Polished and well engineered. Punching above its star count.

AutoAR is an automated security reconnaissance tool, ASM and Discord bot for bug bounty hunters and penetration testers. It automates gathering subdomains, scanning ports, detecting technologies, mapping GitHub repositories, fuzzing, testing vulnerabilities, and AI analysis.

Documentation

82

Contributing guide5pt25

Contributing guidance is in the README, not a dedicated CONTRIBUTING.md (−20 pts).

Moving it to a CONTRIBUTING.md makes it easier to find and keeps the README focused. A dedicated file earns +47 pts base.

README12pt90

README is present.

Install and run instructions9pt90

README documents how to install the project.

License6pt100

A license file is present.

Engineering

82

Issue and PR templates6pt0

No issue or PR templates found (−100 pts).

Add .github/ISSUE_TEMPLATE/ with bug_report.md and feature_request.md to guide contributors. It dramatically improves issue quality.

CI/CD14pt85

CI is configured (.github/workflows/ci.yml).

Reproducibility6pt85

Lockfile present (go.sum). Installs are reproducible.

Tests18pt100

Test files detected (internal/api/api_test.go).

Linting and formatting5pt100

Formatting enforced (gofmt (built into Go toolchain)).

Project health

100

Dependency manifest6pt100

Dependency manifest found (go.mod).

Repository metadata5pt100

Repository has a description.

Activity5pt100

Actively maintained (pushed within the last month).

Housekeeping3pt100

.gitignore present.

Repository health signals

Activity, community, and responsiveness at scan time

Activity

  • Commits (30d / 90d)
  • 50
    Forks
  • 12
    Releaseslatest 2mo ago

Community

  • Community health
  • authors own >50% of commits
  • 223
    Watchers

Responsiveness

  • 24d 21h
    Median issue response
  • <1h
    Median PR merge time
  • 0
    Open issues
Repository files24 root entries
  • .github
    Good: CI is configured (.github/workflows/ci.yml).
  • cmd
  • docs
  • internal
    Good: A license file is present.
    Good: Test files detected (internal/api/api_test.go).
    Good: Security policy present.
  • regexes
  • scripts
  • templates
  • tests
  • web
  • .dockerignore
  • .gitignore
    Good: .gitignore present.
  • .gitleaks.toml
  • .gitmodules
  • autoar.sample.yaml
  • docker-compose.yml
  • Dockerfile
    Good: Environment pinned via Dockerfile.
  • entrypoint
  • env.example
  • go.mod
    Good: Dependency manifest found (go.mod).
  • go.sum
    Good: Lockfile present (go.sum). Installs are reproducible.
  • image.png
  • Modelfile
  • package.json
  • README.md
    Good: README is present.
    Good: README is well structured with multiple sections.
    Good: README includes screenshots or visuals. Great for first impressions.
    Good: README has code examples.
    Good: README links to a live demo or deployed app.
    Issue: No status badges in the README (−10 pts).Fix: Add CI/build status badges from shields.io or your CI provider to signal project health.
    Good: README documents how to install the project.
    Good: README documents how to run the project.