Implemented source-audit standard

4 pillars. 20 weighted rubric points.

V2P combines deterministic static scanners with a proprietary audit workflow powered by AI specialist agents. Findings are mapped to a fixed 100-point rubric, then coverage, pillar, and critical-security gates determine the eligible public status.

20 category scores
100 total rubric weight
4 pillar rollups

How V2P analyzes the source

The audit does not ask one model for a single opinion. It combines programmatic checks, contextual AI review, and governed scoring.

Non-AI

Deterministic static scanners

Built-in pattern checks look for exposed secrets. Where relevant and available, specialist scanners also inspect Python security patterns and dependency vulnerabilities.

AI-assisted

Four specialist agents

Relevant files are routed to Security, Performance, UX & Reliability, and Code Quality specialists for contextual source review.

Governed

Fixed scoring and gates

V2P normalizes the findings, applies the 20 weighted categories, and evaluates the result against explicit status and eligibility rules.

The complete rubric

Each point has a weight and a defined scope. The 20 weighted scores roll into one overall score out of 100.

Security

Secrets, authentication, authorization, injection risk, and sensitive-data exposure.

35 / 100
  1. 01
    Secrets & API Key Management

    Hardcoded API keys, tokens, passwords, or secrets in source code. Whether .env files are gitignored. Secrets that leak into the client bundle.

    weight 8
  2. 02
    Authentication & Session Management

    Password hashing, session expiry, token rotation, CSRF protection, secure cookie flags, logout invalidation.

    weight 7
  3. 03
    Authorization & Access Control

    Users can only access their own data. RLS policies, middleware guards, role-based access, and protected admin routes.

    weight 7
  4. 04
    Input Validation & Injection Prevention

    SQL injection, XSS, command injection. Validation and sanitisation of user input. Parameterised queries.

    weight 7
  5. 05
    Data Exposure & Privacy

    Sensitive data (PII, passwords, tokens) leaking through logs, error messages, or API responses. HTTPS enforcement.

    weight 6

Performance

Queries, interface performance, caching, data fetching, APIs, and blocking operations.

20 / 100
  1. 06
    Database & Query Performance

    N+1 queries, missing indexes, unoptimised queries, missing pagination, large unbounded selects, connection pool configuration.

    weight 5
  2. 07
    Frontend Performance

    Large bundle sizes, missing code splitting, unnecessary re-renders, missing image optimisation, unoptimised fonts, lazy-loading.

    weight 5
  3. 08
    Caching & Data Fetching

    Appropriate caching, proper use of SSR/SSG/ISR, efficient data fetching, avoidance of request waterfalls.

    weight 5
  4. 09
    API & Backend Performance

    Slow endpoints, missing rate limiting, inefficient algorithms, blocking operations in async code, missing timeouts on external calls.

    weight 5

UX & Reliability

Errors, accessibility, forms, mobile behavior, loading states, and empty states.

22 / 100
  1. 10
    Error Handling & Resilience

    Unhandled promise rejections, missing try/catch, generic error messages, missing error boundaries, crash-prone edge cases.

    weight 6
  2. 11
    User Experience & Accessibility

    Missing alt text, no ARIA labels, poor keyboard navigation, missing focus management, insufficient colour contrast, lack of semantic HTML.

    weight 5
  3. 12
    Form & Input Handling

    Form validation (client + server), loading states during submission, error display, disabled states, double-submission protection.

    weight 4
  4. 13
    Responsive Design & Mobile

    Layouts work on mobile, touch targets sized correctly, no horizontal overflow, critical features accessible on small screens.

    weight 4
  5. 14
    Loading & Empty States

    Skeleton loaders or spinners during fetches, meaningful empty states with CTAs, handling of slow-network conditions.

    weight 3

Code Quality

Architecture, types, dependencies, tests, documentation, and AI-generated anti-patterns.

23 / 100
  1. 15
    Code Organization & Architecture

    Separation of concerns, proper component decomposition, consistent file structure, avoidance of god files/components.

    weight 5
  2. 16
    Type Safety & Consistency

    Loose `any` types, missing type annotations on function boundaries, inconsistent naming conventions, unused variables/imports.

    weight 4
  3. 17
    Dependency Management

    Up-to-date dependencies, no known vulnerabilities, no unused packages, appropriate use of peer dependencies.

    weight 3
  4. 18
    Testing Coverage

    Presence of tests (unit, integration, e2e), test quality, coverage of critical paths, proper mocking practices.

    weight 3
  5. 19
    Documentation & Readability

    Useful README, complex logic has comments, API endpoints are documented, code is self-documenting.

    weight 3
  6. 20
    Vibe-Code Patterns

    AI-generated anti-patterns: boilerplate bloat, leftover template code, TODO/placeholder code, inconsistent multi-session patterns, over-engineered abstractions, and missing error handling.

    weight 5

How scoring works

Findings reduce a category score according to severity and confidence. Category scores are weighted, summed, and converted to a 0-100 overall score. Pillar scores are the average of their category scores.

Below 75Does Not PassNo V2P verification status is issued.
75–89.9Certified SiteThe assessed site is Verified by V2P, subject to all gates.
90–100Verified with DistinctionThe assessed site is Verified with Distinction by V2P, subject to all gates.

Coverage and status gates

  • Below 75 overall does not pass.
  • Less than 50% eligible source coverage cannot receive a public verification status.
  • Less than 80% eligible source coverage caps the result at Certified Site.
  • A critical Security finding results in Does Not Pass.
  • Verified with Distinction requires minimum scores in every pillar, not only a 90+ overall score.

What the methodology covers

Included

Submitted source files, deterministic category scoring, file-level findings, remediation guidance, re-audits, certificates, public verification pages, and embeddable seals.

Not included

Runtime behavior, load testing, penetration testing, infrastructure configuration, deployment identity, repository ownership, compliance attestation, or business outcomes.

Apply the standard to your source.

Connect a repository, choose the snapshot, and begin with the same 4-pillar, 20-point rubric.

Start an audit
Vibe to Production Verified Site