RepoPilot

ogham/exa vs ruvnet/ruview

Both showing Mixed signals — pick on fit, not health

As of September 2026, exa and ruview both show mixed maintenance signals. exa last saw a commit 1 year ago with 27+ active contributors, while ruview was committed to 1 week ago with 2+ active contributors. Both use the MIT license. ruview has no known critical CVEs, while exa has 2.

Informational only. RepoPilot summarises public signals at the time of analysis. Not professional, security, or legal advice.

ogham/exa

Mixed

Stale — last commit 2y ago

MixedDependency

last commit was 2y ago; 2 high-severity CVEs in dependencies…

HealthyFork & modify

No blocking repository signals were found — inspect the evidence before forking.

HealthyLearn from

Documented and popular — useful reference codebase to read through.

ConcernsDeploy as-is

2 high-severity CVEs in dependencies; last commit was 2y ago…

  • Stale — last commit 2y ago
  • No tests detected in the complete Git tree
  • Scorecard: marked unmaintained (0/10)
  • Scorecard: default branch unprotected (0/10)
  • 2 moderate-severity advisories on direct dependencies
  • 2 high-severity advisories in transitive deps
  • 27+ active contributors
  • Distributed ownership (top contributor 41% of recent commits)
  • MIT licensed
  • CI configured

What would improve this?

  • Use as dependency Mixed to Healthy if: 1 commit in the last 365 days; resolve the high-severity advisories
  • Deploy as-is Concerns to Mixed if: resolve the high-severity advisories

Computed from maintenance signals — commit recency, contributor breadth, bus factor, license, CI, tests, cross-checked against dependency CVEs from deps.dev and OpenSSF Scorecard

ruvnet/ruview

Mixed

Mixed signals — read the receipts

HealthyDependency

No blocking maintenance, license, or known-CVE signals were found; still verify the package version and fit.

HealthyFork & modify

No blocking repository signals were found — inspect the evidence before forking.

HealthyLearn from

Documented and popular — useful reference codebase to read through.

MixedDeploy as-is

Scorecard "Branch-Protection" is 0/10; 1 cyclic import chain detected

  • Small team — 2 contributors active in recent commits
  • Concentrated ownership — top contributor handles 71% of recent commits
  • Scorecard: default branch unprotected (0/10)
  • Last commit today
  • 2 active contributors
  • MIT licensed
  • CI configured
  • Tests present

What would improve this?

  • Deploy as-is Mixed to Healthy if: bring "Branch-Protection" to ≥3/10 (see scorecard report)

Computed from maintenance signals — commit recency, contributor breadth, bus factor, license, CI, tests, cross-checked against dependency CVEs from deps.dev and OpenSSF Scorecard

Signal-by-signal breakdown

exaruview
Stars24,44492,443
Last commit1y ago13d ago
LicenseMITMIT
Open issues213613
Has testsNo
Has CI
Test coverage0%24%
Dependency CVEs0 critical · 2 high · 31 moderate · 0 lowNo CVEs
Architecture gradeCA
Cycles81
Bottom-lineMixed signalsMixed signals

Want the full analysis? ogham/exa · ruvnet/ruview

Ask AI about ogham/exa vs ruvnet/ruview

Open the chat with a comparison question pre-filled.