mrkeyoor.com_
Mon 05 Oct 06:26 UTC
Dev Toolsevaluationupdated 05 Oct 2026

github-ranking-audit review

GitHub Ranking Audit is a small Python command that grades a repository's name, description, topics, README length, stars, and recent activity. It turns public GitHub metadata into a checklist for repository presentation, but its score is a custom heuristic rather than a measurement of GitHub's search algorithm.

Verdict

Our run installed 36 packages and passed all 26 tests in 53 seconds across install, build, and test, so GitHub Ranking Audit is easy to inspect and run. Use its six scores as prompts for repository housekeeping, not as evidence that GitHub will rank a project higher. If search position affects a launch, compare real query results and traffic data before changing a name or pushing a meaningless commit.

We ran it

Lab card: what happened when we ran github-ranking-auditScreenshot of github-ranking-audit (buygithub.com/blog/github-seo-rank-repository/?utm_source=github&utm_medium=readme&utm_campaign=github-ranking-audit)
Install✓ · 39s36 packages · 37 MB
Build✓ · 6s
Tests✓ · 8s26 passed · 0 failed of 26 (pytest)
Known vulns0(pip-audit)
Repo18 files~426 lines of source · 0 MB · 1 CI workflows · tests dir

Answers from our run

Does github-ranking-audit build from source?

Dependencies installed in 39 seconds (36 packages), and the build succeeded in 6 seconds. We cloned commit 59281fd into a clean Debian container with 3 CPUs and no project-specific setup.

Do github-ranking-audit's tests pass?

Yes: 26 of 26 passed when we ran the project's own test command (pytest). Some failures need services or credentials a bare container does not have.

Does github-ranking-audit have known vulnerabilities in its dependencies?

pip-audit found none in the dependency tree at the time of our run.

Who should not use github-ranking-audit?

Teams that need a proven search-ranking predictor: the README says GitHub's exact weights are unpublished, while this tool assigns its own fixed percentages.

What are the alternatives to github-ranking-audit?

GitHub Search, GitHub CLI, OpenSSF Scorecard. Our run installed 36 packages and passed all 26 tests in 53 seconds across install, build, and test, so GitHub Ranking Audit is easy to inspect and run.

Setup5/539-second install, one required library, and a passing build
Docs4/5Usage and weights are clear, but ranking evidence is not supplied
Community2/5211 stars, no open threads, and activity limited to launch day
Maturity2/5One v1.0.0 release and a narrow, tested scoring script

Who it’s for

Maintainers who want a quick check for missing descriptions, sparse topics, short READMEs, or stale activity.
Consultants comparing the same six public signals across several repositories.
Developers who want JSON output they can feed into a report or a simple CI check.
Python users comfortable reading the scoring code before acting on its grade.

Who it’s NOT for

Teams that need a proven search-ranking predictor: the README says GitHub's exact weights are unpublished, while this tool assigns its own fixed percentages.
Maintainers evaluating README relevance: the source computes a first_200 string but scores only total word count, so a long irrelevant README can receive 100.
GitHub Enterprise Server users: the API base is hardcoded to https://api.github.com and the CLI has no endpoint option.
Anyone treating a low activity score as permission for an empty commit: the code checks only days since the last push, not what changed or whether users benefit.

Setup reality

Our sandbox installed commit 59281fd in 39 seconds, adding 36 packages and 37 MB. The build passed in 6 seconds. Pytest finished in 8 seconds with 26 passed and 0 failed, and pip-audit found 0 known vulnerabilities.

The CLI needs network access to GitHub's API. A token is optional for one-off use and raises the API rate limit for batches. Inputs use owner/repo; a target query is optional, and JSON output is available.

The project is only 18 files and about 426 source lines, with 1 CI workflow and a tests directory. There is no Dockerfile. The API host is fixed to GitHub.com, and the score should be read as a checklist grade, not an observed search rank.

Six signals produce one opinionated grade

GitHub Ranking Audit fetches 6 pieces of public repository data and converts them into scores from 0 to 100. Name match gets 25% of the final grade, stars get 20%, description, topics, and README get 15% each, and recent activity gets 10%. You can audit one repository, pass several at once, add a target query, or ask for JSON output.

That makes the tool easy to understand. It also defines its limit. The README says GitHub does not publish the exact weights behind its Best match order. The percentages here are therefore the author's model, not a reconstruction validated against search results. An A means a repository satisfies these thresholds. It does not mean the repository will appear above a B for a given user, query, or date.

The checklist catches neglected repository metadata

A missing description scores 0, fewer than 5 topics score 40, and a README under 50 words scores 20. Those thresholds can surface obvious presentation gaps before a launch. The CLI also prints direct tips when name matching, topics, README length, activity, or stars fall below its cutoffs. For a maintainer who has never reviewed the repository page as a search result, that five-minute pass can be useful.

Some tips deserve restraint. Activity is calculated only from the last push date: 7 days or less earns 100, while more than 180 days earns 10. The code cannot tell a documentation fix from an empty commit, nor can it judge whether a stable project needs frequent changes. Treat that result as a prompt to explain maintenance status. Do not manufacture activity for a higher grade.

What happened when we ran it

Our measurement setup cloned commit 59281fd into a fresh unprivileged Debian container with 3 CPUs, 8 GB of RAM, Python 3.12, and no secrets. Installation finished in 39 seconds, bringing in 36 packages and using 37 MB on disk. The build completed in 6 seconds. Pip-audit reported 0 known vulnerabilities in the installed environment.

Pytest took 8 seconds and reported 26 passed with 0 failed. The repository contained 18 files, about 426 lines of source, 1 CI workflow, and a tests directory. There was no Dockerfile, which is reasonable for a one-file Python CLI. Our run covered installation, packaging, scoring functions, and CLI tests. It did not validate the grade against GitHub search outcomes.

The distinction matters because a green suite proves the code follows its formula. It cannot prove the formula predicts ranking. The tests check exact thresholds for description length, topic count, README length, stars, and push age. They also check query-name overlap and basic CLI errors. No test compares an audit score with a search result position or later traffic.

README relevance is reduced to word count

The README says the tool checks keyword presence in the first 200 words. In ranking_audit.py, the function creates a lowercase first_200 value but never uses it. The returned score depends only on total length: fewer than 50 words gets 20, 50 to 199 gets 50, 200 to 499 gets 75, and 500 or more gets 100. A long README about the wrong subject can therefore ace this signal.

Name scoring behaves differently. Without a target query, every repository name receives 100. With --query, it treats hyphens and low-line characters as separators, then scores the overlap with query words. This is predictable and transparent, but it ignores description and README query matches when calculating that name score. Use the query mode to spot missing words, then inspect real GitHub results before renaming a repository and breaking links.

GitHub.com and its rate limits define the operating boundary

The script makes 3 API requests per repository: repository metadata, README content, and topics. It reads GITHUB_TOKEN when present and otherwise sends unauthenticated requests. That is enough for a small manual audit, while batches can hit GitHub's lower unauthenticated limit. The CLI has no cache, retry policy, backoff, or option for a GitHub Enterprise Server URL.

JSON mode prints the regular human report before the JSON array, so consumers expecting stdout to contain only valid JSON should test their parser against the actual command. The result object contains the six scores, rounded overall score, grade, and repository name. It leaves out the fetched metadata and tips, limiting what a downstream report can explain without calling GitHub again.

One launch-day release is too little history to judge durability

The repository was created, released as v1.0.0, and last pushed on September 17, 2026. GitHub showed 211 stars and 0 open issues or pull requests on October 5. There is no issue activity to examine, and no later release yet. That is a young project with a clean queue, not evidence of long-term maintenance or abandonment.

Use GitHub Ranking Audit when you want six repository-page checks in a readable terminal report. Its 26 passing tests and 426-line codebase make the rules cheap to verify. The final grade should stay in that narrow role. For an actual discoverability decision, record the target query, inspect GitHub's live results, and compare referral traffic after a meaningful metadata change.

Alternatives

ProjectWhat it isPick it when
GitHub SearchGitHub's own search shows the result set and ordering users actually encounter.pick this instead when you need to verify a repository's current position for a real query.
GitHub CLI gh↗The official command-line client exposes repository metadata and search for custom scripts.pick this instead when you want primary GitHub data without accepting someone else's grading formula.
OpenSSF ScorecardA repository checker focused on open-source security practices rather than discoverability.pick this instead when the decision concerns security posture and supply-chain controls.

What people are saying

  1. [velocity-scout] nMaas8388/github-ranking-audit

Sources

  1. GitHub Ranking Audit repository
  2. GitHub Ranking Audit README
  3. GitHub Ranking Audit scoring source
  4. GitHub Ranking Audit v1.0.0 release

More dev tools reviews

learning-python · github-launch-checklist · blitzstrike · AirCard · gpt_sub_analysis · PythonRobotics · the whole board →