inspect.software

About inspect.software

A public record of open-source software health — every repository inspected by one published method, versioned methodology, results independent of payment.

Updated 2026-07-13

inspect.software keeps a public record of open-source software health. Every repository in it is measured against the same transparent, versioned methodology, spanning maintainability, engineering quality, security posture, ecosystem adoption, and governance. The method is published, the weights are published, and no repository can pay for a better result.

Mission

Make the health, quality, and security of open-source software legible and trustworthy for everyone who depends on it — developers choosing a library, security teams reviewing a supply chain, procurement functions approving a vendor's stack.

The problem the record exists to solve

Modern software is assembled from thousands of open-source dependencies, yet the signals used to judge them are weak. Stars measure popularity, not health. Bus factor is invisible: a package with fifty million weekly downloads maintained by one exhausted volunteer is a systemic risk — the pattern behind left-pad, Log4Shell, and the xz-utils backdoor. Security practice is opaque, and maintenance velocity takes manual digging to read.

No consistent, transparent, third-party signal aggregated these into something a developer, a security team, or a CTO could act on. The public record exists to be that signal.

Technical health is only part of an enterprise dependency decision. The record also makes policy-defined context visible through signals such as high-risk jurisdiction exposure, helping security and procurement teams identify dependencies that merit enhanced review without turning public profile evidence into a judgement about people.

Principles

  1. Transparency is the product. Every metric, weight, formula, and threshold is published in the methodology and the wiki. Every report echoes its inputs so any value can be recomputed by hand.
  2. Results are independent of payment. No commercial relationship — certification fees, sponsorship, vendor alignment — can alter a published result. Payment buys analysis, privacy, and frequency; never a better number.
  3. Signals, not warranties. The record states exactly what it measures and no more — see how to read the results.
  4. Versioned and accountable. Methodology changes are dated, explained, and recorded in every report — see methodology versions.
  5. Public good first. Inspection of high public-value open-source software is free and its results are public, permanently.

How the institution sustains itself

Free public-interest coverage is funded by paid services around it: audits of private repositories, on-demand certification of niche public repositories, continuous monitoring, and enterprise reporting — described on the certification & pricing page. The guardrail is absolute: a higher result is never for sale.

The record

The public record lists every inspected repository with its full report: category profile, per-metric breakdowns, component evidence, and the raw machine-readable data. Repositories carry embeddable badges reflecting their current standing.

Questions and corrections are welcome — data errors can be flagged through the contact channels, and the correction path is part of the methodology's accountability.