01 · Roasts
PoC pantry stocked
audit-dojo has four exploit PoCs and Foundry tests; the missing CI and license are the audit report's unresolved findings.
Live, not loud
FundChain has a Vercel deployment and Sepolia contract, but its adoption counter is still 1 star and 1 fork.
Heatmap jump scare
34 commits this year and long empty stretches make the 2026-07-18 push feel like a rare boss encounter.
Security arc loading
The profile README promises Web3 security ambitions; audit-dojo is the proof, but the profile repo itself is only 7 KB of intent.
Built using
Zoral
Shadows one worker for a week, then takes over their job with zero extra setup. Behaves exactly like the original.
zoral.ai
02 · Category breakdown
- Impact25% weight30F
- Consistency20% weight25F
- Quality20% weight57D
- Depth15% weight50D
- Breadth10% weight55D
- Community10% weight25F
03 · Stats
365-day commit heatmap
11 active days
Language distribution
- Solidity78%
- JavaScript16%
- Python2%
- TypeScript2%
- Ruby1%
- Shell0%
- Other1%
04 · Numbers
Owned repos
non-fork
16
Commits
last 12 months
34
Followers
7
Joined GitHub
Apr 2021
05 · Top repos
mayurrajput04 /
FundChain
FundChain is a documented Ethereum crowdfunding application with a Sepolia deployment, React/Solidity setup guidance, campaign and admin flows, and tests, but adoption remains minimal at 1 star and 1 fork.
mayurrajput04 /
audit-dojo
A documented Solidity smart-contract auditing portfolio with four exploit PoCs, two guided audits, a CodeHawks review, Foundry tests, and executable vulnerability PoCs, but only 2 stars and no CI or license.
mayurrajput04 /
mayurrajput04
A 7 KB profile-style repository centered on a README manifesto for Web3 security, with no sampled implementation files, tests, CI, license, or demonstrated adoption.
06 · Timeline
- Apr 8, 2021Joined GitHub
- Jun 1, 2025Created mayurrajput04
- Jul 28, 2025Created audit-dojo — My Security review Reports
- Oct 14, 2025Created FundChain — check it out !!
- Jul 18, 2026Most recent push to audit-dojo
07 · Compare
08 · Rubric
How this score was produced
Overall = Σ (category × weight) + gentle top-end curve
Tier thresholds
▸ How the pipeline works
- 01Scrape.Pull every non-fork repo pushed in the last 90 days, plus your contribution calendar, followers, and language byte counts — straight from GitHub's REST & GraphQL APIs.
- 02Triage.A small model reads every repo's file tree + README and picks the 20 files per repo that actually reveal how you code.
- 03Grade each repo. All repos run in parallel through a fast scoring model that reads the picked files and rates each one independently on Impact, Quality, and Depth — with evidence citations.
- 04Aggregate. A larger reasoning model combines the per-repo scores with server-computed stats (heatmap, commit cadence, language entropy, follower count) to produce the 6-dimension profile score + roasts.
- 05Correct.Deterministic server-side checks enforce anchor-scale floors (e.g. a profile with 2,000+ public commits can't score 30 Consistency) and recompute the final verdict.
~90 seconds per profile, ~$0.25 in compute. Total of ~240 files read across your top-12 repos. One rating per GitHub account per day.
▸ Data sources & caveats
- Heatmap & commit totals: GitHub GraphQL
contributionsCollection— covers the last 365 days, includes private repos when the user has opted in (default). - Language %: byte totals across the top 30 owned non-fork repos.
- Curve: a small upward nudge centered on raw score ≈ 70, capping at 100. Prevents specialists from being unfairly penalised for narrow breadth.
- Anchor corrections: when server-measured signals (e.g. privateWorkLikely, multiRepoVolume, follower count) mandate a minimum category score, the aggregation step enforces it. These are signal-conditional, not identity-based floors.