Record in aggregate · metrics 2.10.0

The state of the record.

Aggregate statistics across the public record — how software health distributes, where the download volume concentrates, and which engineering practices are common or rare. Figures describe the inspected record, not the entirety of open source.

Inspected repositories
64,832 of 67,604 indexed
Monthly downloads under inspection
586B registry-reported
Median health index
60 Moderate
Good or better
43% index 65 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

52% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 67% of the entire volume.

Repositories
18%20%25%
Download volume
17%18%17%
BandRepositoriesDownloads / moVolume share
Exceptional3,59892.3B16%
Excellent11,586101B17%
Good12,88789B15%
Moderate16,081104B18%
Weak10,18496.8B17%
At Risk7,80189.7B15%
Critical2,69512.5B2.1%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality70
1100
Community & Adoption46
1100
Sustainability & Governance59
1100
Engineering Quality65
1100
Security48
1100
AI Readiness54
1100

Category profile

Median category score across the scope. Categories are documented in the methodology wiki.

Vitality
70
Community & Adoption
46
Sustainability & Governance
59
Engineering Quality
65
Security
48
AI Readinessunweighted
54

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
94% of 64,832
License detected
91% of 64,832
Automated tests
85% of 64,832
CI workflows
81% of 64,832
Linter configuration
43% of 64,832
Documentation directory
39% of 64,832
Contributing guide
37% of 64,832
Code of conduct
23% of 64,832
Security policy
19% of 64,832

Agent-era signals

One-command bootstrap
28% of 64,832
AI agent instructions
24% of 64,832
llms.txt
8.5% of 64,832

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 43,913
56 · 41–69
100 – 999 12,347
71 · 54–84
1,000 – 9,999 6,858
83 · 63–91
10,000 and more 1,714
92 · 81–96

By monthly downloads

Under 10K / month 13,127
59 · 47–71
10K – 1M 11,251
67 · 53–83
1M – 100M 4,679
75 · 53–89
100M and more 1,315
55 · 36–83

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.1
Fuzzing
0.6
Signed-Releases
0.9
Branch-Protection
1.3
SAST
1.5
Pinned-Dependencies
1.8
Token-Permissions
1.8
Code-Review
2.1
Security-Policy
2.5
Dependency-Update-Tool
4.1
Maintained
5.5
Contributors
6.1
CI-Tests
6.4
Vulnerabilities
6.5
License
9.0
Dangerous-Workflow
9.7
Binary-Artifacts
9.8
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
5,0397.8% of the record · 7.8% of 64,829 assessed
High-risk jurisdiction exposure
1,2391.9% of the record · 2.1% of 57,851 assessed
Malicious dependencies
870.1% of the record · 0.3% of 35,211 assessed
Inorganic growth
25<0.1% of the record · 1.4% of 1,738 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 4 days of inspection.

Push recency
74%
Last pushRepositoriesShare
Pushed within 30 days48,20174%
31 – 90 days6,77010%
91 – 365 days4,2566.6%
Over a year5,6058.6%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

37,871Organization-stewarded median 67
26,961Personal accounts median 53

Maintainer bus factor

75% of inspected repositories depend on a single maintainer for the majority of their commits — including 4,036 with over a million monthly downloads.

1 maintainer
48,513
2 maintainers
9,624
3–5 maintainers
5,226
6+ maintainers
951

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 47,112 reports with a collected dependency graph.

The median repository declares 4 direct dependencies — and resolves to 26 packages in total.

Resolved packages per repository

0
4,931
1 – 5
6,423
6 – 20
10,687
21 – 50
5,413
51 – 200
7,089
201 – 500
4,556
501 – 1,000
3,769
Over 1,000
4,244

License landscape

The most common detected licenses across the scope (SPDX identifiers).

MIT
30,276
Apache-2.0
13,343
Custom license
7,068
No license detected
5,919
BSD-3-Clause
1,986
GPL-3.0
1,642
AGPL-3.0
1,108
MPL-2.0
689
GPL-2.0
593
BSD-2-Clause
533

Ecosystems compared

Each ecosystem's slice of the record. A repository publishing to several ecosystems counts in each. Every row opens that ecosystem's full statistics.

EcosystemInspectedMedian healthBand mixGood or betterDownloads / mo
npm19,796 67 Good54%476B
Go17,884 56 Moderate34%1.4B
PyPI9,826 69 Good58%87.7B
Packagist7,460 57 Moderate34%5.2B
crates.io5,913 67 Good55%30.5B
RubyGems3,168 62 Moderate47%1.4B
NuGet3,102 69 Good56%6.1M
Maven2,290 71 Good59%2.3B
Hex1,468 50 Moderate22%323M

Most relied upon

The most-downloaded repositories under inspection — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

npm
99Exceptionalhealth index
typescript-eslint/typescript-eslint
:sparkles: Monorepo for all the tooling which enables ESLint to support TypeScript
TypeScript★ 16.4K↓ 3.8B/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm
90Excellenthealth index
npm/node-semver
The semver parser for node (the one npm uses)
JavaScript★ 5,459↓ 3.5B/moAug 29, 2026
ISCAug 29, 2026 · metrics 2.10.0
npm
53Moderatehealth index
jridgewell/sourcemaps
Monorepo for various sourcemap libraries
TypeScript · JavaScript★ 52↓ 3.3B/moAug 29, 2026
No licenseAug 29, 2026 · metrics 2.10.0
npm
98Exceptionalhealth index
babel/babel
🐠 Babel is a compiler for writing next generation JavaScript.
TypeScript · JavaScript★ 44K↓ 3.3B/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm
94Exceptionalhealth index
eslint/js
Monorepo for the JS language tools.
JavaScript★ 2,387↓ 3.1B/moAug 29, 2026
BSD-2-ClauseAug 29, 2026 · metrics 2.10.0
npm
77Goodhealth index
isaacs/minimatch
a glob matcher in javascript
JavaScript · TypeScript★ 3,518↓ 2.9B/moAug 29, 2026
BlueOak-1.0.0Aug 29, 2026 · metrics 2.10.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 2.10.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-09-11 06:16 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.