Free Upwork Job Post Red Flag Scorecard — 7 Categories, Instant Pass/Fail

Upwork connections cost money. Wasting them on scams costs more. Rate every job post across these 7 categories before you apply — or let BidPropel's TOS Firewall do it automatically.

Red flag scorecard for evaluating Upwork job posts — 7 categories of TOS violations and scam signals

The 7 Red Flag Categories

🔴 RED FLAG 1: Off-Platform Contact Bait

Severity: HIGH. The client asks you to contact them outside Upwork before a contract is in place.

Watch for: Email addresses in the job description, “message me on Telegram/WhatsApp/Skype,” “contact us at [external URL],” any request to “discuss details off the platform.”

Verdict: Do not apply. Report the job post. This is a TOS violation and almost always a scam — they're trying to get you off-platform where Upwork can't protect you or track payment.

🔴 RED FLAG 2: Unpaid Test Tasks

Severity: HIGH. The client requires you to complete work before hiring — “as part of the application process.”

Watch for: “Submit a sample,” “Complete this small task to demonstrate your skills,” “We'll pay for the test if we like it.”

Verdict: Do not apply. Legitimate clients review your portfolio. Scammers use “test tasks” to get free work from multiple freelancers.

🟡 RED FLAG 3: Equity/Crypto-Only Payment

Severity: MEDIUM-HIGH. The client offers equity, rev-share, or crypto instead of cash payment.

Watch for: “Equity in a fast-growing startup,” “Revenue share model,” “Paid in [crypto token],” “This will be great for your portfolio.”

Verdict: Decline unless you're an accredited investor evaluating a legitimate startup (you're not — you're a freelancer looking to get paid). Upwork requires USD payment.

🔴 RED FLAG 4: Impossible Scope for Budget

Severity: HIGH. The scope is mathematically impossible for the stated budget.

Watch for: “Full-stack SaaS platform, $500 budget, 2 weeks.” “Complete e-commerce site with payment integration, $200.”

Verdict: Do not apply. This client will either (a) never hire anyone, (b) hire the cheapest bid and get terrible work, or (c) scope-creep you into oblivion. None of these outcomes are worth a connect.

🟡 RED FLAG 5: Identity Harvesting

Severity: MEDIUM. The client asks for personal documents, ID scans, or account credentials.

Watch for: “Send a photo of your ID for verification,” “We need your Upwork login to post jobs from your account,” “Submit your passport for the background check.”

Verdict: Do not apply. Legitimate verification happens through Upwork's Identity Verification system, not through client requests.

🟡 RED FLAG 6: Security Bypass Requests

Severity: MEDIUM. The client asks you to disable security features, share credentials, or bypass authentication.

Watch for: “We'll share the admin password,” “Just log in as me,” “Disable 2FA so I can access it.”

Verdict: Decline and explain why. If they push back, walk away. You're being set up as the fall guy for a security incident.

🟡 RED FLAG 7: Unauthorized Access

Severity: MEDIUM. The job requires accessing systems, accounts, or networks you shouldn't have access to.

Watch for: “Scrape competitor data,” “Access our former employee's accounts,” “Bypass the paywall on [site],” “Get into [system] without credentials.”

Verdict: Do not apply. This is illegal in most jurisdictions and violates Upwork TOS.


The Quick-Decision Framework

FindingAction
Any HIGH flagDo not apply. Report if TOS violation.
2+ MEDIUM flagsProceed with extreme caution. Document everything.
1 MEDIUM flagApply if the project is otherwise a strong fit. Watch for escalation.
0 flagsSafe to apply. This is a legitimate project.

Get the printable red flag scorecard

All 7 categories with text patterns, severity levels, and the decision framework in a one-page PDF. Keep it open while you browse Upwork jobs.

No spam. Unsubscribe anytime. We'll send the scorecard and occasional tips for winning more on Upwork.

Frequently asked questions

What are the 7 categories of red flags?
Off-platform contact bait, unpaid test tasks, equity/crypto-only payment, impossible scope for budget, identity harvesting, security bypass requests, and unauthorized access requests. Each category has severity levels and specific text patterns to watch for.
How do I use the scorecard?
Rate each job post across all 7 categories. Any single HIGH severity flag = do not apply. Two or more MEDIUM flags = proceed with caution. The scorecard includes the exact text patterns, severity criteria, and decision framework.
Does BidPropel do this automatically?
Yes. BidPropel's TOS Firewall scans every job post you paste in for all 7 categories before you spend a single connect. The scorecard is the manual version — the same framework the AI uses, formatted for human review.