What “No external APIs found” says, and what it does not
As of 2026-10-09 — counted from the results published that day
“No external APIs found” is the state this site is most careful with. It is not a promise that a tool never goes online. It records that a set scope was read to the end and no code calling an external API was found inside it. This note sets out that scope and how far the statement holds.
How many there are
46 of the 149 published results are “No external APIs found”: 27 after a complete check, 19 after a conditional partial check (below). Examples are BurntSushi/ripgrep and jj-vcs/jj in Rust, rakyll/hey in Go and apple/container in Swift. Many are developer tools — search, version control, load testing, containers — with no reason to call an outside service in the first place.
When the check is complete
A check is complete only when all of these hold:
- GitHub did not cut the file list.
- No read limit was reached (400 files and 8 MB for a basic check, 2,000 files and 64 MB for a deeper one).
- There is no submodule.
- Every import path in the code was followed (none left unresolved).
- Source in languages this site does not read (C, C++, Zig …) is not a real share of the code.
The last condition was added on 9 October 2026. Before that, a repository whose source was barely read — a debugger written in C, for one — could still be published as a complete check. Such repositories are now “Needs review”, and the scope line says how many files are in languages not read (see Why “Needs review” remains).
When it is a conditional partial check
When only part of a large repository was read, the result is still “No external APIs found”, tagged “Partial check”, if all of these hold:
- Every manifest, config, Docker, README and entry-point file was read.
- No manifest lists a provider SDK from the catalog.
- No code that was read mentions an external host or SDK at all (calls and mere mentions alike).
The result page gives the share read as “Partial check — files read/all files”. The smaller the first number, the more was left unread, so read the ratio too.
What is not counted
An “external API” is a call that hands work to someone else's service. These use the network but are listed separately, not counted as external APIs:
- Infrastructure: package registries, the GitHub API (releases, update checks), CDNs, documentation sites — under “Fetched over the network” on the result page.
- Telemetry and analytics: under “Data sent out”.
- The repository's own service: a domain matching the repository's name or homepage, tagged “The repository's own service”.
- Strings that are not calls: addresses in help text, logs, comments, tests and examples.
So a tool with “No external APIs found” may still download model files on first run or check for updates. To see that too, read “Fetched over the network” and “Data sent out” near the bottom of the result page.
What reading code cannot tell
This site does not run code. Addresses a user enters at run time, code that plugins add later and scripts downloaded while running are not in the commit that was read, so they cannot be known. Every result is pinned to a commit; when a repository changes, “Check the latest commit” reads it again.