How flat is your stack?
Paste a public repository. The scorecard reads it file by file, straight from the git host, and grades it against the nine principles of the flat stack. Every verdict shows the files it came from.
How it reads a repository
It runs where you are reading this. Your browser asks GitHub or GitLab for the file list, then fetches the handful of files the checks need: manifests, lockfiles, pages, entry points, infrastructure templates. Nothing is cloned, nothing is uploaded, and there is no account to sign in with. The repository sits in memory for one scan, and the finished scorecard is kept in this browser only, so a rescan of an unchanged repo is instant.
GitHub allows 60 anonymous API requests an hour from each address, and a scan spends three. When they run out, the scorecard reads through the jsDelivr mirror instead and says so at the top of the result.
The checks are grouped by language. Every repository gets the common ones: always-on infrastructure, committed secrets, tests, documentation. HTML pages and Node.js projects get their own on top. Each language is one self-contained file of checks, so adding the next one touches nothing else.
What it does not measure
It reads what is committed, not what is deployed. A repo with no infrastructure templates might be running on a fleet of servers someone set up by hand, and the scorecard will not know. A server that looks always-on might sit behind a runtime that stops it, configured somewhere outside the repo.
It pattern-matches. It does not execute. The secret scan finds the shapes of well-known keys, not every credential, and a pass on it is no substitute for a real scanner in CI. Very large repositories are sampled: at most a few hundred files are read.
The grade is a conversation starter, not an audit. Each principle is weighted equally, and each verdict links to the lines behind it, so when a grade looks wrong you can see exactly which rule made it.
Whose rules these are
The nine principles are airbrx's flat-stack manifesto, the doctrine behind the airbrx gateway. The scorecard is a community project: a check that misjudged your repo, or a language it does not read yet, is an issue or a pull request away. If the grade points at a warehouse bill, scan your query history to see what the repetition costs.