Is Dependabot Composer Safe?
Use Dependabot Composer with some caution. Dependabot Composer is a Ruby gem with a Nerq Trust Score of 68.2/100 (B-), based on 3 independent data dimensions. It is below the recommended threshold of 70. Security: 90/100. Popularity: 100/100. Data sourced from rubygems.org, GitHub, and NVD. Last updated: 2026-03-29. Machine-readable data (JSON).
Is Dependabot Composer safe?
CAUTION — Dependabot Composer has a Nerq Trust Score of 68.2/100 (B-). It has moderate trust signals but shows some areas of concern that warrant attention. Suitable for development use — review security and maintenance signals before production deployment.
Trust Score Breakdown
Key Findings
Details
| Author | Dependabot |
| Category | gems |
| Source | N/A |
Safety Guide: Dependabot Composer
What is Dependabot Composer?
Dependabot Composer is a Ruby gem — Dependabot-Composer provides support for bumping PHP (composer) libraries via Dependabot. If you want support for multiple package managers, you probably want the meta-gem dependabot-omnibus..
How to Verify Safety
Run bundle audit. Review on rubygems.org.
You can also check the trust score via API: GET /v1/preflight?target=dependabot-composer
Key Safety Concerns for Ruby gems
When evaluating any Ruby gem, watch for: dependency vulnerabilities, maintenance status.
Trust Assessment
Dependabot Composer has a Nerq Trust Score of 68/100 (B-) and has not yet reached Nerq trust threshold (70+). This score is based on automated analysis of security, maintenance, community, and quality signals.
Key Takeaways
- Dependabot Composer has a Trust Score of 68/100 (B-).
- Review carefully before use — below trust threshold.
- Always verify independently using the Nerq API.
Frequently Asked Questions
Is Dependabot Composer safe to use?
What is Dependabot Composer's trust score?
What are safer alternatives to Dependabot Composer?
Does Dependabot Composer have known vulnerabilities?
How actively maintained is Dependabot Composer?
Popular in gems
Disclaimer: Nerq trust scores are automated assessments based on publicly available signals. They are not endorsements or guarantees. Always conduct your own due diligence.