mrkeyoor.com_
Mon 28 Sept 07:45 UTC
Self-Hostedevaluationupdated 28 Sept 2026

niubigeo review

NiubiGEO is a self-hosted workbench for checking how model APIs describe a product, which competitors they mention, and which sources appear in their answers. It stores the original responses and test conditions so a marketing or product team can inspect the evidence behind each visibility result instead of trusting one blended score.

Verdict

Our NiubiGEO run installed 58 packages in 10 seconds and built in 11 seconds, but 1 of 256 tests failed. It is a credible self-hosted choice for inspecting model-API answers when your team values raw evidence and can secure the service. Keep it local, review the open citation and search-status bugs, and treat repeated results as observations rather than proof that a GEO change worked.

We ran it

Lab card: what happened when we ran niubigeoScreenshot of niubigeo (niubigeo.ai)
Install✓ · 10s58 packages · 74 MB
Build✓ · 11s
Tests✗ · 30s255 passed · 1 failed of 256 (node:test)
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo569 files~47,487 lines of source · 47.1 MB · 4 CI workflows · Dockerfile · tests dir

Answers from our run

Does niubigeo build from source?

Dependencies installed in 10 seconds (58 packages), and the build succeeded in 11 seconds. We cloned commit 8bc65e9 into a clean Debian container with 3 CPUs and no project-specific setup.

Do niubigeo's tests pass?

Not all of them: 255 of 256 passed and 1 failed when we ran the project's own test command (node:test). Some failures need services or credentials a bare container does not have.

Does niubigeo have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use niubigeo?

Anyone planning to expose the workbench directly to the internet: the deployment guide says it has no built-in authentication, TLS, or multi-user access control.

What are the alternatives to niubigeo?

Promptfoo, Profound, Peec AI. Our NiubiGEO run installed 58 packages in 10 seconds and built in 11 seconds, but 1 of 256 tests failed.

Setup4/510-second install and Docker path; one test still failed
Docs5/5Deployment, evidence, metrics, limits, and upgrades are documented
Community4/54,855 stars with 6 open issues and 6 open pull requests
Maturity3/5v0.2.1 is active, but one test and measurement bugs remain

Who it’s for

Product and marketing teams that want to compare brand answers across model APIs using their own keys.
GEO consultants who need original responses, citations, failures, and repeated observations beside a report.
Technical operators comfortable running Node.js or Docker and protecting a local workbench.
Teams that accept API results as their measurement surface rather than treating them as consumer ChatGPT or Gemini results.

Who it’s NOT for

Anyone planning to expose the workbench directly to the internet: the deployment guide says it has no built-in authentication, TLS, or multi-user access control.
Teams that need consumer-chat tracking or traditional search rankings: the README says it observes provider API responses and does not include search-engine rank tracking.
Buyers who want every metric to be final: open issue 18 says requested web search can be reported as used without execution evidence, and issue 12 reports duplicate citation URLs.
Operators expecting browser-entered keys to power unattended monitoring: v0.2.1 keeps those keys only for the session, while the separate scheduler needs server-side credentials.

Setup reality

Our sandbox installed 58 npm packages in 10 seconds and used 74 MB. The build passed in 11 seconds. Tests exited 1 after 30 seconds: 255 passed and 1 failed of 256. The supplied log tail contains only passing lines, so it does not show the failed assertion. Npm audit reported 0 known vulnerabilities.

Local use needs Node.js 22.13 or newer plus API credentials. OpenRouter is the shortest path; v0.2.1 also accepts direct providers and custom OpenAI-compatible endpoints. Structured analysis requires JSON Schema support, and real calls incur model or search fees.

Docker and Compose files are included, with a separate worker for schedules. Browser keys vanish on refresh and cannot feed that worker. The workbench binds locally by default and has no built-in authentication, TLS, or multi-user isolation, so remote access needs a controlled network or authentication proxy.

The evidence view is more useful than a visibility score

NiubiGEO asks model APIs about a domain or a neutral keyword, then keeps the answer, returned sources, model route, search setting, failures, and derived observations together. The workbench can compare descriptions, associated keywords, competitor mentions, and recommendations across models. Each domain has its own project and history, which reduces the chance of mixing one client's evidence into another report.

The README includes 20 real product cases, and 11 of them include keyword tests. Those examples are valuable because they preserve awkward results and parsing failures rather than presenting a perfect demo. The project also states the central limit clearly: an API answer is not the same surface as a consumer chat application. NiubiGEO can tell you what its configured route returned under recorded conditions. It cannot tell you what every user saw.

What happened when we ran it

Our sandbox installed 58 npm packages in 10 seconds and used 74 MB on disk. The build completed in 11 seconds. Npm audit found 0 known vulnerabilities, including 0 critical, high, moderate, or low findings. The repository at commit 8bc65e9 had 569 files, about 47,487 source lines, and a 47.1 MB checkout.

The test command failed with exit code 1 after 30 seconds. Node's test runner reported 255 passed and 1 failed of 256. The supplied final log lines were all marked ok, including checks for JSON-LD collection, unavailable site preparation, retry behavior, and the multilingual app shell. Because the tail does not contain the failed assertion, it does not support a diagnosis. The proper finding is simply that this commit did not pass its full suite in our container.

Version 0.2.1 supports mixed model sources with limits

The September 28, 2026 release adds 16 platform shortcuts and lets one test mix OpenRouter, direct provider APIs, and custom OpenAI-compatible endpoints. Endpoint, model, search setting, answer, citation, and failure identities remain separate even when model names match. Custom endpoints can load model IDs from /models or accept manual IDs. Structured GEO analysis requires JSON Schema support.

Credentials have two operating modes. Keys entered in the browser remain in memory for that session and disappear on refresh. They are excluded from browser storage and saved evidence, but the separate scheduler cannot use them. Scheduled work therefore needs an environment or file-based server credential. That split protects casual keys from persistence, while making unattended monitoring an operator task with real API costs.

Public deployment needs an authentication layer

The Docker guide binds port 8787 to 127.0.0.1 and explicitly warns against exposing the workbench directly. NiubiGEO has no built-in login, TLS, or multi-user authorization. A remote deployment needs a controlled network or an authenticated reverse proxy. The server and schedule worker must share the same data volume, and the guide recommends backing up the whole product-v2 tree before an upgrade.

Storage is a set of JSON records rather than a transactional database. Single-file writes use temporary files and rename, but the architecture document says this does not provide cross-file transactions, encryption, or tamper resistance. That is acceptable for a local analyst's workbench. It is a poor fit for a public client portal or a regulated multi-tenant service unless you add those controls outside the application.

Two open bugs can change how evidence is counted

Issue 18 says a report may label provider-native web search as used when NiubiGEO requested the capability but received no execution event or native citation. Issue 12 says the same canonical URL can be counted twice when it arrives as both a provider citation and an ordinary answer link. Open pull requests address citation deduplication, but the issue and fixes were still open when fetched.

These are measurement bugs, not cosmetic defects. Search execution and unique source counts shape the story a GEO report tells. Until fixes land in a release, inspect the raw answer and source list before repeating either claim to a client. The project's own evidence-first interface makes that review possible, which is a meaningful advantage over a dashboard that exposes only aggregate percentages.

Active maintenance does not make short runs causal evidence

GitHub showed 4,855 stars, 6 open issues, 6 open pull requests, and a last push on September 28, 2026. Release v0.2.1 was published the same day. The checkout contains 4 CI workflow files, a Dockerfile, a Compose file, and tests. Those are healthy maintenance signals even though our own suite ended with one failure.

Repeated answers still need modest interpretation. Models, routes, search indexes, and returned sources can change. A mention after editing a page does not prove the edit caused it, and a few observations do not establish a trend. NiubiGEO is best used as an evidence ledger: freeze the test conditions, retain failures, read the raw responses, and investigate changes before turning them into marketing claims.

Alternatives

ProjectWhat it isPick it when
Promptfoo gh↗An open-source test harness for comparing prompts, models, agents, RAG systems, and safety behavior.pick this instead when you need programmable model evaluations and CI checks rather than a brand-visibility workbench.
ProfoundA hosted platform for AI brand monitoring, prompt-demand data, and content workflows.pick this instead when managed monitoring and marketing workflows matter more than self-hosting and source access.
Peec AIA hosted AI-search analytics product focused on brand performance and prompt tracking.pick this instead when your marketing team wants a hosted interface and does not want to operate API keys or a scheduler.

What people are saying

  1. [producthunt] NiubiGEO
  2. [velocity-scout] Albert-Weasker/niubigeo

Sources

  1. NiubiGEO repository
  2. NiubiGEO v0.2.1 release
  3. NiubiGEO Docker deployment guide
  4. Web search execution issue 18
  5. Duplicate citation issue 12

More self-hosted reviews

kuboard-press · taskview-community · dae · yuvomi · mlmvpn_windows · teable · the whole board →