82

/ 100

GradeB

Good shape overall. A few tweaks would push it into the top tier.

Top 28% of 5,156 graded repos

Automatically scan AUR packages for malware before installing (using LLM/AI)

Top fixes

Highest-impact changes first, ranked by point weight

11 to address
  1. 1
    CI/CD14pt

    Add a lint step to catch style issues automatically.

  2. 2
    CI/CD14pt

    Add `tsc --noEmit`, `mypy`, or `cargo check` to catch type errors before they merge.

  3. 3
    CI/CD14pt

    Upload coverage to Codecov, Coveralls, or report it with `--coverage` flags.

  4. 4
    Install and run instructions9pt

    Add a .env.example listing all required environment variables so contributors know what to set up.

Working through the fixes? Let every push regrade itself.

The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.

Install the GitHub App

Scorecard

Every check, grouped by category and sorted worst-first

Documentation

85

Contributing guide5pt25

Contributing guidance is in the README, not a dedicated CONTRIBUTING.md (−20 pts).

Moving it to a CONTRIBUTING.md makes it easier to find and keeps the README focused. A dedicated file earns +47 pts base.

Install and run instructions9pt90

README documents how to install the project.

README12pt100

README is present.

License6pt100

Licensed under Other.

Engineering

72

Issue and PR templates6pt0

No issue or PR templates found (−100 pts).

Add .github/ISSUE_TEMPLATE/ with bug_report.md and feature_request.md to guide contributors. It dramatically improves issue quality.

Reproducibility6pt5

No dependency lockfile found (−70 pts).

Commit go.sum so Go module downloads are repeatable.

CI/CD14pt85

CI is configured (.github/workflows/ci.yml).

Tests18pt100

Test files detected (cmd/aurscan/paclist_test.go).

Linting and formatting5pt100

Formatting enforced (gofmt (built into Go toolchain)).

Project health

100

Dependency manifest6pt100

Dependency manifest found (go.mod).

Repository metadata5pt100

Repository has a description.

Activity5pt100

Actively maintained (pushed within the last month).

Housekeeping3pt100

.gitignore present.

Repository health signals

Activity, community, and responsiveness at scan time

Activity

  • 51 / 51
    Commits (30d / 90d)
  • 10
    Forks
  • 15
    Releaseslatest 1mo ago

Community

  • 42% - Weak
    Community health
  • -
    authors own >50% of commits
  • 104
    Watchers

Responsiveness

  • 4h
    Median issue response
  • 14h
    Median PR merge time
  • 2
    Open issues
Repository files12 root entries
  • .github
    Good: CI is configured (.github/workflows/ci.yml).
  • cmd
    Good: Test files detected (cmd/aurscan/paclist_test.go).
  • internal
  • packaging
  • testdata
  • .gitignore
    Good: .gitignore present.
  • CHANGELOG.md
  • go.mod
    Good: Dependency manifest found (go.mod).
  • install.sh
  • LICENSE
    Good: Licensed under Other.
  • Makefile
  • README.md
    Good: README is present.
    Good: README is well structured with multiple sections.
    Good: README includes screenshots or visuals. Great for first impressions.
    Good: README has code examples.
    Good: README links to a live demo or deployed app.
    Good: README includes status badges.
    Good: README documents how to install the project.
    Good: README documents how to run the project.
RepoGrade badge preview

Add this badge to your README

It updates automatically each time the repo is re-graded.

[![RepoGrade](https://www.repo-grade.com/api/badge/manticore-projects/aurscan)](https://www.repo-grade.com/report/manticore-projects/aurscan)

More graded Go repos