SAUR
Secure Arch User Repository scanner using AVX2 vectors to detect malware in AUR packages
API Rated 7 Oct 2026
- Built by
Tetstack
Bloat
90/500Where it landed on the scale
0
300
400
Summary
SAUR is a single-day project that responds to a real problem (malicious AUR packages) with a local scanner. The repo is live, but it has no releases, license, docs, payments or support path, and the creator's post describes it as a personal tool for paranoid users. It's a reasonable weekend build, not yet a product or a business.
Bloat · Not much here works or looks likely to last, yet.
Breakdown
Five measures, 100 points each. Open the receipts under any of them to see the posts and pages behind the points.
Viability
Is there a real problem, someone who would pay, and a market this builder can actually reach?
The problem is real for Arch users worried about malicious AUR packages, but there's no user base, no way to charge, and a niche audience that expects free tools. It reads as a utility, not a business.
18/100
Rubric 0–20No clear problem or user. A toy, a practice clone, or a solution looking for a problem.
Receipts (2)
Motivated by ongoing attacks on AUR packages, which is a real problem, but pitched to 'paranoid fellas' with no mention of paying users.
“sorry for disappearing for about idk 2 weeks, but if you guys checked the attack on AUR pkg never stopped. so I made SAUR (Secure Arch User Repository), It's a heavy scanner with AVX2 vector to scan for any regex malwares and abuse.ch list of recent known servers that shares malware's. Pros: Full scan on your device, to make sure the AUR package didn't hide it some where unnoticeable. Cons: It ”
Post · @Tetstack · 3 Aug 2026 · open on Telegram (opens in a new tab)
The repo has no license, no releases and no homepage, so there's no sign of a path to adoption or revenue.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/SAUR (opens in a new tab)
Moat
What stops someone copying it?
Regex matching against a public abuse.ch feed is something another developer could rebuild in a weekend. The AVX2 angle is a performance edge, but nothing here compounds like proprietary data or a user network.
14/100
Rubric 0–20A thin wrapper or a clone that anyone here could rebuild in a weekend.
Receipts (2)
Detection relies on regex patterns and the public abuse.ch list of known malicious servers, which anyone can use.
“sorry for disappearing for about idk 2 weeks, but if you guys checked the attack on AUR pkg never stopped. so I made SAUR (Secure Arch User Repository), It's a heavy scanner with AVX2 vector to scan for any regex malwares and abuse.ch list of recent known servers that shares malware's. Pros: Full scan on your device, to make sure the AUR package didn't hide it some where unnoticeable. Cons: It ”
Post · @Tetstack · 3 Aug 2026 · open on Telegram (opens in a new tab)
A single day of commits and no releases suggest the only edge is the initial execution.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/SAUR (opens in a new tab)
Momentum
Did the updates keep coming?
Everything happened on one day, 2026-08-03, and there have been no updates in the 65 days since, so there's no track record of steady shipping yet.
0/100
- Sustained shipping0/60
Worked on across 1 days.
- Consistency0/40
Updates in 1 of 1 month.
- Quiet
No update for 65 days, so scaled to 96%.
Receipts (1)
Earliest post about it.
“sorry for disappearing for about idk 2 weeks, but if you guys checked the attack on AUR pkg never stopped. so I made SAUR (Secure Arch User Repository), It's a heavy scanner with AVX2 vector to scan for any regex malwares and abuse.ch list of recent known servers that shares malware's. Pros: Full scan on your device, to make sure the AUR package didn't hide it some where unnoticeable. Cons: It ”
Post · @Tetstack · 3 Aug 2026 · open on Telegram (opens in a new tab)
Infrastructure
Does a real, working product exist?
A live GitHub repo exists with a described scanner, but there are no releases, docs, license or evidence of it running, so it only counts at demo level.
56/100
- It's live20/20
https://github.com/PicasoTheDeal/SAUR responded when checked.
- HTTPS5/5
Hosted on a platform (store, GitHub or Telegram), so HTTPS is the platform's.
- Real product15/35
There's a repo with a described scanner, but the dossier shows no releases, install instructions or demo of it working. The snapshot text is a one-line description, so it can't be credited as a working product beyond a demo-level artifact.
- Own home0/10
No home found.
- Maintained15/15
Last sign of shipping 2026-08-03.
- Operations1/15
Only a GitHub repo exists. There's no backend, API, docs, status page or second platform, and no license.
Receipts (4)
https://github.com/PicasoTheDeal/SAUR responded when checked.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/SAUR (opens in a new tab)
Repo exists with zero releases and only a one-line description.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/SAUR (opens in a new tab)
The post describes what the scanner does and admits it's slow, but doesn't show output or usage.
“sorry for disappearing for about idk 2 weeks, but if you guys checked the attack on AUR pkg never stopped. so I made SAUR (Secure Arch User Repository), It's a heavy scanner with AVX2 vector to scan for any regex malwares and abuse.ch list of recent known servers that shares malware's. Pros: Full scan on your device, to make sure the AUR package didn't hide it some where unnoticeable. Cons: It ”
Post · @Tetstack · 3 Aug 2026 · open on Telegram (opens in a new tab)
No homepage, releases or license were found on the repo.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/SAUR (opens in a new tab)
Sustainability
Is it being set up to last?
There's no distribution beyond the repo, no payments or pricing, no privacy or terms, no support contact, and no sign of ongoing commitment. It stays a hobby tool until someone picks it up.
2/100
- Distribution0/30
No working way to get it was found.
- Payments0/15
No payment provider found.
- Pricing0/10
No pricing found on the site.
- Revenue0/5
Nothing in the post or repo mentions customers, payments or revenue.
- Privacy policy0/7
No privacy policy found.
- Terms0/5
No terms of service found.
- Support0/8
No support contact found.
- Commitment2/20
The creator runs a blog and a files channel, but nothing is dedicated to SAUR. There's no team, roadmap or funding, and there's been no activity since the first day.
Receipts (3)
The post offers the tool as a free scanner with no pricing or customers mentioned.
“sorry for disappearing for about idk 2 weeks, but if you guys checked the attack on AUR pkg never stopped. so I made SAUR (Secure Arch User Repository), It's a heavy scanner with AVX2 vector to scan for any regex malwares and abuse.ch list of recent known servers that shares malware's. Pros: Full scan on your device, to make sure the AUR package didn't hide it some where unnoticeable. Cons: It ”
Post · @Tetstack · 3 Aug 2026 · open on Telegram (opens in a new tab)
All commits landed on a single day, 2026-08-03, with nothing since.
Checked 7 Oct 2026 · github.com/PicasoTheDeal/SAUR (opens in a new tab)
The post is a one-off announcement with no roadmap or follow-up plans.
“sorry for disappearing for about idk 2 weeks, but if you guys checked the attack on AUR pkg never stopped. so I made SAUR (Secure Arch User Repository), It's a heavy scanner with AVX2 vector to scan for any regex malwares and abuse.ch list of recent known servers that shares malware's. Pros: Full scan on your device, to make sure the AUR package didn't hide it some where unnoticeable. Cons: It ”
Post · @Tetstack · 3 Aug 2026 · open on Telegram (opens in a new tab)