SourceRank Reliability Analysis in PyPI
Published:Dec 30, 2025 18:34
•1 min read
•ArXiv
Analysis
This paper investigates the reliability of SourceRank, a scoring system used to assess the quality of open-source packages, in the PyPI ecosystem. It highlights the potential for evasion attacks, particularly URL confusion, and analyzes SourceRank's performance in distinguishing between benign and malicious packages. The findings suggest that SourceRank is not reliable for this purpose in real-world scenarios.
Key Takeaways
- •SourceRank's ability to distinguish between benign and malicious packages is limited in real-world scenarios.
- •URL confusion is an emerging attack vector that can inflate SourceRank scores.
- •SourceRank's failure to timely reflect package removals contributes to its unreliability.
Reference
“SourceRank cannot be reliably used to discriminate between benign and malicious packages in real-world scenarios.”