubyGemsrex-textindirect
RubyGemsrex-text0.2.63indirect
RubyGemsrex-zipindirect
RubyGemsrex-zip0.1.6indirect
RubyGemsrexml3.4.1indirect
RubyGemsrinda0.2.0indirect
RubyGemsrkelly-remix0.0.7indirect
RubyGemsrouge4.5.1indirect
RubyGemsrspec3.13.1indirect
RubyGemsrspec-core3.13.5indirect
RubyGemsrspec-expectations3.13.5indirect
RubyGemsrspec-mocks3.13.5indirect
RubyGemsrspec-rails8.0.2indirect
RubyGemsrspec-rerun1.1.0indirect
RubyGemsrspec-support3.13.6indirect
RubyGemsrubocop1.75.7indirect
RubyGemsrubocop-ast1.47.1indirect
RubyGemsruby-machoindirect
RubyGemsruby-macho4.1.0indirect
RubyGemsruby-mysqlindirect
RubyGemsruby-mysql4.2.0indirect
RubyGemsruby-prof1.7.2indirect
RubyGemsruby-progressbar1.13.0indirect
RubyGemsruby-rc40.1.5indirect
RubyGemsruby2_keywords0.0.5indirect
RubyGemsruby_smbindirect
RubyGemsruby_smb3.3.21indirect
RubyGemsrubyntlmindirect
RubyGemsrubyntlm0.6.5indirect
RubyGemsrubyzipindirect
RubyGemsrubyzip3.3.0indirect
RubyGemssafe_yaml1.0.5indirect
RubyGemssassc2.4.0indirect
RubyGemssawyer0.9.2indirect
RubyGemssecurerandom0.4.1indirect
RubyGemssimplecov-html0.13.1indirect
RubyGemssimpleidn0.2.3indirect
RubyGemssinatraindirect
RubyGemssinatra4.2.1indirect
RubyGemssqlite3indirect
RubyGemssqlite32.9.4indirect
RubyGemssshkeyindirect
RubyGemssshkey3.0.0indirect
RubyGemsstringio3.1.1indirect
RubyGemsstrptime0.2.5indirect
RubyGemsswagger-blocksindirect
RubyGemsswagger-blocks3.0.0indirect
RubyGemssyslog0.3.0indirect
RubyGemsterminal-table3.0.2indirect
RubyGemstest-prof1.4.4indirect
RubyGemsthinindirect
RubyGemsthin2.0.1indirect
RubyGemsthor1.5.0indirect
RubyGemstilt2.6.0indirect
RubyGemstimecop0.9.10indirect
RubyGemstimeout0.4.3indirect
RubyGemstomlrb2.0.4indirect
RubyGemstsort0.2.0indirect
RubyGemsttfunk1.8.0indirect
RubyGemstzinfoindirect
RubyGemstzinfo2.0.6indirect
RubyGemstzinfo-dataindirect
RubyGemstzinfo-data1.2025.1indirect
RubyGemsunicode-display_width2.6.0indirect
RubyGemsunicode-display_width3.2.0indirect
RubyGemsunicode-emoji4.1.0indirect
RubyGemsunix-cryptindirect
RubyGemsunix-crypt1.3.1indirect
RubyGemsuri1.1.1indirect
RubyGemsuseragent0.16.11indirect
RubyGemswardenindirect
RubyGemswarden1.2.9indirect
RubyGemswebmock3.26.2indirect
RubyGemswebrick1.9.1indirect
RubyGemswebsocket-driver0.7.7indirect
RubyGemswebsocket-extensions0.1.5indirect
RubyGemswin32apiindirect
RubyGemswin32api0.1.0indirect
RubyGemswindows_errorindirect
RubyGemswindows_error0.1.6indirect
RubyGemswinrmindirect
RubyGemswinrm2.3.9indirect
RubyGemswith_env1.1.0indirect
RubyGemsxdrindirect
RubyGemsxdr3.0.1indirect
RubyGemsxml-simple1.1.9indirect
RubyGemsxmlrpcindirect
RubyGemsxmlrpc0.3.3indirect
RubyGemsyard0.9.37indirect
RubyGemszeitwerkindirect
RubyGemszeitwerk2.7.3indirect
Dependency advisories 19

This repository publishes no package the index resolves, so its own dependency graph was assessed — 279 packages, which also include development and test pins that never ship: 19 carry known advisories, of which 0 are direct. 102 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list.

PackageVersionRelationSeverityAdvisoriesFixed in
next15.0.4indirectcritical3316.2.11
addressable2.8.7indirecthigh12.9.0
concurrent-ruby1.3.5indirecthigh31.3.7
erb5.0.3indirecthigh16.0.4
faraday2.7.11indirecthigh32.14.3
json2.15.1indirecthigh22.19.9
mcp0.13.0indirecthigh50.23.0
nokogiri1.18.10indirecthigh111.19.4
puma6.6.0indirecthigh28.0.2
websocket-driver0.7.7indirecthigh40.8.2
aws-sdk-s31.182.0indirectmoderate11.208.0
bcrypt3.1.20indirectmoderate13.1.22
loofah2.24.1indirectmoderate12.25.2
msgpack1.6.1indirectmoderate11.8.2
net-imap0.5.6indirectmoderate90.6.4.1
rexml3.4.1indirectmoderate13.4.2
sqlite32.9.4indirectmoderate22.9.5
yard0.9.37indirectmoderate20.9.44
rails-html-sanitizer1.6.2indirectlow11.7.1

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable

Feedback

Spotted something off in this report, or have thoughts to share? Wrong measurements, missed tooling, ideas, questions — anything is welcome. Every message is read and gets a response.

The message is kept through sign-in.

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v2.10.0, schema v0.31.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsRubyGems.