xlegit
Menu
How scoring works

How our Twitter bot checker works.

Is an X account a bot, a fake profile or a real person? xlegit looks for clues in public profile information and posts. This guide explains how those clues become a trust score, how we check the evidence and where the results can be wrong.

How to read the trust score

03070100
0–29

Likely bot or scam

A risk override was triggered, or several areas show strong warning signs.

30–69

Uncertain

Mixed signals. Worth a closer look before engaging.

70–100

Broadly trustworthy

The available profile, post and engagement signals appear consistent. This does not verify identity.

Six types of profile signals

We look at these signals together to estimate risk. A new account or an unusual posting pattern does not tell the whole story. Certain risk signals can override the combined score, as explained below.

01Account fingerprint

Basic profile details can help put an account in context. We check its age, handle, bio and links, including whether a bio link appears on a phishing denylist. These signals contribute to the account fingerprint score.

What we look at

Account age, handle patterns, bio and bio links.

What we skip

Profile picture aesthetics, hobbies, opinions.

Available with

Free and Pro scans.

02Content originality

We look for repeated wording, copied structures and templates across the available posts. Repetition can suggest automation, but it does not prove an account is a bot. The topic or opinion expressed is not a scoring criterion.

What we look at

Repeated wording, sentence structure and templates.

What we skip

What the post is about. Politics. Sentiment.

Available with

Free and Pro scans.

03Behavioral patterns

We look at when posts appear and how regular or concentrated the activity is. Some patterns can suggest automation. Posting often does not, by itself, mean an account is a bot.

What we look at

Time between posts, active hours and sudden bursts of activity.

What we skip

How much someone posts. Topic concentration.

Available with

Free and Pro scans.

04Network quality

Follower and following counts, audience ratios and engagement patterns can raise questions about an account’s network. We assess these patterns without judging the identities of individual followers.

What we look at

Audience counts, follower ratios and engagement patterns.

What we skip

Who specifically follows you. Specific accounts.

Available with

Free and Pro scans.

05Engagement authenticity

Grok, xAI’s language model, reads a sample of recent posts for signs of templated promotion, scam offers, impersonation or coordinated boosting. This analysis is one part of the score and can be wrong.

What we look at

Post content, repeated templates and signs of coordination.

What we skip

The opinions in the posts. Identity of anyone replying.

Available with

Server-side checks, when evidence is available.

06Visual identity

An image model estimates whether a profile picture contains a face and whether it was generated by AI. A result above the configured AI confidence threshold can set the score to zero. It does not prove who runs the account or whether they intend harm.

What we look at

AI-generation probability, presence of a face.

What we skip

Who the person is. Appearance. Anything about you.

Available with

Server-side checks, when evidence is available.

How Free and Pro scans work

FreeGuided collection

Scroll to collect

Start a scan in the extension and scroll while the guide collects up to 100 public posts. The server checks the profile header and a sample of posts through the X API before assessing the evidence, including Grok post analysis.

5 scans a day, up to 30 per calendar month. Unpublished assessments remain private previews.

ProAutomatic collection

Scan without scrolling

The server fetches up to 100 public posts through the X API and applies the same scoring engine and Grok analysis. Results include the available account, content, behavior, network, engagement and visual signals.

No scrolling needed. We label assessments when evidence is incomplete. Every score is an estimate.

§ 04 · Auto-zero

Two conditions can set the score to zero, even when other signals look normal.

This happens if a bio link points to a host on a public threat list (URLhaus or OpenPhish), or if the image model is more than 95% confident that an avatar is AI-generated. The badge identifies the condition that triggered it. Detection can be wrong, and an AI-generated avatar alone does not prove that an account is a bot or a scam. Account holders can request a review.

Privacy and scoring limits

Here is what we collect, how long we keep it and how we keep community reports separate from the trust score.

  1. i.

    Opinions are not scoring criteria.

    We assess signs of automation, deception and authenticity. A person’s political views or choice of topic should not determine their score.

  2. ii.

    Observations are kept for 30 days.

    We keep collected public signals, including posts, for 30 days so we can compare observations, then delete them. Analysis sends a sample of public posts to Grok. xAI processes those API inputs under its own data terms.

  3. iii.

    Community reports stay separate.

    Community reports do not change the algorithmic score. Both are shown so you can see when they disagree.

  4. iv.

    No sale of profile data.

    We do not sell profile signals. Selected public evidence is processed by the analysis providers described in our privacy policy, including xAI for post analysis and Sightengine for image checks.

Each report includes the scoring version, so you can see which version was used. Scores can change when new evidence arrives or the model is updated. Check the assessment date when you read a report.

xlegit · Scoring guide · September 2026