# About inspect.software

> A public record of open-source software health — every repository inspected by one published method, versioned methodology, results independent of payment.


**inspect.software** keeps a public record of open-source software health.
Every repository in it is measured against the same transparent, versioned
methodology, spanning maintainability, engineering quality, security posture,
ecosystem adoption, and governance. The method is published, the weights are
published, and no repository can pay for a better result.

## Mission

Make the health, quality, and security of open-source software **legible and
trustworthy** for everyone who depends on it — developers choosing a library,
security teams reviewing a supply chain, procurement functions approving a
vendor's stack.

## The problem the record exists to solve

Modern software is assembled from thousands of open-source dependencies, yet
the signals used to judge them are weak. Stars measure popularity, not
health. Bus factor is invisible: a package with fifty million weekly
downloads maintained by one exhausted volunteer is a systemic risk — the
pattern behind left-pad, Log4Shell, and the xz-utils backdoor. Security
practice is opaque, and maintenance velocity takes manual digging to read.

No consistent, transparent, third-party signal aggregated these into
something a developer, a security team, or a CTO could act on. The public
record exists to be that signal.

Technical health is only part of an enterprise dependency decision. The
record also makes policy-defined context visible through signals such as
[high-risk jurisdiction exposure](/wiki/jurisdiction-exposure), helping
security and procurement teams identify dependencies that merit enhanced
review without turning public profile evidence into a judgement about people.

## Principles

1. **Transparency is the product.** Every metric, weight, formula, and
   threshold is published in the [methodology](/methodology) and the
   [wiki](/wiki). Every report echoes its inputs so any value can be
   recomputed by hand.
2. **Results are independent of payment.** No commercial relationship —
   certification fees, sponsorship, vendor alignment — can alter a published
   result. Payment buys analysis, privacy, and frequency; never a better
   number.
3. **Signals, not warranties.** The record states exactly what it measures
   and no more — see
   [how to read the results](/wiki/signals-not-warranties).
4. **Versioned and accountable.** Methodology changes are dated, explained,
   and recorded in every report — see
   [methodology versions](/wiki/methodology-versions).
5. **Public good first.** Inspection of high public-value open-source
   software is free and its results are public, permanently.

## How the institution sustains itself

Free public-interest coverage is funded by paid services around it: audits
of private repositories, on-demand certification of niche public
repositories, continuous monitoring, and enterprise reporting — described on
the [certification & pricing](/pricing) page. The guardrail is absolute:
**a higher result is never for sale.**

## The record

The [public record](/#record) lists every inspected repository with its full
report: category profile, per-metric breakdowns, component evidence, and the
raw machine-readable data. Repositories carry
[embeddable badges](/badges) reflecting their current standing.

Questions and corrections are welcome — data errors can be flagged through
the [contact](/contact) channels, and the correction path is part of the
methodology's accountability.
