Inspect the provenance of any open source contributor at a glance. Trace contribution history, assess license obligations, and surface trust signals before they become risks.
23 signals across 5 weighted categories produce a transparent trust score and letter grade for any GitHub contributor.
AI-powered analysis explains why a contributor is flagged — not just an abstract number, but full context.
Historical data-powered heuristics detect burst-vanish patterns, velocity anomalies, and synthetic profiles.
Identify bot accounts and AI-generated contributions as a separate transparency dimension.
See the license obligations across every repo to which a contributor has committed.
Automate PR author scoring in your repo with a GitHub Action to gate merges on contributor trust.
Signals map to 8 of 20 NIST SSDF practices — audit-ready evidence of contributor vetting.
Integrate trust scoring into your existing internal systems using the DevTrace API.
DevTrace has no plans, no pricing, and no subscriptions — every feature is available to every account.
It is operated on a best-effort basis: no SLA, no uptime guarantee, and no support commitment. Per-account limits exist only to keep the shared instance responsive for everyone using it.
The source for this service is on GitHub, under the Apache License 2.0. You are welcome to run your own instance.