@cyberhub/trust-faker
v1.0.65
Published
Security Trust Report: [email protected] — 54/100 (C, standard). 1 vulnerability found. Maintainer risk, supply chain analysis from 8 security databases.
Maintainers
Readme
Security Trust Report: faker
[email protected]: 54/100 | Grade: C | Tier: STANDARD (confidence: ±3)
Scanned on 2026-04-18 from 8 security databases. View package on npm →
TL;DR
- 1 vulnerability found (0 critical, 1 high)
- Consider switching to @faker-js/faker (Community fork, actively maintained)
- Pin your version and monitor for changes
⚠️ Security Incident Background
In January 2022, the same maintainer (marak) deleted all code from faker and replaced it with a protest message. The community fork @faker-js/faker was created to restore the functionality.
Score Breakdown
Maintainer Trust: ████████░░░░░░░░░░░░ 38/100
Package Health: ██████████████████░░ 90/100
Supply Chain: █████████░░░░░░░░░░░ 47/100
Community: █████████░░░░░░░░░░░ 43/100Why this score?
- Maintainer Trust is 38 because: single maintainer (bus factor risk), maintainer changes detected
- Supply Chain is 47 because: 1 known CVEs, in breach database
- Community is 43 because: no public GitHub repo linked (may be private or on another platform)
Vulnerabilities (1 vulnerability)
| Severity | Count | |----------|-------| | 🟠 High | 1 |
Key Risk Flags
- 🔴 CRITICAL: HISTORICAL BREACH: Maintainer sabotaged — deleted all code (2022)
- 🔴 CRITICAL: Maintainer "marak" has history of package sabotage
- 🟠 HIGH: Maintainer(s) removed in v2.1.4: fotoverite (evidence)
- 🟠 HIGH: 1 HIGH vulnerability detected
🛠️ What Should You Do?
Immediate:
- 📌 Pin to known-safe version: Use @faker-js/faker instead (community fork)
- 🔄 Or replace with @faker-js/faker — Community fork, actively maintained
- 📖 Review the security incident above
Always: Pin version, run pkgtrust scan in CI, monitor at nrupak.com/trust/faker
🔄 Safer Alternatives
| Package | Why | npm | Trust Score | |---------|-----|-----|-------------| | @faker-js/faker | Community fork, actively maintained | npm | View score | | chance | Random data generator | npm | View score |
Maintainers (1)
- ⛔ marak — COMPROMISED: Deliberately sabotaged colors and faker (2022) (Trust profile)
Methodology: 18+ signals across 4 categories (Maintainer 35%, Package 25%, Supply Chain 25%, Community 15%). Full scoring docs →
Check your project: npm i -g @cyberhub/pkgtrust && pkgtrust scan faker — CLI docs
Data Sources: GitHub Advisories · OSV.dev · npm audit · Snyk · Socket.dev · npms.io · Bundlephobia · deps.dev · CISA KEV · Packagephobia · OpenSSF Scorecard · Ecosyste.ms · GitHub Enhanced · Keybase · npm Provenance
Report by pkgtrust · Dashboard · Compare · CLI
This is an automated security report. Not affiliated with the faker team. Updated 2026-04-18.
