{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "node-red",
    "name": "Node-RED",
    "vendor": "OpenJS Foundation",
    "vendorUrl": "https://nodered.org",
    "kind": "http-api",
    "category": "workflow-automation",
    "summary": "Node-RED is an open-source flow-based automation runtime hosted by the OpenJS Foundation. The owner runs it on Node.js, and an Admin HTTP API and a command-line client deploy flows and install nodes.",
    "url": "https://www.anchorterminal.com/tools/node-red",
    "markdownUrl": "https://www.anchorterminal.com/tools/node-red.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/node-red.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/node-red.json",
    "repo": "https://github.com/node-red/node-red",
    "license": "Apache-2.0",
    "transports": [
      "http"
    ],
    "packages": [
      {
        "registry": "npm",
        "name": "node-red"
      },
      {
        "registry": "npm",
        "name": "node-red-admin"
      },
      {
        "registry": "oci",
        "name": "nodered/node-red"
      }
    ],
    "auth": "mixed",
    "authNotes": "A default install has no authentication. Setting `adminAuth` in `settings.js` turns on users with bcrypt-hashed passwords and permissions of `*`, `read` or a list such as `flows.read`. An agent then posts the username and password to `/auth/token` for a bearer token, valid seven days by default with no refresh. Access is self-serve, by running the software. Routes made by HTTP In nodes share one basic-auth username and password.",
    "pricing": "free",
    "pricingNotes": "Free under Apache-2.0 with nothing to buy from the project, so an agent can start with no account, card or contract. FlowFuse, a separate company, sells a hosted platform for Node-RED that the docs link, and it is not graded here (https://nodered.org/about/license/, checked 2026-10-09).",
    "priceSummary": "Free · OSS",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs or the source. The project sells nothing (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 23729,
      "npmWeekly": 55172,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://nodered.org/docs/api/admin/",
    "capabilities": [
      "automation.workflows",
      "automation.webhooks",
      "automation.code",
      "automation.apps"
    ],
    "tags": [
      "self-hosted",
      "open-source",
      "local",
      "free",
      "javascript",
      "webhooks",
      "cli",
      "docker"
    ],
    "lastRelease": "2026-10-08",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 61,
      "grade": "C",
      "agentReady": false,
      "rank": 486,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 44,
        "maintenance": 81,
        "payments": 60,
        "reliability": 90,
        "schema": 41,
        "security": 51,
        "transparency": 65
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 90,
          "points": 18,
          "reason": "Graded as software the owner runs, on Node-RED 5.0.8. Official npm package `node-red` and Docker image `nodered/node-red`, with Node.js 22.9 or later required (20). Public GitHub Actions tests on Node 22 and 24, and the run on `main` for the 5.0.8 release on 8 October 2026 passed (25). 215 open issues and 122 open pull requests. Of six issues opened from 1 to 8 October, five carried `needs-triage` with no comment, though a crash reported on 8 October had a fix proposed the same day, and September's issues had one to eight comments (17). Major, minor and maintenance releases follow a written plan and 5.0.0 lists its breaking change. Two points off because 5.0.3, 5.0.4 and 5.0.6 each reverted a dependency update shipped in the release before (13). Version 5.0, with 1.0 released on 30 September 2019 (15)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 41,
          "points": 6.66,
          "reason": "No OpenAPI file or other machine-readable contract was found on the site or in the repository (0). `llms.txt` returns 404 and the docs are served as HTML only (0). Each of the 20 documented methods has a one-line purpose and the permission it needs, with nothing on when to choose it, and routes for context, plugins, library and projects are in the source but not in the method list (9). A types page describes Node, Flow, Node Module and Node Set objects in prose tables. Node objects are open, with fields set by each node type, and the deployment type header has four listed values (6). Methods carry curl and JSON examples and a status code table, and the errors page lists six codes (11). The `Node-RED-API-Version` header selects `v1` or `v2`, and the changelog is public (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 44,
          "points": 7.15,
          "reason": "`GET /flow/:id` returns one tab, but `GET /flows` and `GET /nodes` return everything with no field selection or limit (8). No pagination or filtering on any method. An `Accept` header switches `/nodes` between JSON and HTML (3). Errors use standard status codes and a `code` and `message` body on 400, with 409 documented for a stale revision (14). No idempotency key. `rev` on `POST /flows` rejects a deploy over newer flows, and `PUT /flow/:id` is safe to repeat (12). Few required parameters and sensible defaults. The only clients are the `node-red-admin` CLI and the JavaScript module, with no SDK in a second language (7)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 51,
          "points": 8.93,
          "reason": "Bearer tokens with scope `*` or `read`, per-user permissions by resource, revocation at `/auth/revoke` and a seven-day expiry. Tokens come from a username and password grant with no refresh (22). Ten off because the docs give `?access_token=` in the editor URL as the way to use a custom token (12). Read-only users, a read-only default user and per-resource write permissions. No approval step for a deploy or a module install, and `adminAuth` is off in the default settings file (12). The Admin API returns the owner's flow configuration and node metadata from npm. No guidance on untrusted content reaching an agent was found (7). An audit log of Admin API calls with user, path and IP address, off by default and written to the console logger (11). SECURITY.md gives a contact and escalation to the OpenJS Foundation CNA after six business days, and two advisories from 2021 are published. No security.txt, bug bounty or certification was found (9)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 60,
          "points": 7.5,
          "reason": "Read with the self-hosted rule. No x402, MPP or L402 (0). The software is free under Apache-2.0 and the project sells nothing, stated on the licence page without a login (20). Free to run with no card (20). An agent can install the npm package or start the Docker image and call the API with no signup (20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 81,
          "points": 7.09,
          "reason": "5.0.8 and 4.1.16 released on 8 October 2026 (30). 12 releases between 30 July and 8 October 2026 across 5.x and 4.x (20). Maintainers merge community fixes each month and September's issues were answered, but five of six issues from the first week of October were untriaged with no reply (17). No SDKs and no MCP server. The `node-red-admin` CLI is bundled and current, which earns part of the line (5). Dependencies are pinned and updated in most maintenance releases, CI runs on two Node.js versions, and Dependabot covers only the workflow actions (9)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 65,
          "points": 5.69,
          "note": "editorial 85, provenance 45",
          "reason": "Apache-2.0, copyright held by the OpenJS Foundation (30). For self-hosted use the only data that leaves the host is the opt-in telemetry report, and its page states the four fields sent, a 90-day limit on individual reports and that only core committers see raw data. The project has no privacy policy of its own, and the foundation's was not read (20). The release plan dates the maintenance start and end of life of each major version and limits breaking changes to one major a year. No notice period for Admin API changes was found (15). Telemetry is off until the user opts in, is documented field by field and has three ways to disable it (20)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`GET /flow/:id` returns one tab, but `GET /flows` and `GET /nodes` return everything with no field selection or limit (8). No pagination or filtering on any method. An `Accept` header switches `/nodes` between JSON and HTML (3). Errors use standard status codes and a `code` and `message` body on 400, with 409 documented for a stale revision (14). No idempotency key. `rev` on `POST /flows` rejects a deploy over newer flows, and `PUT /flow/:id` is safe to repeat (12). Few required parameters and sensible defaults. The only clients are the `node-red-admin` CLI and the JavaScript module, with no SDK in a second language (7).",
          "maintenance": "5.0.8 and 4.1.16 released on 8 October 2026 (30). 12 releases between 30 July and 8 October 2026 across 5.x and 4.x (20). Maintainers merge community fixes each month and September's issues were answered, but five of six issues from the first week of October were untriaged with no reply (17). No SDKs and no MCP server. The `node-red-admin` CLI is bundled and current, which earns part of the line (5). Dependencies are pinned and updated in most maintenance releases, CI runs on two Node.js versions, and Dependabot covers only the workflow actions (9).",
          "payments": "Read with the self-hosted rule. No x402, MPP or L402 (0). The software is free under Apache-2.0 and the project sells nothing, stated on the licence page without a login (20). Free to run with no card (20). An agent can install the npm package or start the Docker image and call the API with no signup (20).",
          "reliability": "Graded as software the owner runs, on Node-RED 5.0.8. Official npm package `node-red` and Docker image `nodered/node-red`, with Node.js 22.9 or later required (20). Public GitHub Actions tests on Node 22 and 24, and the run on `main` for the 5.0.8 release on 8 October 2026 passed (25). 215 open issues and 122 open pull requests. Of six issues opened from 1 to 8 October, five carried `needs-triage` with no comment, though a crash reported on 8 October had a fix proposed the same day, and September's issues had one to eight comments (17). Major, minor and maintenance releases follow a written plan and 5.0.0 lists its breaking change. Two points off because 5.0.3, 5.0.4 and 5.0.6 each reverted a dependency update shipped in the release before (13). Version 5.0, with 1.0 released on 30 September 2019 (15).",
          "schema": "No OpenAPI file or other machine-readable contract was found on the site or in the repository (0). `llms.txt` returns 404 and the docs are served as HTML only (0). Each of the 20 documented methods has a one-line purpose and the permission it needs, with nothing on when to choose it, and routes for context, plugins, library and projects are in the source but not in the method list (9). A types page describes Node, Flow, Node Module and Node Set objects in prose tables. Node objects are open, with fields set by each node type, and the deployment type header has four listed values (6). Methods carry curl and JSON examples and a status code table, and the errors page lists six codes (11). The `Node-RED-API-Version` header selects `v1` or `v2`, and the changelog is public (15).",
          "security": "Bearer tokens with scope `*` or `read`, per-user permissions by resource, revocation at `/auth/revoke` and a seven-day expiry. Tokens come from a username and password grant with no refresh (22). Ten off because the docs give `?access_token=` in the editor URL as the way to use a custom token (12). Read-only users, a read-only default user and per-resource write permissions. No approval step for a deploy or a module install, and `adminAuth` is off in the default settings file (12). The Admin API returns the owner's flow configuration and node metadata from npm. No guidance on untrusted content reaching an agent was found (7). An audit log of Admin API calls with user, path and IP address, off by default and written to the console logger (11). SECURITY.md gives a contact and escalation to the OpenJS Foundation CNA after six business days, and two advisories from 2021 are published. No security.txt, bug bounty or certification was found (9).",
          "transparency": "Apache-2.0, copyright held by the OpenJS Foundation (30). For self-hosted use the only data that leaves the host is the opt-in telemetry report, and its page states the four fields sent, a 90-day limit on individual reports and that only core committers see raw data. The project has no privacy policy of its own, and the foundation's was not read (20). The release plan dates the maintenance start and end of life of each major version and limits breaking changes to one major a year. No notice period for Admin API changes was found (15). Telemetry is off until the user opts in, is documented field by field and has three ways to disable it (20)."
        },
        "sources": [
          {
            "what": "home page",
            "url": "https://nodered.org/",
            "seen": "2026-10-09"
          },
          {
            "what": "Admin API overview",
            "url": "https://nodered.org/docs/api/admin/",
            "seen": "2026-10-09"
          },
          {
            "what": "Admin API methods, read from the website repository source after the page failed to load",
            "url": "https://nodered.org/docs/api/admin/methods/",
            "seen": "2026-10-09"
          },
          {
            "what": "Admin API authentication",
            "url": "https://nodered.org/docs/api/admin/oauth",
            "seen": "2026-10-09"
          },
          {
            "what": "Admin API errors",
            "url": "https://nodered.org/docs/api/admin/errors",
            "seen": "2026-10-09"
          },
          {
            "what": "Admin API types",
            "url": "https://nodered.org/docs/api/admin/types",
            "seen": "2026-10-09"
          },
          {
            "what": "POST /flows",
            "url": "https://nodered.org/docs/api/admin/methods/post/flows/",
            "seen": "2026-10-09"
          },
          {
            "what": "securing guide",
            "url": "https://nodered.org/docs/user-guide/runtime/securing-node-red",
            "seen": "2026-10-09"
          },
          {
            "what": "logging and audit",
            "url": "https://nodered.org/docs/user-guide/runtime/logging",
            "seen": "2026-10-09"
          },
          {
            "what": "command-line administration",
            "url": "https://nodered.org/docs/user-guide/node-red-admin",
            "seen": "2026-10-09"
          },
          {
            "what": "usage telemetry",
            "url": "https://nodered.org/docs/telemetry/",
            "seen": "2026-10-09"
          },
          {
            "what": "release plan",
            "url": "https://nodered.org/about/releases/",
            "seen": "2026-10-09"
          },
          {
            "what": "supported Node.js versions",
            "url": "https://nodered.org/docs/faq/node-versions",
            "seen": "2026-10-09"
          },
          {
            "what": "licence page",
            "url": "https://nodered.org/about/license/",
            "seen": "2026-10-09"
          },
          {
            "what": "website source, the Markdown behind the docs pages",
            "url": "https://github.com/node-red/node-red.github.io",
            "seen": "2026-10-09"
          },
          {
            "what": "source, CHANGELOG.md, SECURITY.md, settings.js, CI workflow and tags",
            "url": "https://github.com/node-red/node-red",
            "seen": "2026-10-09"
          },
          {
            "what": "repository advisories",
            "url": "https://github.com/node-red/node-red/security/advisories",
            "seen": "2026-10-09"
          },
          {
            "what": "open issues",
            "url": "https://github.com/node-red/node-red/issues",
            "seen": "2026-10-09"
          },
          {
            "what": "test workflow runs",
            "url": "https://github.com/node-red/node-red/actions/workflows/tests.yml",
            "seen": "2026-10-09"
          },
          {
            "what": "releases",
            "url": "https://github.com/node-red/node-red/releases",
            "seen": "2026-10-09"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/node-red",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt, 404",
            "url": "https://nodered.org/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.org/domain/nodered.org",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the OpenJS Foundation privacy policy and terms of use linked from the site footer were not read, because they are a parent body's website documents",
          "unchecked: the forum at discourse.nodered.org and the Slack workspace were not read, so support responsiveness rests on GitHub issues alone",
          "unchecked: the Docker Hub page for `nodered/node-red` was not read. The image name comes from the project's Docker guide",
          "unchecked: https://nodered.org/docs/api/admin/methods/ failed with a connection error on one request and was not retried. The page's Markdown source in node-red/node-red.github.io was read instead",
          "Whether the 5.0.2 change to session messages (pull request 5883) and the September move to a patched copy of JSONata fixed security flaws. Neither has an advisory or a note in the changelog",
          "The lead named the vendor as OpenJS Foundation / Node-RED project and the interface as Admin HTTP API, flow HTTP endpoints and CLI. All three hold. The CLI manages nodes and has no command for flows",
          "The RDAP lookup through rdap.org followed a redirect to the registry's RDAP host before that host's robots.txt was read"
        ]
      },
      "negative": 0,
      "verdict": "Node-RED's Admin HTTP API covers flows, nodes and settings in 20 documented methods, with read and write permissions per resource and a revision check on deploys. It has no OpenAPI file, no pagination and no SDK, and a default install accepts API calls from anyone who can reach port 1880.",
      "bestFor": "Owners who want event-driven flows on their own machine or device, with a large library of community nodes, and an agent that deploys or edits flows as JSON.",
      "strengths": [
        "Apache-2.0, with 12 releases between 30 July and 8 October 2026 on the 5.x and 4.x lines",
        "Admin API permissions are per resource, such as `flows.read` and `flows.write`, and a user or token can be limited to `read`",
        "`POST /flows` with `Node-RED-API-Version: v2` takes a `rev` value and answers 409 when the runtime holds newer flows",
        "Usage telemetry is opt-in, lists the four fields sent, and can be switched off in settings, by flag or by environment variable",
        "A release plan gives each major version a maintenance start and an end-of-life date, with 4.x ending on 31 December 2026"
      ],
      "weaknesses": [
        "No OpenAPI file, `llms.txt` or SDK. The Admin API is documented as 20 hand-written pages on nodered.org",
        "`adminAuth` is commented out in the default settings file, so a fresh install has no authentication on the editor or the Admin API",
        "No pagination, filtering or field selection. `GET /flows` returns the whole flow configuration",
        "Access tokens come from a username and password grant, last seven days by default and cannot be refreshed",
        "Routes for context, plugins, library and projects exist in the source and are missing from the published method list"
      ],
      "agentNotes": [
        "Call `GET /auth/login` first. An empty object means no authentication is set and every Admin API call is open",
        "Send `Node-RED-API-Version: v2` and the last `rev` on `POST /flows`, and re-read the flows on a 409",
        "Set `Node-RED-Deployment-Type` to `nodes` or `flows` to restart only what changed. The default `full` stops every node",
        "Prefer `GET /flow/:id` and `PUT /flow/:id` for one tab. `GET /flows` returns every node in the runtime",
        "Treat `flows.write` and `nodes.write` as code execution on the host. Function nodes run JavaScript and `POST /nodes` installs npm modules"
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 61
        }
      ],
      "editorialScores": {
        "ergonomics": 44,
        "maintenance": 81,
        "payments": 60,
        "reliability": 90,
        "schema": 41,
        "security": 51,
        "transparency": 85
      },
      "provenanceScore": 45
    },
    "connect": {
      "install": "sudo npm install -g node-red",
      "http": "curl http://localhost:1880/auth/token --data 'client_id=node-red-admin\u0026grant_type=password\u0026scope=*\u0026username=admin\u0026password=password'"
    },
    "letme": {
      "capability": "https://letme.dev/automation.workflows",
      "tool": "https://letme.dev/node-red"
    },
    "notable": [
      "By default the editor and Admin API are not secured, and the docs say this suits only a trusted network (https://nodered.org/docs/user-guide/runtime/securing-node-red)",
      "The docs give `?access_token=\u003cACCESS_TOKEN\u003e` in the editor URL as the way to sign in with a custom token (https://nodered.org/docs/user-guide/runtime/securing-node-red)",
      "Two advisories are published on the repository, both from 19 February 2021 (https://github.com/node-red/node-red/security/advisories)",
      "5.0.0 on 9 June 2026 raised the minimum Node.js version to 22.9, listed under Breaking Changes in the changelog (https://github.com/node-red/node-red/blob/main/CHANGELOG.md)",
      "Releases 5.0.3, 5.0.4 and 5.0.6 each reverted a dependency update from the release before, two for JSONata and one for bcrypt (https://github.com/node-red/node-red/blob/main/CHANGELOG.md)",
      "The diagnostics page says `GET /diagnostics` needs `settings.read`. The source checks `diagnostics.read` (https://nodered.org/docs/api/admin/methods/get/diagnostics/)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Version graded",
        "value": "Node-RED 5.0.8 (8 October 2026), self-hosted. Requires Node.js 22.9 or later, and the project recommends Node 24. FlowFuse, a separate company's hosted platform for Node-RED, is not graded here"
      },
      {
        "label": "Admin API",
        "value": "HTTP and JSON on the editor port, 1880 by default, under `httpAdminRoot`. 20 documented methods for `/auth`, `/settings`, `/diagnostics`, `/flows`, `/flows/state`, `/flow/:id` and `/nodes` (https://nodered.org/docs/api/admin/methods/)"
      },
      {
        "label": "Auth",
        "value": "None by default. With `adminAuth` set, `POST /auth/token` exchanges a username and password for a bearer token with scope `*` or `read`, valid seven days unless `sessionExpiryTime` changes it, revoked at `POST /auth/revoke`. OAuth and OpenID sign-in through Passport strategies, and a `tokens` function for the owner's own tokens"
      },
      {
        "label": "Permissions",
        "value": "Per resource, read or write, such as `flows.read`, `flows.write`, `nodes.write`, `settings.read` and `context.read`. A user holds `*`, `read` or a list"
      },
      {
        "label": "Deploys",
        "value": "`POST /flows` replaces the whole configuration. `Node-RED-Deployment-Type` is `full`, `nodes`, `flows` or `reload`. With API version `v2` a stale `rev` gets 409"
      },
      {
        "label": "Flow endpoints",
        "value": "HTTP In nodes publish routes written in a flow. `httpNodeAuth` sets one basic-auth username and password for all of them, and `httpNodeMiddleware` takes Express middleware such as a rate limiter"
      },
      {
        "label": "Errors",
        "value": "200, 204, 400, 401, 404, 409 and 500. A 400 carries `code` and `message`, with six documented codes such as `invalid_request`, `type_in_use` and `invalid_api_version`"
      },
      {
        "label": "Rate limits",
        "value": "None on the Admin API. The password grant refuses a username after more than five attempts in ten minutes, per the source"
      },
      {
        "label": "CLI",
        "value": "`node-red admin`, built in since 1.1.0 and published separately as `node-red-admin`, with `target`, `login`, `list`, `info`, `enable`, `disable`, `search`, `install`, `remove` and `hash-pw`. It has no command for flows"
      },
      {
        "label": "Audit",
        "value": "`logging.console.audit: true` logs each Admin API call with event, path, IP address, time and, when `adminAuth` is set, the user. Off by default"
      },
      {
        "label": "Releases",
        "value": "One major a year, timed to Node.js. 5.x since 9 June 2026. 4.x in maintenance until 31 December 2026 (https://nodered.org/about/releases/)"
      },
      {
        "label": "Telemetry",
        "value": "Opt-in since 4.1.0. Sends an instance identifier, Node-RED version, Node.js version and OS details once a day. Individual reports kept up to 90 days. Disabled by `telemetry.enabled: false`, `--no-telemetry` or `NODE_RED_DISABLE_TELEMETRY`"
      },
      {
        "label": "Tests",
        "value": "GitHub Actions runs build, lint and 135 mocha spec files on Node 22 and 24. The run on `main` for the 5.0.8 release on 8 October 2026 passed"
      }
    ],
    "provenance": {
      "legalEntity": "OpenJS Foundation",
      "domain": "nodered.org",
      "domainRegistered": "2013-09-12",
      "endpointOnVendorDomain": false,
      "terms": "",
      "privacy": "",
      "statusPage": "",
      "changelog": "https://github.com/node-red/node-red/blob/main/CHANGELOG.md",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The licence page on nodered.org says copyright is retained by the OpenJS Foundation, and the site footer reads Copyright OpenJS Foundation and Node-RED contributors.",
        "No terms or privacy link is given. Node-RED is Apache-2.0 software the owner runs, and the project publishes no service agreement or privacy policy of its own. The site footer links the OpenJS Foundation's terms of use and privacy policy, which are a parent body's website documents and were not read.",
        "The Admin API answers on the owner's own host, by default http://localhost:1880. Only the opt-in telemetry report goes to an endpoint the project hosts.",
        "https://nodered.org/.well-known/security.txt returns 404. SECURITY.md in the repository gives team@nodered.org and escalation to the OpenJS Foundation CNA.",
        "RDAP for nodered.org gives a registration date of 2013-09-12. The lookup through rdap.org was redirected to the registry's RDAP host.",
        "nodered.org has no robots.txt (404). No status page exists because there is no hosted service."
      ],
      "score": 45,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "OpenJS Foundation",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "nodered.org, registered 2013-09-12 (13 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": " is not on nodered.org",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Terms of service",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Privacy policy",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/node-red.json",
    "live": {
      "slug": "node-red",
      "versions": [
        {
          "registry": "github",
          "name": "node-red/node-red",
          "version": "5.0.8",
          "released": "2026-10-08",
          "seenAt": "2026-10-09T17:08:22.991909994Z"
        },
        {
          "registry": "npm",
          "name": "node-red",
          "version": "5.0.8",
          "seenAt": "2026-10-09T17:08:20.781082858Z"
        },
        {
          "registry": "npm",
          "name": "node-red-admin",
          "version": "4.1.8",
          "seenAt": "2026-10-09T17:08:21.396260251Z"
        }
      ],
      "githubStars": 23730,
      "npmWeekly": 55172,
      "pages": [
        {
          "url": "https://raw.githubusercontent.com/node-red/node-red/main/CHANGELOG.md",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-09T18:45:37.181546944Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "4223a5392d5c"
        }
      ],
      "updatedAt": "2026-10-09T18:45:37.181546944Z"
    }
  }
}
