Is Plugin Code Analyzer Safe?

Plugin Code Analyzer — Nerq Trust Score 75.0/100 (B+ grade). Based on analysis of 2 trust dimensions, it is generally safe but has some concerns. Last updated: 2026-04-07.

Yes, Plugin Code Analyzer is safe to use. Plugin Code Analyzer is a npm package with a Nerq Trust Score of 75.0/100 (B+), based on 3 independent data dimensions. Recommended for production use. Security: 90/100. Popularity: 60/100. Data sourced from npm registry, GitHub repository, NVD, OSV.dev, and OpenSSF Scorecard. Last updated: 2026-04-07. Machine-readable data (JSON).

Is Plugin Code Analyzer safe?

YES — Plugin Code Analyzer has a Nerq Trust Score of 75.0/100 (B+). It meets Nerq's trust threshold with strong signals across security, maintenance, and community adoption. Recommended for production use — review the full report below for specific considerations.

Security Analysis → Plugin Code Analyzer Privacy Report →

What is Plugin Code Analyzer's trust score?

Plugin Code Analyzer has a Nerq Trust Score of 75.0/100, earning a B+ grade. This score is based on 2 independently measured dimensions including security, maintenance, and community adoption.

Security
90
Popularity
60

What are the key security findings for Plugin Code Analyzer?

Plugin Code Analyzer's strongest signal is security at 90/100. No known vulnerabilities have been detected. It meets the Nerq Verified threshold of 70+.

Security score: 90/100 (strong)
Popularity: 60/100 — community adoption

What is Plugin Code Analyzer and who maintains it?

Authordemianbrecht
Categorynpm Packages
SourceN/A

Similar Npm by Trust Score

@eslint/eslintrc (85)@opentelemetry/resource-detector-alibaba-cloud (85)@tiptap/extension-code (85)@tiptap/extension-link (85)@sanity/sdk (85)
See all safest Npm →

Compare

Plugin Code Analyzer vs @eslint/eslintrcPlugin Code Analyzer vs @opentelemetry/resource-detector-alibaba-cloudPlugin Code Analyzer vs @tiptap/extension-code

Safety Guide: Plugin Code Analyzer

What is Plugin Code Analyzer?

Plugin Code Analyzer is a Node.js package — Salesforce Code Analyzer is a unified tool to help Salesforce developers analyze their source code for security vulnerabilities, performance issues, best practices, and more..

How to Verify Safety

Run npm audit to check for vulnerabilities. Review the package's GitHub repository for recent commits.

You can also check the trust score via API: GET /v1/preflight?target=@salesforce/plugin-code-analyzer

Key Safety Concerns for Node.js package

When evaluating any Node.js package, watch for: dependency vulnerabilities, malicious packages, typosquatting.

Trust Assessment

Plugin Code Analyzer has a Nerq Trust Score of 75/100 (B+) and meets Nerq trust threshold. This score is based on automated analysis of security, maintenance, community, and quality signals.

Key Takeaways

Frequently Asked Questions

Is Plugin Code Analyzer Safe?
Yes, it is safe to use. @salesforce/plugin-code-analyzer with a Nerq Trust Score of 75.0/100 (B+). Strongest signal: security (90/100). Score based on Security (90/100), Popularity (60/100).
What is Plugin Code Analyzer's trust score?
@salesforce/plugin-code-analyzer: 75.0/100 (B+). Score based on Security (90/100), Popularity (60/100). Scores update as new data becomes available. API: GET nerq.ai/v1/preflight?target=@salesforce/plugin-code-analyzer
What are safer alternatives to Plugin Code Analyzer?
In the npm Packages category, more Node.js packages are being analyzed — check back soon. @salesforce/plugin-code-analyzer scores 75.0/100.
Does Plugin Code Analyzer have known vulnerabilities?
Nerq checks Plugin Code Analyzer against NVD, OSV.dev, and registry-specific vulnerability databases. Current security score: 90/100. Run your package manager's audit command for the latest findings.
Is Plugin Code Analyzer actively maintained?
Plugin Code Analyzer maintenance score: N/A. Check the repository for recent commit activity and issue responsiveness.
API: /v1/preflight Trust Badge API Docs

See Also

Disclaimer: Nerq trust scores are automated assessments based on publicly available signals. They are not endorsements or guarantees. Always conduct your own due diligence.

We use cookies for analytics and caching. Privacy