Skip to content

Trending Algorithm Vulnerable to Download Inflation #8869

@khoadng

Description

@khoadng

Problem

The trending algorithm calculates scores purely from download counts without validating download legitimacy. This allows package authors to artificially inflate their package rankings.

Impact

  • Legitimate trending packages get displaced
  • Users may discover artificially promoted packages instead of genuinely popular ones
  • Trending recommendations become unreliable for package discovery

Evidence

Check https://pub.dev/packages?sort=trending - the first page is full of packages created by the same publisher in less than 5 days.

Click to expand Image

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions