Public-interest software inspection versioned methodology

A public record of software health.

Bridges, elevators, and food have condition records kept in public. The software underneath all three does not. This is that record: maintainability, engineering quality, security posture, ecosystem adoption, and governance, measured the same way for every repository.

01Evidence attached02Results independent of payment03Method versioned

Request a scan

Free for high public-value repositories. Private and niche repositories follow the documented certification route.

Public queue operational
Reproducible evidenceEvery published result links to inspectable source evidence and methodology.
Independent resultsPayment, sponsorship, and vendor alignment cannot alter a published result.
Signals, not warrantiesResults inform review and procurement; they do not replace expert judgement.
Live catalogue

The record, as it stands.

Every repository admitted so far, searchable and rankable, each entry opening on a full report with its evidence.

Indexed repositories
82,107
Monthly downloads under inspection
622B
Median health index
59 Moderate

Kind

What the repository builds — library, application, host extension. Repositories whose evidence answers nothing are listed under Unclassified.

Red flags

Findings that adjust a rating downward rather than scoring into it. Selecting several shows repositories raising any of them.

Clear filters
2,942 recordsRanked by popularity · browse by tag · record statistics
18Criticalhealth index
zzugg/libbeat
Moved to: https://github.com/elastic/beats
Go★ 0Sep 18, 2026
Custom licenseSep 18, 2026 · metrics 2.10.0
Go
17Criticalhealth index
zzycn003/stormrpc
⚡ StormRPC is an RPC "framework" built on top of the Request-Reply message capabilities from NATS.
Go★ 0Sep 18, 2026
MITSep 18, 2026 · metrics 2.10.0