Record in aggregate · metrics 2.10.0

The state of the record.

Aggregate statistics across the public record — how software health distributes, where the download volume concentrates, and which engineering practices are common or rare. Figures describe the inspected record, not the entirety of open source.

Inspected repositories
64,683 of 66,909 indexed
Monthly downloads under inspection
546B registry-reported
Median health index
60 Moderate
Good or better
43% index 65 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

54% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 69% of the entire volume.

Repositories
17%20%25%16%
Download volume
16%18%18%16%
BandRepositoriesDownloads / moVolume share
Exceptional3,47279.6B15%
Excellent10,88588.5B16%
Good13,22082.9B15%
Moderate16,40599.6B18%
Weak10,59195.9B18%
At Risk7,61688.3B16%
Critical2,49411.5B2.1%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality71
1100
Community & Adoption46
1100
Sustainability & Governance59
1100
Engineering Quality65
1100
Security47
1100
AI Readiness53
1100

Category profile

Median category score across the scope. Categories are documented in the methodology wiki.

Vitality
71
Community & Adoption
46
Sustainability & Governance
59
Engineering Quality
65
Security
47
AI Readinessunweighted
53

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
94% of 64,683
License detected
91% of 64,683
Automated tests
85% of 64,683
CI workflows
81% of 64,683
Linter configuration
42% of 64,683
Documentation directory
39% of 64,683
Contributing guide
37% of 64,683
Code of conduct
23% of 64,683
Security policy
19% of 64,683

Agent-era signals

One-command bootstrap
29% of 64,683
AI agent instructions
24% of 64,683
llms.txt
5.5% of 64,683

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 43,792
54 · 41–69
100 – 999 12,338
71 · 54–84
1,000 – 9,999 6,848
83 · 63–91
10,000 and more 1,705
92 · 81–96

By monthly downloads

Under 10K / month 12,530
59 · 47–71
10K – 1M 10,601
67 · 53–81
1M – 100M 4,352
75 · 51–89
100M and more 1,230
53 · 36–80

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.1
Fuzzing
0.6
Signed-Releases
0.9
Branch-Protection
1.3
SAST
1.5
Pinned-Dependencies
1.7
Token-Permissions
1.8
Code-Review
2.1
Security-Policy
2.5
Dependency-Update-Tool
4.1
Maintained
5.4
Contributors
6.1
CI-Tests
6.4
Vulnerabilities
6.6
License
9.0
Dangerous-Workflow
9.7
Binary-Artifacts
9.8
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
4,2126.5% of the record · 6.5% of 64,689 assessed
High-risk jurisdiction exposure
1,1331.8% of the record · 2.0% of 57,599 assessed
Malicious dependencies
690.1% of the record · 0.3% of 27,030 assessed
Inorganic growth
25<0.1% of the record · 1.4% of 1,761 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 3 days of inspection.

Push recency
78%
Last pushRepositoriesShare
Pushed within 30 days50,32578%
31 – 90 days4,6037.1%
91 – 365 days4,1806.5%
Over a year5,5758.6%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

37,925Organization-stewarded median 65
26,758Personal accounts median 53

Maintainer bus factor

75% of inspected repositories depend on a single maintainer for the majority of their commits — including 3,764 with over a million monthly downloads.

1 maintainer
47,916
2 maintainers
9,979
3–5 maintainers
5,325
6+ maintainers
951

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 46,910 reports with a collected dependency graph.

The median repository declares 3 direct dependencies — and resolves to 26 packages in total.

Resolved packages per repository

0
4,946
1 – 5
6,350
6 – 20
10,601
21 – 50
5,405
51 – 200
7,128
201 – 500
4,506
501 – 1,000
3,738
Over 1,000
4,236

License landscape

The most common detected licenses across the scope (SPDX identifiers).

MIT
30,109
Apache-2.0
13,375
Custom license
7,009
No license detected
5,970
BSD-3-Clause
1,979
GPL-3.0
1,665
AGPL-3.0
1,109
MPL-2.0
685
GPL-2.0
589
BSD-2-Clause
534

Ecosystems compared

Each ecosystem's slice of the record. A repository publishing to several ecosystems counts in each. Every row opens that ecosystem's full statistics.

EcosystemInspectedMedian healthBand mixGood or betterDownloads / mo
npm19,564 65 Good53%471B
Go18,138 56 Moderate34%1.3B
PyPI9,793 69 Good57%53.5B
Packagist7,390 57 Moderate33%5.2B
crates.io5,819 67 Good54%29.5B
RubyGems3,148 62 Moderate47%1.4B
Maven2,214 71 Good60%996M
NuGet2,167 60 Moderate44%6M
Hex1,266 51 Moderate22%287M

Most relied upon

The most-downloaded repositories under inspection — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

npm
99Exceptionalhealth index
typescript-eslint/typescript-eslint
:sparkles: Monorepo for all the tooling which enables ESLint to support TypeScript
TypeScript★ 16.4K↓ 3.8B/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm
90Excellenthealth index
npm/node-semver
The semver parser for node (the one npm uses)
JavaScript★ 5,459↓ 3.5B/moAug 29, 2026
ISCAug 29, 2026 · metrics 2.10.0
npm
53Moderatehealth index
jridgewell/sourcemaps
Monorepo for various sourcemap libraries
TypeScript · JavaScript★ 52↓ 3.3B/moAug 29, 2026
No licenseAug 29, 2026 · metrics 2.10.0
npm
98Exceptionalhealth index
babel/babel
🐠 Babel is a compiler for writing next generation JavaScript.
TypeScript · JavaScript★ 44K↓ 3.3B/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm
94Exceptionalhealth index
eslint/js
Monorepo for the JS language tools.
JavaScript★ 2,387↓ 3.1B/moAug 29, 2026
BSD-2-ClauseAug 29, 2026 · metrics 2.10.0
npm
77Goodhealth index
isaacs/minimatch
a glob matcher in javascript
JavaScript · TypeScript★ 3,518↓ 2.9B/moAug 29, 2026
BlueOak-1.0.0Aug 29, 2026 · metrics 2.10.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 2.10.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-09-06 05:11 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.