applicable weight 65%
korifey-ad/vulnerable-repo
Language: HTML
branch master
The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
Open on SourceCraftDownload report (Markdown)snapshot 8 October 2026signal coverage 65%analysed 17 September 2026 at 20:21 UTC — part unavailable
What the 100 is made of
category weightDocumentation 20Activity 20Security 20CI/CD 15Issues 15Code health 10
The light segments — Security: will appear with a member token; Issues: the tracker is empty or not set up. The rest share their weight for now.
Six categories
earned / weightDocumentation and best practicessignal coverage 90%23.4–26.4 / 30.8
partial
Project activity3.9 / 30.8
scored
Securitywill appear with a member token
no data
CI/CDsignal coverage 50%0–11.5 / 23.1
partial
Issuesthe tracker is empty or not set up
no data
Code health0–15.4 / 15.4
collection failed
States:weight goes to the restinterval, not zero
scored
partial
no data
collection failed
Not measured: CI runswill become a group once access opens
closed by the platform
Not measured: docs directory, TODO/FIXME densitythe platform's window was truncated: a deep file or a recent version may have fallen outside it
couldn't see it
Strengths
what's already done- The README introduces the project
- The license file is in place
- Tests live in the repository
- The build is described by a Dockerfile
- Dependency versions are pinned
What affected the score
Penalties
Documentation and best practices
- −3review policyno protection
- −1branch protection policyno protection
Project activity
- −5top author's share of commits — 100%
- −5unique authors — 1 author
- −5last releaseno releases or version tags
- −4last commit — 295 days
- −4commits in the last year — 1 commit
- −4weekly activity — 1 week
CI/CD
- −12SourceCraft CI configurationmissing
Not measured — interval width
Not a penalty: the lower bound of the score counts the metric as zero, the upper bound as full
Documentation and best practices
- up to −3docs directorydata not collected
CI/CD
- up to −12CI runsdata not collected
Code health
- up to −15TODO/FIXME densitydata not collected
What will raise the score
by strength of impact- add a SourceCraft CI configuration (.sourcecraft/ci.yaml); the service does not see external CISourceCraft CI configurationwhy: the build and the checks are reproducible for whoever takes the code+12CI/CD
- share the work with other contributorstop author's share of commits — 100%why: the work does not rest on a single person+5Activity
- bring in a second maintainerunique authors — 1 authorwhy: the work does not rest on a single person+5Activity
- publish a release or tag a version+5
- make a commit soon+4
- commit more often+4
- spread work across more weeks instead of bursts+4
- set up a review policy+3
- set up a branch protection policy+1