Skip to the main content
The Repo Vitals mark: a pulse that ends in a commitREPO VITALS

applicable weight 65%

vchekryzhov/vulnerable-repo2

Language: HTML
branch master

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.

Open on SourceCraftDownload report (Markdown)snapshot 8 October 2026signal coverage 65%analysed 17 September 2026 at 22:26 UTC — part unavailable

What the 100 is made of

category weight
Documentation 20Activity 20Security 20CI/CD 15Issues 15Code health 10

The light segments — Security: will appear with a member token; Issues: the tracker is empty or not set up. The rest share their weight for now.

Six categories

earned / weight
Documentation and best practicessignal coverage 90%
23.4–26.4 / 30.8
partial
Project activity
11.4 / 30.8
scored
Securitywill appear with a member token
no data
CI/CDsignal coverage 50%
0–11.5 / 23.1
partial
Issuesthe tracker is empty or not set up
no data
Code health
0–15.4 / 15.4
collection failed
States:
scored
partial
no data
weight goes to the rest
collection failed
interval, not zero
Not measured: CI runs
closed by the platform
will become a group once access opens
Not measured: docs directory, TODO/FIXME density
couldn't see it
the platform's window was truncated: a deep file or a recent version may have fallen outside it

Strengths

what's already done
  • The README introduces the project
  • The license file is in place
  • Tests live in the repository
  • The build is described by a Dockerfile
  • Dependency versions are pinned

What affected the score

Penalties

Documentation and best practices

  • −3
    review policyno protection
  • −1
    branch protection policyno protection

Project activity

  • −5
    last releaseno releases or version tags
  • −4
    last commit — 295 days
  • −4
    weekly activity — 1 week
  • −3
    commits in the last year — 3 commits
  • −3
    unique authors — 2 authors
  • −1
    top author's share of commits — 67%

CI/CD

  • −12
    SourceCraft CI configurationmissing

Not measured — interval width

Not a penalty: the lower bound of the score counts the metric as zero, the upper bound as full

Documentation and best practices

  • up to −3
    docs directorydata not collected

CI/CD

  • up to −12
    CI runsdata not collected

Code health

  • up to −15
    TODO/FIXME densitydata not collected

What will raise the score

by strength of impact
  • CI/CD
    +12
    add a SourceCraft CI configuration (.sourcecraft/ci.yaml); the service does not see external CISourceCraft CI configurationwhy: the build and the checks are reproducible for whoever takes the code
  • Activity
    +5
    publish a release or tag a versionlast releasewhy: the build and the checks are reproducible for whoever takes the code
  • Activity
    +4
    make a commit soonlast commit — 295 dayswhy: the repository shows it is alive, not abandoned
  • spread work across more weeks instead of bursts+4
  • set up a review policy+3
  • commit more often+3
  • bring in a second maintainer+3
  • set up a branch protection policy+1
  • share the work with other contributors+1