Record in aggregate · metrics 1.13.0

The state of the record.

Aggregate statistics across the public record — how software health distributes, where the download volume concentrates, and which engineering practices are common or rare. Figures describe the inspected record, not the entirety of open source.

Inspected repositories
33,940 of 35,368 indexed
Monthly downloads under inspection
378B registry-reported
Median health index
57 Moderate
Good or better
19% index 70 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

77% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 64% of the entire volume.

Repositories
18%49%26%
Download volume
18%35%32%
BandRepositoriesDownloads / moVolume share
Excellent51519B5.0%
Good5,96166.6B18%
Moderate16,495132B35%
At risk8,992121B32%
Critical1,97739.6B10%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality73
1100
Community & Adoption46
1100
Sustainability & Governance59
1100
Engineering Quality66
1100
Security45
1100
AI Readiness46
1100

Category profile

Median category score across the scope. Categories are documented in the methodology wiki.

Vitality
73
Community & Adoption
46
Sustainability & Governance
59
Engineering Quality
66
Security
45
AI Readinessunweighted
46

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
95% of 33,940
License detected
91% of 33,940
Automated tests
87% of 33,940
CI workflows
82% of 33,940
Linter configuration
41% of 33,940
Documentation directory
40% of 33,940
Contributing guide
39% of 33,940
Code of conduct
25% of 33,940
Security policy
21% of 33,940

Agent-era signals

One-command bootstrap
30% of 33,940
AI agent instructions
26% of 33,940
llms.txt
1.9% of 33,940

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 22,316
53 · 43–62
100 – 999 6,761
63 · 51–71
1,000 – 9,999 3,663
70 · 61–77
10,000 and more 1,200
78 · 70–84

By monthly downloads

Under 10K / month 7,942
55 · 46–63
10K – 1M 4,621
62 · 52–70
1M – 100M 1,955
67 · 55–76
100M and more 806
51 · 39–66

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.1
Fuzzing
0.6
Signed-Releases
0.9
Branch-Protection
1.3
Pinned-Dependencies
1.7
SAST
1.7
Token-Permissions
1.7
Code-Review
2.3
Security-Policy
2.8
Dependency-Update-Tool
4.3
Maintained
5.8
Contributors
6.2
CI-Tests
6.6
Vulnerabilities
6.6
License
9.0
Dangerous-Workflow
9.7
Binary-Artifacts
9.8
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

High-risk jurisdiction exposure
1,1863.5% of the record · 3.9% of 30,082 assessed
Abandonment
9272.7% of the record · 2.7% of 33,944 assessed
Inorganic growth
25<0.1% of the record · 1.4% of 1,792 assessed
Malicious dependencies
10<0.1% of the record · 0.2% of 4,977 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 2 days of inspection.

Push recency
82%
Last pushRepositoriesShare
Pushed within 30 days27,86882%
31 – 90 days1,3143.9%
91 – 365 days2,0786.1%
Over a year2,6807.9%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

20,399Organization-stewarded median 61
13,541Personal accounts median 52

Maintainer bus factor

73% of inspected repositories depend on a single maintainer for the majority of their commits — including 1,771 with over a million monthly downloads.

1 maintainer
24,528
2 maintainers
5,647
3–5 maintainers
2,949
6+ maintainers
578

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 23,178 reports with a collected dependency graph.

The median repository declares 3 direct dependencies — and resolves to 27 packages in total.

Resolved packages per repository

0
2,706
1 – 5
3,112
6 – 20
5,000
21 – 50
2,554
51 – 200
3,531
201 – 500
2,225
501 – 1,000
1,815
Over 1,000
2,235

License landscape

The most common detected licenses across the scope (SPDX identifiers).

MIT
16,050
Apache-2.0
6,954
Custom license
3,484
No license detected
3,171
BSD-3-Clause
1,069
GPL-3.0
861
AGPL-3.0
644
MPL-2.0
333
GPL-2.0
329
BSD-2-Clause
288

Ecosystems compared

Each ecosystem's slice of the record. A repository publishing to several ecosystems counts in each. Every row opens that ecosystem's full statistics.

EcosystemInspectedMedian healthBand mixGood or betterDownloads / mo
npm10,674 60 Moderate26%320B
Go10,070 53 Moderate14%1.2B
PyPI5,259 62 Moderate32%51.6B
Packagist3,151 58 Moderate17%3.9B
crates.io2,462 62 Moderate27%12.5B
RubyGems2,105 56 Moderate19%459M
Hex1,096 51 Moderate7%253M
Maven870 65 Moderate36%518M
NuGet561 56 Moderate13%6M

Most relied upon

The most-downloaded repositories under inspection — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

npm
49At riskhealth index
chalk/ansi-regex
Regular expression for matching ANSI escape codes
JavaScript★ 202↓ 2.1B/moJul 22, 2026
MITJul 22, 2026 · metrics 1.13.0
npm
66Moderatehealth index
vercel/ms
Tiny millisecond conversion utility
TypeScript★ 5,541↓ 2.1B/moJul 22, 2026
MITJul 22, 2026 · metrics 1.13.0
PyPI
89Excellenthealth index
pypa/packaging
Core utilities for Python packages
Python★ 745↓ 2.1B/moJul 16, 2026
Custom licenseJul 16, 2026 · metrics 1.13.0
npm
68Moderatehealth index
isaacs/node-lru-cache
A fast cache that automatically deletes the least recently used items
JavaScript · TypeScript★ 5,902↓ 2.1B/moJul 22, 2026
BlueOak-1.0.0Jul 22, 2026 · metrics 1.13.0
npm
60Moderatehealth index
sindresorhus/string-width
Get the visual width of a string - the number of columns required to display it
JavaScript★ 529↓ 2B/moJul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
npm
49At riskhealth index
chalk/supports-color
Detect whether a terminal supports color
JavaScript★ 370↓ 1.9B/moJul 22, 2026
MITJul 22, 2026 · metrics 1.13.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 1.13.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-07-23 02:23 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.