Scorecard is free, open source, and for what it measures it is the closest thing to a standard. Here is what it measures, what it does not, and when the free one is enough.
The short answer. Scorecard measures how a project is run: branch protection, pinned dependencies, signed releases, dangerous CI workflows, committed binaries. RepoGates asks whether a repository's publisher is who it looks like and what runs when you open it. The first is hygiene, the second is provenance, and a purpose-built malicious repository can have excellent hygiene. If you are grading your own project, or choosing between established ones, Scorecard is free and you should use it. If you are deciding whether to download a stranger's repository, it was not built for that question — and RepoGates reads Scorecard anyway, as one of its 22 checks.
The OpenSSF Scorecard is about twenty automated checks, run by the OpenSSF on a schedule against the projects it covers and published through a free API, with a CLI and a GitHub Action for running it yourself. Each check scores 0 to 10: Branch-Protection, Code-Review, Pinned-Dependencies, Signed-Releases, Token-Permissions, Maintained, License, Dangerous-Workflow, Binary-Artifacts and the rest. It is good work, it is free, and it is the right tool for the job it describes: telling a maintainer, or a consumer choosing between maintained projects, how carefully a project is run.
The repository vetting standard RepoGates is built on reads Scorecard asymmetrically — a low score is disqualifying and a high score is meaningless — because Scorecard does not ask the question a campaign exploits. A repository published last week by an account created last week can pin every dependency, protect its main branch and sign its releases, and ship a trojan as the signed release. Nothing in a hygiene score is lowered by that.
And the campaigns live where Scorecard is mostly absent. Its public results cover the projects it scans; the great majority of GitHub — including nearly every fresh repository — has no entry. FakeGit published roughly 7,600 repositories from about 6,600 fabricated accounts; a young repository from a young account is exactly the shape that has no Scorecard result to read. A missing entry is not evidence of anything, in either direction.
| OpenSSF Scorecard | RepoGates | |
|---|---|---|
| The question | How carefully is this project run? | Should I trust this repository enough to download it? |
| Price | Free, open source | Free for 10 repositories within 14 days; Personal $69 a year |
| Coverage | The projects it scans; any public repository if you run the CLI yourself with a GitHub token | Any public GitHub repository you open, on demand |
| Owner account age | No | Yes (C1) — a 45-point finding under 90 days |
| Stars against history | No | Yes (C3) |
| Maintenance, licence, contributors | Yes — Maintained, License, Contributors | Yes (C5–C7) |
| Committed binaries | Yes — Binary-Artifacts | Yes (C15), and Scorecard's own result read as C8 |
| Dangerous CI workflows | Yes — Dangerous-Workflow | Read from Scorecard (C8) |
| Branch protection, code review, signed releases, pinning | Yes — this is its core | No |
| Binaries attached to releases | Whether releases are signed | What is attached (C9) — the FakeGit delivery path |
| What runs when a folder opens | No | devcontainer, editor tasks, build scripts, bare repositories, .envrc (C10–C17) |
| Agent configuration files | No | CLAUDE.md, .cursorrules, MCP launch configs, hidden Unicode (C18–C21) |
| That an AI assistant sent you | No | Yes, in the browser only (C22) |
| Acts at download time | No — it is a report | Holds a browser download while the verdict is fetched, and cancels one your policy blocks |
Scorecard's column is from its published checks as read for our coverage matrix, 13 August 2026. Read the project's own documentation for today's list.
As check C8, weighted as a second opinion on hygiene. If Dangerous-Workflow or Binary-Artifacts scores under 5 out of 10, the finding is HIGH and costs 8 points; an overall score under 3 is MEDIUM and costs 4. A good score adds nothing. A repository Scorecard has never scanned gets a note — no Scorecard entry — and no finding. C8 contributes nothing to the FakeGit catch rate, and its page says so, because fresh campaign repositories have no entry to read.
Scorecard's result for any project it covers is public:
curl -s https://api.scorecard.dev/projects/github.com/OWNER/REPO | jq '{score, checks: [.checks[] | {name, score}]}'
A 404 means unscanned, not bad. Then ask the question Scorecard does not — how old is the owner?
gh api users/OWNER --jq '{created_at, public_repos, followers}'
RepoGates gates browser-initiated downloads — Download ZIP, release-asset archives, Save Link As. It does not see git clone, package managers, curl, or fetches made by AI agents outside the browser. A browser extension cannot observe other processes, and a PASS is not a statement that the code is good.
OpenSSF Scorecard is free. Why pay for RepoGates? Because they answer different questions. Scorecard measures how a project is run — branch protection, pinned dependencies, signed releases, dangerous CI workflows, committed binaries. A purpose-built malicious repository can score well on all of it, and most fresh repositories, which is where the campaigns live, have no Scorecard entry at all. RepoGates asks who published the repository and since when, whether its popularity matches its history, what is attached to its releases, what runs when you open it, and whether an AI assistant sent you. If your question is hygiene, Scorecard is free and good. If it is whether to trust a stranger's repository, Scorecard was not built to answer it.
Does RepoGates use Scorecard? Yes, as one of its 22 checks (C8). If Scorecard's Dangerous-Workflow or Binary-Artifacts check scores under 5 out of 10, that costs 8 points; an overall score under 3 costs 4. A good Scorecard adds nothing, and a repository Scorecard has never scanned gets a note, not a finding — a low score is disqualifying, a high score is not evidence of anything.
Does a high Scorecard mean a repository is safe? No, and the same is true of a RepoGates PASS. Scorecard measures process hygiene; a repository can protect its branches, pin its dependencies and sign its releases while shipping a trojan as the signed release. A RepoGates PASS means none of its 22 checks fired at a level your policy acts on — not that the code is good.
Add RepoGates to Chrome or Edge How C8 reads Scorecard
Numbers on this page: Island and BleepingComputer, July 2026 (FakeGit); weights and thresholds from the product's policy and scoring tables; our coverage matrix of 22 checks against about 45 products, 13 August 2026. OpenSSF Scorecard is a project of the Open Source Security Foundation; this page is our reading of its public documentation. Also compare: RepoGates vs Socket.dev.