82
/ 100
Good shape overall. A few tweaks would push it into the top tier.
Automatically scan AUR packages for malware before installing (using LLM/AI)
Top fixes
Highest-impact changes first, ranked by point weight
- 1CI/CD14pt
Add a lint step to catch style issues automatically.
- 2CI/CD14pt
Add `tsc --noEmit`, `mypy`, or `cargo check` to catch type errors before they merge.
- 3CI/CD14pt
Upload coverage to Codecov, Coveralls, or report it with `--coverage` flags.
- 4Install and run instructions9pt
Add a .env.example listing all required environment variables so contributors know what to set up.
Working through the fixes? Let every push regrade itself.
The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.
Scorecard
Every check, grouped by category and sorted worst-first
Documentation
85
Contributing guidance is in the README, not a dedicated CONTRIBUTING.md (−20 pts).
→ Moving it to a CONTRIBUTING.md makes it easier to find and keeps the README focused. A dedicated file earns +47 pts base.
README documents how to install the project.
README is present.
Licensed under Other.
Engineering
72
No issue or PR templates found (−100 pts).
→ Add .github/ISSUE_TEMPLATE/ with bug_report.md and feature_request.md to guide contributors. It dramatically improves issue quality.
No dependency lockfile found (−70 pts).
→ Commit go.sum so Go module downloads are repeatable.
CI is configured (.github/workflows/ci.yml).
Test files detected (cmd/aurscan/paclist_test.go).
Formatting enforced (gofmt (built into Go toolchain)).
Project health
100
Dependency manifest found (go.mod).
Repository has a description.
Actively maintained (pushed within the last month).
.gitignore present.
Repository health signals
Activity, community, and responsiveness at scan time
Activity
- 51 / 51Commits (30d / 90d)
- 10Forks
- 15Releaseslatest 1mo ago
Community
- 42% - WeakCommunity health
- -authors own >50% of commits
- 104Watchers
Responsiveness
- 4hMedian issue response
- 14hMedian PR merge time
- 2Open issues
Repository files12 root entries
- .githubGood: CI is configured (.github/workflows/ci.yml).
- cmdGood: Test files detected (cmd/aurscan/paclist_test.go).
- internal
- packaging
- testdata
- .gitignoreGood: .gitignore present.
- CHANGELOG.md
- go.modGood: Dependency manifest found (go.mod).
- install.sh
- LICENSEGood: Licensed under Other.
- Makefile
- README.mdGood: README is present.Good: README is well structured with multiple sections.Good: README includes screenshots or visuals. Great for first impressions.Good: README has code examples.Good: README links to a live demo or deployed app.Good: README includes status badges.Good: README documents how to install the project.Good: README documents how to run the project.
Add this badge to your README
It updates automatically each time the repo is re-graded.
[](https://www.repo-grade.com/report/manticore-projects/aurscan)