SerpApi yesterday released Review Audit, an open-source tool that reads the 200 newest reviews of a Google Maps listing, pulls the review history of selected reviewers and reports how much of the star rating the place's own reviewers can explain.

In Short

SerpApi, a company that sells search results as structured data, has published an open-source program that studies the recent Google Maps reviews of a business and flags the ones that look arranged rather than spontaneous. It matters to anyone who picks a restaurant, a clinic or an agency client by star rating, because a rating can be padded in ways that no single review gives away. The program takes the unexplained extra reviews out of the average, shows the rating without them, and lists every set-aside review with a link back to Google so that a reader can check the call and disagree.

What Review Audit reads and what it reports

The tool was published on SerpApi's blog yesterday in a post by Çağdaş Salur, a senior engineer at the company. According to SerpApi, each audit starts with the 200 newest reviews of a place, together with each reviewer's review count, Local Guide status, photos and sub-ratings. Cheap checks run first. They single out the reviewers worth a closer look, and only then does the tool spend credits pulling the full Google history of those accounts.

Each place gets one page. SerpApi lists three elements on it: the verdict, "the rating without the reviews it can't explain", and the evidence. Below the findings the audit also reads the reviews for what they say - praise and complaints, food, service and atmosphere sub-ratings with and without the set-aside reviews, the hours at which people post, where else the reviewers go, and how often the owner replies. Every audit is a single self-contained HTML file. The adjusted rating lives in that file; the figure Google displays is untouched.

One design choice governs the rest. What gets set aside, SerpApi says, is only "the excess over what the place's own reviewers explain". A venue whose customers are simply generous keeps its high score, and the tool subtracts only what that clientele cannot account for.

Six patterns, each measured against the place itself

The post is explicit about the yardstick: "Each pattern is measured against the place itself, not against a global rule." Its example is a busy lunch spot that gets 30 reviews on a Saturday, which is unremarkable, against a dentist that gets 30 in a week when its normal week is four.

First-time reviewers come first. The tool compares how often accounts with no record award five stars against how often accounts holding 4 to 50 reviews do so at the same place. "The gap is the finding, not the count," the post says, since a famous place collects plenty of first reviews innocently. A second check looks at the calendar: a week is flagged only when it carries at least 2.5 times the place's median week of five-star reviews and is also very unlikely by chance.

Timing is then tested at the scale of minutes. Pairs of five-star reviews posted within ten minutes of each other are counted and set against what the hours people actually post at would predict, so that, in the post's words, "a lunch rush is not mistaken for a batch upload".

Staff names supply a separate signal. Reviews that name the same member of staff, posted in pairs after dinner by people sharing a surname, are described as reviews asked for at the table. The post does not say how the check tells solicited reviews apart from relatives who dined together and wrote separately.

Repeated wording and shared reviewers form the fifth group: reviews that say the same thing in the same words, and clusters of accounts that keep reviewing the same places. Two accounts that share other places are usually a couple, the post notes, and "Review Audit needs three."

The four-star tail is the sixth. Real places, according to SerpApi, collect the occasional four-star review from "the customer who enjoyed it but waited too long". A place that receives none is read differently: "A wall of fives with nothing beside it means someone is choosing who gets asked."

None of this is presented as a finding of fraud. "None of these condemns a single review on its own," SerpApi writes, and the tool reports "patterns worth a closer look, not verdicts on individual reviews". Hence the wording: each verdict is phrased with the verb looks.

Credits, calls and figures that do not reconcile

Installation runs through uv, with uv tool install git+https://github.com/serpapi/reviewaudit followed by reviewaudit serve, which opens a local app. A user pastes a SerpApi key, searches for a place and starts the read. A command-line version takes the key from a SERPAPI_KEY environment variable and a place name and city. For busy venues, a --reviews 600 option reads further back.

The post lays out the call budget in three steps.

StepSerpApi engineCallsWhat it returns
1Google Maps API1The place, its photo, hours and Google's lifetime star counts
2Google Maps Reviews API10The 200 newest reviews, each with reviewer data
3Google Maps Contributor Reviews API30Everything the reviewers worth checking have ever reviewed

SerpApi puts the total at about 42 credits a place and says every response is cached, so re-reading a place or rebuilding its page costs nothing. The free plan, at 250 searches a month, is described as enough for about five places.

The software is open source, but the data behind it is metered, and SerpApi is the vendor selling the meter. That is the commercial frame for an otherwise free tool, and the figures are SerpApi's own.

Several of them do not quite agree with each other. The table sums to 41 calls, against "about 42" in the text, and the post does not say what the extra call is; it also uses "calls" and "credits" interchangeably without defining the exchange rate. The review count is another case. The post states that the first page of reviews holds 8 entries and later pages 20, which would make ten calls return 188 reviews rather than 200. And 250 searches divided by 42 gives just under six places, not five. Each gap is small, and each is hedged with "about", but together they leave the real cost of an audit slightly uncertain.

What the post tells developers building on the same engines

The post devotes a short section to quirks of the underlying APIs. The contributor engine returns relative dates only, such as "a week ago", whereas the reviews engine provides iso_date; timing patterns are therefore drawn from the place's reviews, and a reviewer's record is used for what they reviewed rather than when. The user.reviews field counts written reviews only, while the full record also carries rating-only entries, so an account showing one review can have 19 ratings behind it. Review Audit, SerpApi says, trusts the full record.

What the post says the tool cannot do

SerpApi prints four blind spots in each audit and repeats them in the post.

  • A place where everyone gives five stars looks the same whether they mean it or not. "A flat 95% is not evidence; the gradient across account depth is."
  • A first review at a famous place is normal, and a thin account alone never counts.
  • Hotels carry Tripadvisor and Trip.com reviews with no Google account behind them. Those are left out, and the page states how many.
  • 200 reviews at a very busy place can cover as little as two weeks. The audit says so when the window is short.

Language coverage is a further limit. The staff-name and stop-word lists exist only for English and Turkish, and the repository invites contributions of "new patterns with a rationale behind them" and lists for other languages.

What the post leaves out is also informative. It publishes no false-positive rate, and no comparison against reviews of known provenance. The only places audited in the post are invented. SerpApi built a demo, tools/demo.py, which acts as a fake Google Maps answering the same three engines in the same shapes, with made-up businesses on real streets in Portland, Maine, and names checked against Google Maps. The padding in those places "is written in on purpose", and the tool finds it. A test of that kind shows that the detectors fire on planted patterns. It says little about how often they would misfire at real venues, where honest reviewers also arrive in bursts after a viral post or a local newspaper write-up.

SerpApi gives its own reason for the invented examples: "Running a tool like this against real businesses and publishing the results is a different thing from building it." Whoever runs the tool against a real business and shares the page takes that step independently of the vendor.

A Maps tool from a vendor in litigation with Google

Review Audit draws on SerpApi's Google Maps engines, and SerpApi is the defendant in a federal case brought by Google. Google sued SerpApi on December 19, 2025 in the Northern District of California, alleging circumvention of SearchGuard, its anti-bot protection, under two provisions of Section 1201 of the Digital Millennium Copyright Act (DMCA). On July 20, 2026, Chief Judge Yvonne Gonzalez Rogers granted SerpApi's motion to dismiss. Claims covering search results without copyrighted content were dismissed without leave to amend; claims over copyrighted images in Knowledge Panels were dismissed with leave to amend.

Google filed an amended complaint on August 10, 2026. It adds paragraphs arguing that copyright holders authorized access controls such as SearchGuard, keeps the two DMCA claims for Knowledge Panel results that contain copyrighted material, and removes references to Google Maps and Google Shopping. SerpApi moved to dismiss again on August 24, 2026, with a hearing set for September 29, 2026, at 2:00 p.m. No ruling on that motion had been found in published coverage when this article was written.

The sequence matters here for a narrow reason. The pleading now stays within Google Search results, so the Maps engines that Review Audit calls are no longer part of what Google asserts. That is a statement about what Google has pleaded, not about the legality of any particular product, and SerpApi's post does not mention the case.

Dependence on Google-side behavior has a precedent in the SEO tooling market. When Google removed the num=100 SERP parameter on September 14, 2025, tools that had fetched 100 results in a single request needed ten, a tenfold rise in request volume that Keyword Insights described as 10 times the cost. Review Audit's own call count rests on a similar pagination fact, the 8-then-20 page sizes the post mentions.

Why a Maps rating carries commercial weight

Star ratings are not decoration. Google's Business Profile help page says that more reviews and positive ratings can help a business's local ranking; review volume feeds into prominence, one of three ranking factors alongside relevance and distance. A padded rating, on that logic, has a commercial purpose that extends beyond appearance, and SerpApi's post opens on the same point: "Every business with a rating has an incentive to improve it, and there is a market that will help."

Platforms and regulators have been working on the problem from the other direction. Google said in an April 7, 2025 blog post that during 2024 it blocked or removed more than 240 million policy-violating reviews and more than 12 million fake Business Profiles, and placed more than 900,000 accounts under posting restrictions. The figures are Google's own. In the UK, the Competition and Markets Authority secured undertakings from Google on January 24, 2025. Under them, businesses found boosting ratings with fake reviews receive a prominent warning on their profile and have their review function deactivated, repeat offenders have all their reviews deleted for six months or more, and Google reports to the regulator over three years. In the US, the Federal Trade Commission finalized a rule banning fake reviews on August 14, 2024, with civil penalties of up to $51,744 per violation, according to TechCrunch. The rule took effect in October 2024.

All of that enforcement runs through a platform or a regulator and proceeds review by review or account by account. Review Audit applies statistics to one place's own review population and subtracts an excess. Its output is not evidence of a breach of Google's policies or of consumer law, and the post does not claim otherwise.

Who might use it? The post names developers building on SerpApi's engines and no one else. The situations it describes - a market that sells reviews, a dentist whose week suddenly carries 30 of them - are familiar to local-search agencies and reputation managers, but how useful the checks prove in that setting depends on how they hold up outside a demo. SerpApi lists issues and pull requests on GitHub as the route for feedback, which leaves the set of six patterns open to extension by outside contributors.

Timeline

Summary

Who: SerpApi, an API vendor based in Austin, Texas, through a blog post by senior engineer Çağdaş Salur.

What: Review Audit, an open-source tool that reads the 200 newest reviews of a Google Maps place, retrieves the histories of selected reviewers, tests six patterns against the place's own baseline and reports the rating without the reviews it cannot explain. It runs locally on a user's SerpApi key and costs about 42 credits a place.

When: Yesterday, October 8, 2026.

Where: On GitHub under serpapi/reviewaudit, as a local app and a command-line tool, drawing on three SerpApi Google Maps engines.

Why: According to SerpApi, padded reviews are invisible one at a time but visible in aggregate, and a tool that measures patterns against each place's own baseline can show how much of a rating the place's genuine reviewers explain. SerpApi also lists blind spots, and the post publishes no false-positive rate.