The useful output is a shortlist, not a safety verdict
Meme Radar watches AVE ranking pages across BSC, Solana, Base, Ethereum, and Robinhood, then turns the available fields into local candidate cards. Supported chains may receive DexScreener data, and deeper review can use GoPlus where available. The default fast scan does not inspect every token through those secondary sources. Missing contract, liquidity, tax, or holder data stays marked unknown instead of being counted as a pass.
That distinction carries the whole product. A candidate is an item to inspect, not a recommendation. The scanner excludes some observed conditions, including liquidity below $3,000, developer holdings above 1%, and buy or sell tax above 5%. Yet the README says the free fast path can miss honeypots and scams because it does not complete a contract audit for each coin. The dashboard can narrow attention; it cannot close the risk question.
One AVE key buys controlled polling, not full-chain coverage
All enabled chains share one AVE request queue. Production scanning makes at most one ranking request every 5 minutes across the whole app, so 1, 2, or 3 enabled chains are normally revisited about every 5, 10, or 15 minutes. Each round reads one ranking page of up to 100 entries. This is a rotating sample of AVE's ranking data, not a live feed of every new token on each chain.
The local budget starts with a 1,000,000 CU cumulative ceiling, 30,000 CU per day, and 1,250 CU per UTC hour. Those are client-side protections, not promises about the user's AVE allowance. HTTP 429 responses push the interval to 8 minutes and, if needed, 15 minutes. A failed 5-minute retry prevents another such probe for 24 hours. The bookkeeping survives restarts and key changes, which is better than treating every restart as a fresh allowance.
What happened when we ran it
Our unprivileged Debian sandbox installed commit 7ecd342 in 8 seconds. Npm added 0 packages, and the resulting environment used 3 MB on disk. There was no build script or target, so we skipped that step rather than inventing one. The repository contained 106 files, roughly 17,028 lines of source, and occupied 1.4 MB when checked out.
The test command failed after 31 seconds. Node's test runner reported 447 passed and 2 failed out of 449. The supplied tail shows tests 438 through 449 passing, including offline audio state, Windows proxy parsing, portable startup, and registry fallback. It does not name the 2 failures or show their assertions. We can report a nearly green suite, but assigning a cause would go beyond the log.
Npm audit found 0 known vulnerabilities across critical, high, moderate, and low severity. The repository had a test directory, 0 CI workflow files, and no Dockerfile. Those facts fit a small, dependency-free local service, but they also leave release automation and repeatable container packaging outside the visible repository controls. Buyers with a mandatory CI check should add their own before trusting a downloaded archive.
Local storage reduces exposure while keeping one sensitive credential
The service listens on the loopback interface and expects a browser on the same machine. It accepts an AVE market-data key, not a wallet seed, private key, or exchange credential. The README says the key stays in a restricted project state file and does not enter URLs, logs, HTTP responses, or browser storage. Browser responses also pass through a field allowlist instead of exposing raw upstream payloads.
Local does not mean disposable. Favorites, up to 500 notes, budget records, risk exclusions, and exported research can remain on disk. The upgrade guide tells users to stop both copies and run a migration script before first launch in the new directory. It refuses several unsafe states instead of overwriting them. An exported JSON file omits the AVE key, but it can still contain personal notes, so it should not be posted as a harmless debug attachment.
Chinese documentation and unfinished Windows verification narrow the audience
The README is detailed about polling, stale evidence, alert deduplication, budget resets, migration, and risk boundaries. It is written in Chinese. There is no English README in the root, although the interface language can change and voice alerts support Chinese or English with local system voices. An English-only team would need to translate operational details that matter, including what an unknown field means.
Release v0.1.12 shipped on September 30, 2026, and fixed API connection diagnostics, key-save behavior after cancellation, and error categories for rate limits, quota, invalid credentials, network failures, and upstream errors. The release notes say macOS received local verification, while the Windows portable package received structural and file checks without a current real-machine acceptance run. GitHub showed 486 stars, 2 open pull requests, and 0 open issues on October 3.
Meme Radar is worth running when the desired outcome is a calmer research inbox. Keep the words on its cards literal: unverified means unverified, old evidence is old, and a spoken alert means only that a recent item met the available fast filters. Our 447 passing tests support a closer look, while the 2 failures and young v0.1.12 release justify a guarded rollout on one machine before anyone relies on its alert rhythm.

