inspect.software keeps a public record of open-source software health. Each repository is assessed with the same published, versioned methodology across maintainability, engineering quality, security posture, ecosystem adoption, and governance. The weights and production scanner are public, and payment cannot change a result.
Mission
Make the health, quality, and security of open-source software legible and trustworthy for everyone who depends on it — developers choosing a library, security teams reviewing a supply chain, procurement functions approving a vendor's stack.
Who operates it
inspect.software is run by Vitalii Stepanenko, from València, Spain. The full identification is in section 10 of the terms; enquiries go through contact.
The problem the record exists to solve
Modern software is assembled from thousands of open-source dependencies, yet the signals used to judge them are weak. Stars measure popularity, not health. Bus factor is invisible: a package with fifty million weekly downloads maintained by one exhausted volunteer is a systemic risk — the pattern behind left-pad, Log4Shell, and the xz-utils backdoor. Security practice is opaque, and maintenance velocity takes manual digging to read.
No consistent, transparent, third-party signal aggregated these into something a developer, a security team, or a CTO could act on. The public record exists to be that signal.
Technical health is only part of an enterprise dependency decision. The record also makes policy-defined context visible through signals such as high-risk jurisdiction exposure, helping security and procurement teams identify dependencies that merit enhanced review without turning public profile evidence into a judgement about people.
Principles
- Transparency is the product. The methodology and wiki document every metric, weight, formula, and threshold. The AGPL-licensed scanner is the production engine used to generate reports. Each report includes its observed evidence so the result can be checked manually or recomputed with the published code.
- Results are independent of payment. No commercial relationship — certification fees, sponsorship, vendor alignment — can alter a published result. Payment buys analysis, privacy, and frequency; never a better number.
- Signals, not warranties. The record states exactly what it measures and no more — see how to read the results.
- Versioned and accountable. Methodology changes are dated, explained, and recorded in every report — see methodology versions.
- Public good first. Inspection of high public-value open-source software is free and its results are public, permanently.
How the institution sustains itself
Free public-interest coverage is funded by paid services around it: audits of private repositories, on-demand certification of niche public repositories, continuous monitoring, and enterprise reporting — described on the certification & pricing page. The guardrail is absolute: a higher result is never for sale.
The record
The public record lists every inspected repository with its full report: category profile, per-metric breakdowns, component evidence, and the raw machine-readable data. Repositories carry embeddable badges reflecting their current standing.
Questions and corrections are welcome — data errors can be flagged through the contact channels, and the correction path is part of the methodology's accountability.