applicable weight 65%
usersourcecraft/vulnerable-repo
Language: HTML
branch master
The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
Open on SourceCraftDownload report (Markdown)snapshot 8 October 2026signal coverage 65%analysed 17 September 2026 at 20:22 UTC — part unavailable
What the 100 is made of
category weightDocumentation 20Activity 20Security 20CI/CD 15Issues 15Code health 10
The light segments — Security: will appear with a member token; Issues: the tracker is empty or not set up. The rest share their weight for now.
Six categories
earned / weightDocumentation and best practicessignal coverage 90%23.4–26.4 / 30.8
partial
Project activity11.4 / 30.8
scored
Securitywill appear with a member token
no data
CI/CDsignal coverage 50%0–11.5 / 23.1
partial
Issuesthe tracker is empty or not set up
no data
Code health0–15.4 / 15.4
collection failed
States:weight goes to the restinterval, not zero
scored
partial
no data
collection failed
Not measured: CI runswill become a group once access opens
closed by the platform
Not measured: docs directory, TODO/FIXME densitythe platform's window was truncated: a deep file or a recent version may have fallen outside it
couldn't see it
Strengths
what's already done- The README introduces the project
- The license file is in place
- Tests live in the repository
- The build is described by a Dockerfile
- Dependency versions are pinned
What affected the score
Penalties
Documentation and best practices
- −3review policyno protection
- −1branch protection policyno protection
Project activity
- −5last releaseno releases or version tags
- −4last commit — 295 days
- −4weekly activity — 1 week
- −3commits in the last year — 3 commits
- −3unique authors — 2 authors
- −1top author's share of commits — 67%
CI/CD
- −12SourceCraft CI configurationmissing
Not measured — interval width
Not a penalty: the lower bound of the score counts the metric as zero, the upper bound as full
Documentation and best practices
- up to −3docs directorydata not collected
CI/CD
- up to −12CI runsdata not collected
Code health
- up to −15TODO/FIXME densitydata not collected
What will raise the score
by strength of impact- add a SourceCraft CI configuration (.sourcecraft/ci.yaml); the service does not see external CISourceCraft CI configurationwhy: the build and the checks are reproducible for whoever takes the code+12CI/CD
- publish a release or tag a versionlast releasewhy: the build and the checks are reproducible for whoever takes the code+5Activity
- make a commit soonlast commit — 295 dayswhy: the repository shows it is alive, not abandoned+4Activity
- spread work across more weeks instead of bursts+4
- set up a review policy+3
- commit more often+3
- bring in a second maintainer+3
- set up a branch protection policy+1
- share the work with other contributors+1