Developer reference

Frequently asked questions

Practical answers about repository audits, contribution signals, optional reviews, community features, and the boundaries of the service.

Effective and last updated: August 27, 2026
01

Audit basics

What does a WelcomeScore measure?

It measures six visible public contributor-readiness signals: a contribution guide, code of conduct, setup information, license, good-first-issue labels, and recent repository activity. Read the full methodology on How It Works.

Does a high score mean a repository is safe or guaranteed to be welcoming?

No. A score is a limited snapshot of documented public signals. It does not assess source-code quality, supply-chain risk, maintainers, response times, workplace conditions, commercial legitimacy, legal compliance, or whether a contribution will be accepted.

Why is my repository not found or incomplete?

The repository may be private, renamed, deleted, temporarily unavailable, malformed, rate-limited by GitHub, or missing public data needed for a check. Verify the `owner/repo` path and try again later.

02

Improving an audit honestly

How can I reach 100?

Use real contributor documentation, publish a meaningful code of conduct and license, describe a reproducible setup path, apply a good-first-issue label only to a genuinely approachable public issue, and maintain a truthful public activity signal. Do not create empty files or misleading issues solely to affect a score.

Why do good-first-issue labels matter?

They can give newcomers a scoped starting point. A trustworthy label has a clear outcome, enough context to begin safely, no hidden prerequisite, and a scope small enough for a first contribution. It is not a promise of mentoring, acceptance, or payment.

Will a change appear immediately?

Not always. WelcomeScore caches public scoring data briefly to reduce repeated GitHub requests. GitHub search and repository data can also take time to reflect a newly created file, label, or issue.

03

Algofox reviews and badges

What does Ask Algofox for a review do?

It creates a concise technical review using only the audit’s allowed contributor signals. The action is opt-in. It does not publish a message, add a Hall entry, access raw source code, or assess people.

Why can a review vary?

Equivalent evidence can be expressed in different concise ways. Deterministic guidance rotates bounded copy variants without repeating the immediately prior option for the same evidence context. Provider responses are validated against the audit before display.

Can I add a badge to my README?

Yes. The completed audit offers shareable badge formats that read the same scoring pipeline. A badge is not an endorsement, certification, warranty, or guarantee; it reflects the available audit data at the time it is generated.

04

Hall of Fame

Are repositories added automatically?

No. A qualifying result shows an explicit add action. Someone must deliberately choose that action before an eligible repository is written to the Hall of Fame.

Does appearing in the Hall of Fame mean ETHIOR endorses the repository?

No. The Hall of Fame reflects the product’s documented eligibility signals. It is not an endorsement, safety finding, commercial recommendation, employment recommendation, or guarantee.

05

Dev Lounge

Is the Dev Lounge private?

No. It is an anonymous but public-in-context 24-hour discussion feature. Do not share credentials, personal data, financial information, private repository content, or security details.

Can I use the Lounge for hiring, deals, payments, or private services?

No. The Lounge is not a marketplace, recruiting service, payment platform, legal-advice channel, or escrow arrangement. Users are responsible for their own interactions and any decision to follow an external link or communicate elsewhere.

How do I report harmful content?

Use the project’s private reporting route described in the Dev Lounge Policy and Code of Conduct. Do not repeat or amplify harmful content in a public issue.

06

Privacy, ownership, and forks

What information does WelcomeScore process?

The service processes the public GitHub repository information needed for an audit and limited product data required for its documented features. The Privacy Policy explains the actual data categories, retention, and third-party processing in more detail.

Can I fork or modify WelcomeScore?

WelcomeScore uses a source-available attribution license, not an OSI-approved open-source license. Permitted derivatives must retain the license, notices, and clear original-project attribution. See ATTRIBUTION.md.