Registry › Compare › Deepsec vs REA

Deepsec vs REA

REA leads on trust: 73.8/100 (Grade B) against 57.0/100 (Grade C), a 16.8-point gap. Deepsec leads on adoption; REA leads on provenance and supply-chain integrity, and rests on broader evidence.

C Deepsec 57.0

Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents

vercel-labs/deepsec · #718 overall · #10 Security & Guardrails · coverage C (2/5)

Choose Deepsec if adoption matters most.

  • +0.6Adoption: 8k GitHub stars against 415
B REA 73.8

Reverse engineer anything with agents, from app behavior down to native binaries.

morluto/rea · #246 overall · #4 Security & Guardrails · coverage B (3/5)

Choose REA if provenance and supply-chain integrity matter most.

  • +7.2Identity / Provenance: package provenance attested, against none
  • +4.8Safety / Integrity: package provenance attested, against none
  • B vs CEvidence coverage: 3 of 5 independent signal types, against 2

Where they differ

11.1
Safety / IntegrityREA +4.8
15.9
10.8
Identity / ProvenanceREA +7.2
18.0
13.0
MaintenanceDeepsec +0.3
12.7
9.4
AdoptionDeepsec +0.6
8.8
+0.0
Runtime calibrationREA +5.7
+5.7

1 dimension identical: Transparency 12.7 · Full evidence table

An independent, evidence-based trust comparison of Deepsec and REA, two Security & Guardrails projects in the HVTracker registry. Scores come from public, checkable signals — supply-chain provenance, OSSF Scorecard, maintenance, and adoption — not popularity.

Full evidence

Signal Deepsecvercel-labs/deepsec REAmorluto/rea
HVTrust score 57.0 73.8
Evidence grade C B
Coverage grade C B
Overall rank #718 #246
Rank in Security & Guardrails #10 #4
GitHub stars 8.0k 415
Last updated 3d ago 18d ago
Build provenance No Yes
OSSF Scorecard 4.9 / 10 4.9 / 10
License Apache-2.0 MIT
Downloads — 72/wk
Trust dimensions (points earned)
Safety / integrity / 25 11.1 15.9
Identity & provenance / 18 10.8 18.0
Transparency / 17 12.7 12.7
Maintenance / 20 13.0 12.7
Adoption / 20 9.4 8.8
Runtime capability surface (full matrix)
MCP server — Implemented
External providers — —
Requires API keys No No
Plugin surface — —
Provenance drift — Match
Open in the live compare tool → Deepsec profile REA profile More Security & Guardrails →

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption, scaled by an evidence-confidence factor. Grade bands: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Signals refresh daily. Full methodology v4.3 →