94
/ 100
Excellent work. The main thing left to polish is a contributing guide.
WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com
Top fixes
Highest-impact changes first, ranked by point weight
- 1Tests18pt
Wire your tests to a documented command (e.g. a test script in your build config) so the suite is reproducible.
- 2Install and run instructions9pt
Add a .env.example listing all required environment variables so contributors know what to set up.
- 3Contributing guide5pt
Move the file to the repo root or docs/CONTRIBUTING.md so its setup, style, test, and PR sections can be graded.
- 4Contributing guide5pt
A CODE_OF_CONDUCT.md signals that your project is welcoming. GitHub has a template you can add in one click.
Working through the fixes? Let every push regrade itself.
The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.
Scorecard
Every check, grouped by category and sorted worst-first
Documentation
93
CONTRIBUTING guide found.
README documents how to install the project.
README is present.
Licensed under Other.
Engineering
93
Test files detected (spec).
CI is configured (.github/workflows/build.yml).
Ruby linting configured (.rubocop.yml).
Lockfile present (spec/fixtures/dynamic_finders/plugin_version/acf-content-analysis-for-yoast-seo/composer_file/package-lock.json). Installs are reproducible.
Issue or PR templates present.
Project health
100
Dependency manifest found (Gemfile).
Repository has a description.
Actively maintained (pushed within the last month).
.gitignore present.
Repository health signals
Activity, community, and responsiveness at scan time
Activity
- 5 / 59Commits (30d / 90d)
- 1,348Forks
- 68Releaseslatest 7y ago
Community
- 62% - FairCommunity health
- 2 bus factorauthors own >50% of commits
- 9,724Watchers
Responsiveness
- 4hMedian issue response
- 1hMedian PR merge time
- 0Open issues
Repository files21 root entries
- .githubGood: CONTRIBUTING guide found.Issue: CONTRIBUTING guide contents could not be read (−28 pts vs a readable file).Fix: Move the file to the repo root or docs/CONTRIBUTING.md so its setup, style, test, and PR sections can be graded.Good: CI is configured (.github/workflows/build.yml).Good: Dependabot covers 2 ecosystems (bundler, github-actions). Dependencies stay current.Good: Issue or PR templates present.
- .qlty
- app
- bin
- lib
- specGood: Test files detected (spec).Good: Lockfile present (spec/fixtures/dynamic_finders/plugin_version/acf-content-analysis-for-yoast-seo/composer_file/package-lock.json). Installs are reproducible.
- .dockerignore
- .gitignoreGood: .gitignore present.
- .rspec
- .rubocop.ymlGood: Ruby linting configured (.rubocop.yml).
- .ruby-gemset
- .ruby-version
- .simplecov
- AGENTS.md
- CLAUDE.md
- DockerfileGood: Environment pinned via Dockerfile.
- GemfileGood: Dependency manifest found (Gemfile).
- LICENSEGood: Licensed under Other.
- Rakefile
- README.mdGood: README is present.Good: README is well structured with multiple sections.Good: README includes screenshots or visuals. Great for first impressions.Good: README has code examples.Good: README links to a live demo or deployed app.Good: README includes status badges.Good: README documents how to install the project.Good: README documents how to run the project.
- wpscan.gemspec
Add this badge to your README
It updates automatically each time the repo is re-graded.
[](https://www.repo-grade.com/report/wpscanteam/wpscan)