npx rankmycode
Run this in your terminal
Needs Node 18.17+. No Node? The Windows and macOS / Linux options below need nothing installed.
irm https://poachdev.com/w | iex
curl -fsSL https://poachdev.com/i | sh
brew install jatinjain25/tap/rankme
/plugin marketplace add jatinjain25/rankme
/plugin install rankme@paxel
Two commands — run them one at a time.
$ npx rankmycode
downloading rankme-darwin-arm64
discovering sources...
reading claude_code...
reading cursor...
claude_code 272 sessions 110,343 events
cursor 18 sessions 4,102 events
63 projects · 14 repositories
Analyze this evidence? [y/N] y
EVIDENCE
claude_code 272 sessions 110,343 events
cursor 18 sessions 4,102 events
episodes 198
repositories 14
commits 1893
active days 96
Whether this ranks is decided when the server scores it.
Publish this score to the public leaderboard? [y/N] y
published. You would rank 12th of 47.Nobody here was added to make the list longer. Every row is a measurement that cleared the bar.
13 signals, read from 4 tools.
The third column is a property of how the payload is built, not a promise about how we behave: everything textual lives on a part of each event that the projection to the wire format does not copy, and a second pass refuses the finished payload if it finds any of about thirty forbidden keys at any depth.
Privacy and removal · Macintosh 128K photograph by Grm wnr, from an All About Apple Museum original, CC BY-SA 3.0, modified. Departure Mono and Overused Grotesk, SIL OFL. Homebrew logo © Homebrew contributors, BSD 2-Clause. Windows is a trademark of Microsoft Corporation. Claude is a trademark of Anthropic, PBC. X and GitHub marks are used under their owners’ brand guidelines to link to a profile.
The awkward ones are in here too. If an answer would embarrass us it is still an answer; anything that cannot survive its own FAQ is not worth asking anyone to run.
No. Not a line of it leaves your machine. What we receive is session records, event stream and commit metadata. What we never receive is your code, your prompts, file names, commit messages and transcripts. What goes but never as itself is commands, file paths, project id, author email and branch names — hashed on your machine, so even the names are gone before the upload is built.
That is a property of how the payload is constructed, not a promise about how we behave. Everything textual lives on a part of each event that the projection to the wire format does not copy. A second check then scans the finished payload for about thirty forbidden keys at any depth and refuses to send if it finds one — on your machine before the upload, and again on our server when it arrives.
No. Nothing goes to Claude, to GPT, or to any model — ours or anybody else's. There is no model provider in the product at all.
Your score is arithmetic: counts compared against fixed curves. Nothing reads your work to form an opinion of it, because nothing we hold contains your work.
Yes, and there is a command that does nothing else. builder analyze runs the whole pipeline locally — no network, no server, no account — and prints the evidence it found. You can see everything it would say about you with nothing leaving the machine.
builder publish then shows the exact counts it is about to send along with three real sample events, and stops to ask. That last question is the one --yes cannot answer. Prompts are read from the terminal directly rather than from standard input, so piping the installer into a shell cannot answer them for you either.
Yes, two ways. builder unlink takes this machine off your profile and keeps its evidence. builder forget deletes this machine's evidence and score outright — and if it was the last machine on the profile, the handle and any email address go with it.
A score you never claim deletes itself. Unclaimed uploads are hard-deleted after 30 days, swept daily, with nothing required from you.
Four: Claude Code, Cursor, opencode and Codex CLI. It reads the session history each one already keeps on your disk, plus git metadata for the repositories those sessions point at. Cursor's database is opened read-only and immutable; git is run without hooks and never with a diff.
Codex CLI is the exception: that reader is written from the documented file format and has never been run against real data. builder discover marks it unverified rather than quietly counting what it find.
That is Node missing, not this. npx ships with npm, which ships with Node, and PowerShell is telling you there is no such command on the machine — so nothing of ours ran at all. node -v confirms it in one line.
sh or bash not recognized is the other half of the same sentence, from the curl line rather than the npx one. Windows ships curl.exe, so the download works perfectly and then hands the script to a shell Windows does not have. Nothing of ours ran there either, and the cure is the same.
You do not need Node. In PowerShell: irm https://poachdev.com/w | iex — it fetches the Windows build, checks its SHA-256 before running anything, and installs into your own user profile. If you would rather have Node anyway, winget install OpenJS.NodeJS.LTS, then open a NEW terminal so PATH is picked up, and npx rankmycode works.
Windows on ARM works now — Snapdragon and Surface machines get a native ARM64 build, not an emulated x64 one. It was refused until recently because the compiler had no such target; it does now, so they are built. The installer and npx agree about which machine you are on, which is the thing that matters.
Both of the common ones are conditions on the machine or the network it is on, not faults in the tool. Each happens while PowerShell is still fetching, before a line of ours has run — which is why neither error mentions rankme, and why running it again changes nothing by itself.
Could not establish trust relationship for the SSL/TLS secure channel is PowerShell refusing the certificate on the way to https://poachdev.com. It is the certificate chain, not the protocol version: usually a machine whose trusted-root store has not updated in a long time, or antivirus with HTTPS scanning turned on, or a corporate proxy — all three re-sign traffic with a root the machine does not recognise. No command talks its way past a proxy, and we would rather say so than hand you one that pretends to; whoever runs it has to allow the host through. On a genuinely old machine it is worth trying [Net.ServicePointManager]::SecurityProtocol=3072; in front of the command once — 3072 is TLS 1.2 as a number, because .NET Framework before 4.8 has no Tls12 to name. Windows 10 and 11 do that by default and will not need it.
The remote name could not be resolved: 'github.com' is DNS. The script comes from this site, but the binary it fetches is about 99 MB and lives on GitHub Releases, so a machine that cannot resolve github.com cannot finish the install whatever else it does. A VPN split tunnel, a DNS filter or a captive network is the usual reason; a phone hotspot settles which one in about a minute.
The install put it somewhere your shell does not look. That is deliberate — a one-line install that quietly edits your shell profile is a surprise — so it goes in your own user directory and tells you where rather than changing your environment behind you.
Run it by its full path and it works with nothing changed: ~/.local/bin/rankme on macOS and Linux, %LOCALAPPDATA%\Programs\rankme\rankme.cmd on Windows. The installer prints that line last, after your score.
To type just rankme instead, add the directory to your PATH — export PATH="$HOME/.local/bin:$PATH" in your shell profile on macOS or Linux, then a new terminal. On Windows the installer prints the SetEnvironmentVariable line to paste.
Two floors, and one libc. The binary needs macOS 13 or newer, and Windows 10 version 1809 or newer — below either it would download, pass its checksum, install, and then fail to start with an error naming a symbol or a DLL rather than anything you could act on. It refuses up front instead.
The musl message is about which C library your Linux uses. Alpine and a few others use musl where most desktops use glibc, and the two need different binaries — uname cannot tell them apart, so the installer looks for the musl loader directly. There are musl builds, so this is a message you should only ever see on something genuinely unusual.
None of these are refusals we enjoy. Each one replaced a case where the install said it had worked and then the command did not exist.
No. It is a single binary in ~/.local/bin, run from your shell. There is no container, no daemon and no background agent — when the command exits, nothing of ours is still running.
No. Publishing, claiming and ranking need no sign-in, no password, no email and no GitHub connection. Your machine registers a device token the first time it publishes, and a recovery key is what carries that identity to a machine which does not have it yet.
Signing in is optional, by a link we email you. It gives you a profile you can edit from the browser and an avatar in the menu bar -- once you have claimed a score from your terminal in that signed-in browser.
A score stays anonymous until you decide otherwise. Putting your name on one means typing an eight-character code your terminal prints, good for ten minutes and usable once.
No. There is no payment path in the product — no plan, no quota, and nothing to enter a card into.
Reading is seconds. On the machine this was built on, 272 sessions and 110,343 events were collected in about six seconds.
Publishing takes as long as the upload does: a year of heavy use is roughly 8 MB compressed. Scoring happens on our side, and the command waits for it rather than leaving you to refresh a page.
Yes. Every project your sessions point at is collected and merged by repository, so a repo seen by two different tools counts once rather than twice. --all-repos additionally scans your home directory for git repositories with no sessions attached.
Each machine is its own device. Uploads replace per device rather than summing, and several devices can be claimed onto one profile.
builder restore puts the new machine onto a profile you already have. It asks for a recovery key rather than for your handle, because a handle is public and anybody could type yours.
builder key prints a fresh key from a machine already on the profile. Keep one somewhere that will outlive the disk it was generated on — a machine nobody can prove owns a profile is the one case this cannot fix for you.
Ranking needs a claimed profile and enough evidence to stand behind: 12 effective episodes' worth of work across 8 active days, at 0.65 confidence or better. Sessions are weighed rather than counted, so a handful of substantial ones go further than a pile of short ones.
Percentiles stay hidden until at least 100 people are ranked. A percentile with no population behind it is a made-up number.
With enough effort, yes — and we would rather say so than claim a guarantee we cannot keep. Your machine never states a number: it sends evidence, and the score is computed here. Forging one means forging a session history that holds together when we check it, which costs more than it returns and leaves marks we look for.
That is cost plus detection. It is not proof, and nothing on this site will tell you it is.
Not any more. The collector was mirrored publicly under MIT between 14 and 17 September 2026 and has been proprietary since. Making the repository private stops new copies; it does not revoke the grant on copies already taken, which is why this says so rather than leaving it to be found out.
The part that matters is still checkable without trusting us, because it runs on your hardware: https://poachdev.com/run.sh is served verbatim and is the same bytes the install command pipes into your shell, and the binary it fetches is verified against a published checksum before it is made executable.
Thin, and honest about it. The five dimensions are stable and measure what they say they measure. The thresholds behind them are calibrated against one person's history, plus two anchors taken from a published analysis of 6,852 Claude Code sessions.
Scores recompute from stored evidence rather than from whatever was true at upload time, so replacing those guesses with real percentiles as the population grows is a rescore on our side — never something you have to run again.