94

/ 100

GradeA

Excellent work. The main thing left to polish is a contributing guide.

Top 7% of 5,156 graded repos

WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com

Top fixes

Highest-impact changes first, ranked by point weight

4 to address
  1. 1
    Tests18pt

    Wire your tests to a documented command (e.g. a test script in your build config) so the suite is reproducible.

  2. 2
    Install and run instructions9pt

    Add a .env.example listing all required environment variables so contributors know what to set up.

  3. 3
    Contributing guide5pt

    Move the file to the repo root or docs/CONTRIBUTING.md so its setup, style, test, and PR sections can be graded.

  4. 4
    Contributing guide5pt

    A CODE_OF_CONDUCT.md signals that your project is welcoming. GitHub has a template you can add in one click.

Working through the fixes? Let every push regrade itself.

The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.

Install the GitHub App

Scorecard

Every check, grouped by category and sorted worst-first

Documentation

93

Contributing guide5pt72

CONTRIBUTING guide found.

Install and run instructions9pt90

README documents how to install the project.

README12pt100

README is present.

License6pt100

Licensed under Other.

Engineering

93

Tests18pt80

Test files detected (spec).

CI/CD14pt100

CI is configured (.github/workflows/build.yml).

Linting and formatting5pt100

Ruby linting configured (.rubocop.yml).

Reproducibility6pt100

Lockfile present (spec/fixtures/dynamic_finders/plugin_version/acf-content-analysis-for-yoast-seo/composer_file/package-lock.json). Installs are reproducible.

Issue and PR templates6pt100

Issue or PR templates present.

Project health

100

Dependency manifest6pt100

Dependency manifest found (Gemfile).

Repository metadata5pt100

Repository has a description.

Activity5pt100

Actively maintained (pushed within the last month).

Housekeeping3pt100

.gitignore present.

Repository health signals

Activity, community, and responsiveness at scan time

Activity

  • 5 / 59
    Commits (30d / 90d)
  • 1,348
    Forks
  • 68
    Releaseslatest 7y ago

Community

  • 62% - Fair
    Community health
  • 2 bus factor
    authors own >50% of commits
  • 9,724
    Watchers

Responsiveness

  • 4h
    Median issue response
  • 1h
    Median PR merge time
  • 0
    Open issues
Repository files21 root entries
  • .github
    Good: CONTRIBUTING guide found.
    Issue: CONTRIBUTING guide contents could not be read (−28 pts vs a readable file).Fix: Move the file to the repo root or docs/CONTRIBUTING.md so its setup, style, test, and PR sections can be graded.
    Good: CI is configured (.github/workflows/build.yml).
    Good: Dependabot covers 2 ecosystems (bundler, github-actions). Dependencies stay current.
    Good: Issue or PR templates present.
  • .qlty
  • app
  • bin
  • lib
  • spec
    Good: Test files detected (spec).
    Good: Lockfile present (spec/fixtures/dynamic_finders/plugin_version/acf-content-analysis-for-yoast-seo/composer_file/package-lock.json). Installs are reproducible.
  • .dockerignore
  • .gitignore
    Good: .gitignore present.
  • .rspec
  • .rubocop.yml
    Good: Ruby linting configured (.rubocop.yml).
  • .ruby-gemset
  • .ruby-version
  • .simplecov
  • AGENTS.md
  • CLAUDE.md
  • Dockerfile
    Good: Environment pinned via Dockerfile.
  • Gemfile
    Good: Dependency manifest found (Gemfile).
  • LICENSE
    Good: Licensed under Other.
  • Rakefile
  • README.md
    Good: README is present.
    Good: README is well structured with multiple sections.
    Good: README includes screenshots or visuals. Great for first impressions.
    Good: README has code examples.
    Good: README links to a live demo or deployed app.
    Good: README includes status badges.
    Good: README documents how to install the project.
    Good: README documents how to run the project.
  • wpscan.gemspec
RepoGrade badge preview

Add this badge to your README

It updates automatically each time the repo is re-graded.

[![RepoGrade](https://www.repo-grade.com/api/badge/wpscanteam/wpscan)](https://www.repo-grade.com/report/wpscanteam/wpscan)

More graded Ruby repos