Back to directory
stef41 avatar
stef41 / vibescore

vibescore

๐ŸŽต Grade your vibe-coded project. One command, instant letter grade across security, quality, dependencies, and testing.

23

Stars

1

Forks

0

Watchers

NOASSERTION

License

๐ŸŽต vibescore

Grade your vibe-coded project. One command. Instant letter grade.

PyPI Downloads License Python CI Tests OpenSSF Scorecard

"Vibe coding" is the new reality โ€” you prompt, AI writes, you ship.
But is your vibe-coded project actually good?
Find out in 10 seconds.

demo

$ vibescore .

๐ŸŽต Vibe Check  v0.1.0
โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•

  Project:   tokonomics
  Files:     40 (32 Python, 8 other)
  Lines:     4,658
  Scanned in 0.12s

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Category         โ”‚ Score  โ”‚ Grade โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Code Quality     โ”‚   52.0 โ”‚ F     โ”‚
โ”‚ Security         โ”‚  100.0 โ”‚ A+    โ”‚
โ”‚ Dependencies     โ”‚   98.0 โ”‚ A+    โ”‚
โ”‚ Testing          โ”‚  100.0 โ”‚ A+    โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Overall          โ”‚   87.6 โ”‚ B+    โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐ŸŸก Warnings (11)
  VC201  Function 'export_svg_chart' too long (102 lines)
  VC202  Function '_build_cli' high complexity (30)
  VC203  Function 'export_svg_chart' has 6 parameters (>5)
  ...

๐Ÿ’ก Tips
  โ€ข Reduce function complexity and add type annotations

Install

pip install vibescore

That's it. Zero dependencies. Works with Python 3.9+.

Usage

# Grade the current directory
vibescore .

# Grade a specific project
vibescore /path/to/project

# JSON output (for CI pipelines)
vibescore . --format json

# Fail CI if score is below threshold
vibescore . --min-score 70

As a Python library

from vibescore import scan

report = scan(".")
print(f"Grade: {report.overall_grade} ({report.overall_score:.0f}/100)")

for category in report.categories:
    print(f"  {category.name}: {category.grade}")

What It Checks

Category Checks Codes
Code Quality Function length, cyclomatic complexity, parameter count, type annotations, nesting depth, star imports, docstrings, mutable defaults VC201โ€“VC209
Security Hardcoded secrets, AWS keys, SQL injection, shell injection, unsafe deserialization, eval/exec, debug mode, private keys VC301โ€“VC309
Dependencies Version pinning, lock files, deprecated setup.py, wildcard pins VC401โ€“VC405
Testing Test file presence, test count, CI configuration, conftest.py, test-to-code ratio VC501โ€“VC506

Grading Scale

Grade Score Grade Score
A+ 97โ€“100 C+ 77โ€“79
A 93โ€“96 C 73โ€“76
A- 90โ€“92 C- 70โ€“72
B+ 87โ€“89 D+ 67โ€“69
B 83โ€“86 D 63โ€“66
B- 80โ€“82 D- 60โ€“62
F 0โ€“59

CI Integration

GitHub Actions

- name: Vibe Check
  run: |
    pip install vibescore
    vibescore . --min-score 70

Pre-commit (manual)

# In your Makefile or CI script
vibescore . --min-score 70 --format json > vibe-report.json

Pre-commit

repos:
  - repo: https://github.com/stef41/vibescore
    rev: v0.1.0
    hooks:
      - id: vibescore
        args: ["--min-score", "70"]

How Scoring Works

Each category is scored 0โ€“100 independently. The overall score is a weighted average:

Category Weight
Security 30%
Code Quality 25%
Testing 25%
Dependencies 20%

Security is weighted highest because a security bug in vibe-coded projects can be catastrophic.

Why vibescore?

Vibe coding means AI writes most of your code. That's fast, but it introduces risks:

  • AI hallucinates long functions that are hard to debug
  • AI skips security basics like input validation and secret management
  • AI often omits tests or writes superficial ones
  • AI uses loose dependency pins that break on updates

vibescore catches these patterns in seconds, so you can ship fast and ship safe.

FAQ

Q: Does this only work with Python?
A: Currently Python-focused for code quality and testing analysis. Security and dependency checks work with any project type. More languages coming soon.

Q: Does it phone home or require an API key?
A: No. Zero network requests. Zero dependencies. Runs entirely offline.

Q: How is this different from pylint/ruff/flake8?
A: Those are line-level linters. vibescore gives you a project-level grade across security, quality, testing, and dependencies โ€” a holistic view of your vibe-coded project's health. Use both.

See Also

Tools in the same ecosystem:

License

Apache-2.0

Releases

Apr 11, 2026

Download .zip

What's New

Rust support (VC221-VC227): unwrap density, unsafe blocks, function length, doc comments, clone detection, todo macros Go support (VC231-VC237): unchecked errors, goroutine leaks, function...

Apr 10, 2026

Download .zip

What's New GitHub Actions CI Template

vibescore --init-ci generates .github/workflows/vibescore.yml Customizable threshold, Python version, and trigger events API: generate_workflow(threshold='C', py...

Apr 10, 2026

Download .zip

What's New

JavaScript/TypeScript support โ€” code quality analysis for JS/TS projects (VC211โ€“VC218) Rich terminal output โ€” color-coded grades when rich is installed Pre-commit hook โ€” add vibescore to y...

Apr 10, 2026

v0.1.0 โ€” Grade your vibe-coded project

Download .zip

๐ŸŽต vibescore v0.1.0 Grade your vibe-coded project. One command. Instant letter grade. pip install vibescore vibescore . Features

Code quality analysis (VC201โ€“VC209) Security scanning (VC301โ€“VC309) De...