Loading...
Database for researching & tracking open source components with safety scores.

Database for researching & tracking open source components with safety scores.
Componentpedia is a searchable database and research tool by Meterian for discovering, evaluating, and tracking open source software components across multiple programming languages. The platform provides scored assessments of open source components across three dimensions: **Maintenance Score:** Evaluates how actively a component is maintained by calculating the average time gap between source code updates in its open source repository. A smaller gap between updates results in a higher score. **Safety Score:** Assesses the security history of a component by comparing vulnerable versions against safe versions across the component's version history. Starting from the latest version, each prior version is analyzed and scored based on its threat level. **Popularity Score:** Measures community adoption by analyzing usage metrics such as GitHub forks and watchers, producing a coefficient of popularity relative to comparable components. Componentpedia currently lists over 1.09 million components for NodeJS, with support for Erlang/Elixir, .NET, Rust, and Perl. Additional language support (Python, Java, Kotlin, JavaScript, Ruby, PHP, Scala, Go, Swift, Dart, R, and C/C++) is listed as coming soon. The platform also provides vulnerability coverage comparison data, allowing users to compare Meterian's component vulnerability coverage against other industry databases across supported languages.
Common questions about Meterian Componentpedia including features, pricing, alternatives, and user reviews.
Meterian Componentpedia is Database for researching & tracking open source components with safety scores. developed by Meterian. It is a Application Security solution designed to help security teams with SCA, Open Source, Package Security.
AI-driven app & supply chain security platform with SBOM generation & scanning
Tracks OSS components, monitors vulnerabilities, and ensures license compliance
Get strategic cybersecurity insights in your inbox