# GitHub Repository Analyzer - Security & Maintenance Scorer (`ntriqpro/github-repo-intelligence`) Actor

Score any open-source GitHub repository before you depend on it: security posture, maintainership health, dependency risk and license compliance, combined into a single rating. Built for OSS due diligence in enterprise adoption reviews and VC technical diligence.

- **URL**: https://apify.com/ntriqpro/github-repo-intelligence.md
- **Developed by:** [daehwan kim](https://apify.com/ntriqpro) (community)
- **Categories:** Developer tools, AI, Automation
- **Stats:** 3 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

$50.00 / 1,000 github repository analyses

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

## GitHub Repository Intelligence

Analyze any GitHub repository for security vulnerabilities, outdated dependencies, and maintenance health in seconds. Get a comprehensive 0-100 intelligence score combining security metrics, vulnerability detection, and maintenance indicators.

### What It Does

This Apify Actor performs deep analysis on GitHub repositories using three complementary APIs:

1. **GitHub REST API** — Extracts repository metadata (stars, forks, last commit, open issues, license)
2. **OSV (Open Source Vulnerabilities) API** — Identifies known CVEs in project dependencies with severity levels
3. **npm Registry API** — Detects outdated packages in project dependencies

The actor then synthesizes these data points into **three actionable scores**:

- **Security Score (0-100)** — Vulnerability assessment + dependency freshness
- **Maintenance Score (0-100)** — Last commit age + open issue backlog + dependency updates
- **Overall Score (0-100)** — Combined health indicator for quick evaluation

### Scoring Algorithm

```
Overall Score = 100 baseline
- (days_since_commit / 30) × 5 (max -30 points)
- outdated_packages × 3 (max -30 points)
- critical_vulns × 15 (per CVE)
- high_vulns × 8 (per CVE)
- (open_issues > 50 ? -10 : 0)
Final: Math.max(0, Math.min(100, score))
```

Security and Maintenance scores use similar weighted deductions on domain-specific metrics.

### Input Schema

| Parameter | Type | Required | Notes |
|-----------|------|----------|-------|
| `repoUrl` | string | Yes | Full GitHub URL, e.g. `https://github.com/facebook/react` |
| `githubToken` | string | No | GitHub PAT for 5000 req/hr (vs 60 unauthenticated) |

**Example Input:**

```json
{
  "repoUrl": "https://github.com/nodejs/node",
  "githubToken": "ghp_xxxxxxxxxxxx"
}
```

### Output Fields

| Field | Type | Description |
|-------|------|-------------|
| `repo_url` | string | GitHub URL analyzed |
| `repo_name` | string | owner/repo format |
| `stars` | integer | GitHub star count |
| `last_commit_days` | integer | Days since last push |
| `open_issues_count` | integer | Active issue count |
| `license` | string | Repository license (MIT, Apache, etc.) |
| `outdated_packages_count` | integer | npm packages with newer versions |
| `total_vulns` | integer | Total CVEs found across dependencies |
| `critical_vulns` | integer | CVEs with CRITICAL severity |
| `high_vulns` | integer | CVEs with HIGH severity |
| `security_score` | number | 0-100 vulnerability assessment |
| `maintenance_score` | number | 0-100 activity & health indicator |
| `overall_score` | number | 0-100 combined intelligence score |
| `disclaimer` | string | Legal disclaimer (see below) |
| `timestamp` | string | ISO 8601 analysis timestamp |

**Example Output:**

```json
{
  "repo_url": "https://github.com/nodejs/node",
  "repo_name": "nodejs/node",
  "stars": 112850,
  "last_commit_days": 0,
  "open_issues_count": 2847,
  "license": "MIT",
  "outdated_packages_count": 3,
  "total_vulns": 5,
  "critical_vulns": 0,
  "high_vulns": 2,
  "security_score": 88,
  "maintenance_score": 92,
  "overall_score": 90,
  "disclaimer": "This Actor aggregates publicly available data...",
  "timestamp": "2026-04-13T22:45:00.000Z"
}
```

### Use Cases

- **Dependency Vetting** — Before adding a package, check its security and maintenance posture
- **Portfolio Auditing** — Scan your organization's repositories for vulnerability trends
- **Third-Party Risk** — Evaluate contractor/vendor code quality before integration
- **OSS Monitoring** — Watch libraries your code depends on for security regressions
- **Competitive Analysis** — Benchmark competitors' repo health metrics

### Rate Limits & Performance

- **Without GitHub Token**: 60 requests/hour (rate-limited after ~1 min of heavy scanning)
- **With GitHub Token**: 5,000 requests/hour (recommended for production)
- **Typical Run**: 15–30 seconds per repository
- **Package Analysis**: Limited to 20 dependencies to avoid timeout; larger projects may show partial results

### Disclaimer (Legal)

This Actor aggregates publicly available data from GitHub API (MIT/Apache licensed projects), OSV vulnerability database (CC0), and npm Registry (public data).

**NOT SECURITY ADVICE.** Results are informational only. Always perform professional security audits before production deployment. Data retrieved in real-time; accuracy depends on upstream sources.

The scores are heuristic estimates. A high score does not guarantee security; a low score does not indicate danger. Use as a decision-support tool, not as your sole risk assessment.

### Data Privacy

All input repositories are public GitHub URLs. This actor does not store user data; results are returned in the Apify dataset and comply with GitHub, OSV, and npm data licensing.

### Pricing

Free plan: each run returns up to 25 results. Paid Apify plans receive the full result set.

- **Cost**: $0.05 per repository analyzed
- **Billing**: Pay-per-event; charged only on successful analysis
- **Free Tier**: First 50 runs free as part of Apify platform credits

### See Also

- [OSV Database](https://osv.dev/) — Open Source Vulnerabilities
- [GitHub REST API](https://docs.github.com/en/rest) — Repository metadata
- [npm Registry](https://registry.npmjs.org/) — Package information
- [Apify Platform](https://apify.com/) — Serverless Actor ecosystem

***

**Built by NtriqPRO** | Version 1.0 | MIT License

***

### 🔗 Related Actors by ntriqpro

Build your data pipeline with the ntriqpro Actor suite:

- [**maigret-actor**](https://apify.com/ntriqpro/maigret-actor) — Maigret OSINT — Username search across 3000+ sites
- [**website-tech-detector**](https://apify.com/ntriqpro/website-tech-detector) — Website Tech Stack Scanner
- [**code-review-intelligence-mcp**](https://apify.com/ntriqpro/code-review-intelligence-mcp) — AI Code Reviewer for PR diffs

### ⭐ Love it? Leave a Review

Your rating helps professionals discover this actor. [Rate it here](https://apify.com/ntriqpro/github-repo-intelligence/reviews).

# Actor input Schema

## `repoUrl` (type: `string`):

Full GitHub repository URL (e.g. https://github.com/facebook/react). Free plan: each run returns up to 25 results. Paid Apify plans receive the full result set.

## `githubToken` (type: `string`):

Increases API rate limit from 60 to 5000 requests/hour. Leave empty for anonymous access.

## Actor input object example

```json
{
  "repoUrl": "https://github.com/apify/apify-sdk-js"
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "repoUrl": "https://github.com/apify/apify-sdk-js"
};

// Run the Actor and wait for it to finish
const run = await client.actor("ntriqpro/github-repo-intelligence").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "repoUrl": "https://github.com/apify/apify-sdk-js" }

# Run the Actor and wait for it to finish
run = client.actor("ntriqpro/github-repo-intelligence").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "repoUrl": "https://github.com/apify/apify-sdk-js"
}' |
apify call ntriqpro/github-repo-intelligence --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,ntriqpro/github-repo-intelligence"
        }
    }
}

```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/9esSBGd2mEOKDClud/builds/wMgKkyqklnAj4x4ek/openapi.json
