applicable weight 65%
axidex/nodegoat
Language: HTML
branch master
imported from GitHub
The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
Open on SourceCraftDownload report (Markdown)snapshot 8 October 2026signal coverage 65%analysed 17 September 2026 at 18:43 UTC — part unavailable
What the 100 is made of
category weightDocumentation 20Activity 20Security 20CI/CD 15Issues 15Code health 10
The light segments — Security: will appear with a member token; Issues: the tracker is empty or not set up. The rest share their weight for now.
Six categories
earned / weightDocumentation and best practicessignal coverage 90%23–25.9 / 30.8
partial
Project activity15.5 / 30.8
scored
Securitywill appear with a member token
no data
CI/CDsignal coverage 60%13.8–23.1 / 23.1
partial
Issuesthe tracker is empty or not set up
no data
Code health0–15.4 / 15.4
collection failed
States:weight goes to the restinterval, not zero
scored
partial
no data
collection failed
Not measured: CI runswill become a group once access opens
closed by the platform
Not measured: docs directory, TODO/FIXME densitythe platform's window was truncated: a deep file or a recent version may have fallen outside it
couldn't see it
Strengths
what's already done- SourceCraft CI is configured
- The README introduces the project
- CI checks pull requests
- Commits span the whole year (23 commits)
- Work goes on without long pauses (7 weeks)
What affected the score
Penalties
Documentation and best practices
- −3review policyno protection
- −1branch protection policyno protection
- −<1share of short commit messages — 30%
Project activity
- −4last release — 2,623 days
- −4share of unanswered pull requests — 100%sample: 8 of 10
- −4share of closed pull requests — 0%window: 50 PRs, sample threshold: 8 of 10
- −2unique authors — 2 authors
- −1top author's share of commits — 65%
- −1last commit — 77 days
- −<1weekly activity — 7 weeks
- −<1commits in the last year — 23 commits
Not measured — interval width
Not a penalty: the lower bound of the score counts the metric as zero, the upper bound as full
Documentation and best practices
- up to −3docs directorydata not collected
CI/CD
- up to −9CI runsdata not collected
Code health
- up to −15TODO/FIXME densitydata not collected
What will raise the score
by strength of impact- publish a release or tag a versionlast release — 2,623 dayswhy: the build and the checks are reproducible for whoever takes the code+4Activity
- respond to pull requestsshare of unanswered pull requests — 100%why: an outside contributor gets an answer, and their work is not lostevidence: the repository's pull request list, snapshot of 8 October 2026+4Activity
- close pull requestsshare of closed pull requests — 0%why: an outside contributor gets an answer, and their work is not lostevidence: the repository's pull request list, snapshot of 8 October 2026+4Activity
- set up a review policy+3
- bring in a second maintainer+2
- set up a branch protection policy+1
- share the work with other contributors+1
- make a commit soon+1
- write meaningful commit messages+<1
- spread work across more weeks instead of bursts+<1
- commit more often+<1