Record in aggregate · metrics 2.10.0

The state of crates.io.

Aggregate statistics across every inspected repository publishing to crates.io — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.

Inspected repositories
5,913 of 5,913 indexed
Monthly downloads under inspection
30.5B registry-reported
Median health index
67 Good
Good or better
55% index 65 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

31% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 43% of the entire volume.

Repositories
22%26%25%
Download volume
18%28%23%
BandRepositoriesDownloads / moVolume share
Exceptional4215.5B18%
Excellent1,2818.5B28%
Good1,5227.1B23%
Moderate1,4833.7B12%
Weak5991.9B6.3%
At Risk4303.5B11%
Critical177393M1.3%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality73
1100
Community & Adoption53
1100
Sustainability & Governance62
1100
Engineering Quality67
1100
Security52
1100
AI Readiness61
1100

Category profile

Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.

Vitality
73
Community & Adoption
53
Sustainability & Governance
62
Engineering Quality
67
Security
52
AI Readinessunweighted
61

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
95% of 5,913
License detected
94% of 5,913
CI workflows
92% of 5,913
Automated tests
78% of 5,913
Documentation directory
36% of 5,913
Linter configuration
35% of 5,913
Contributing guide
32% of 5,913
Security policy
18% of 5,913
Code of conduct
18% of 5,913

Agent-era signals

One-command bootstrap
29% of 5,913
AI agent instructions
25% of 5,913
llms.txt
6.7% of 5,913

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 3,443
59 · 47–71
100 – 999 1,562
73 · 62–84
1,000 – 9,999 709
87 · 78–92
10,000 and more 199
94 · 88–97

By monthly downloads

Under 10K / month 1,863
65 · 54–78
10K – 1M 1,799
73 · 59–84
1M – 100M 1,121
65 · 48–83
100M and more 42
86 · 72–90

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.0
Signed-Releases
0.7
SAST
1.1
Fuzzing
1.3
Branch-Protection
1.4
Pinned-Dependencies
1.6
Token-Permissions
1.6
Security-Policy
2.3
Code-Review
2.5
Dependency-Update-Tool
4.3
Maintained
6.4
Vulnerabilities
6.5
Contributors
6.7
CI-Tests
7.0
License
9.3
Binary-Artifacts
9.6
Dangerous-Workflow
9.8
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
3736.3% of the record · 6.3% of 5,913 assessed
High-risk jurisdiction exposure
450.8% of the record · 0.8% of 5,495 assessed
Malicious dependencies
60.1% of the record · 0.2% of 3,744 assessed
Inorganic growth
00% of the record · 0% of 117 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 3 days of inspection.

Push recency
77%
Last pushRepositoriesShare
Pushed within 30 days4,56677%
31 – 90 days58910.0%
91 – 365 days3606.1%
Over a year3986.7%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

3,154Organization-stewarded median 75
2,759Personal accounts median 59

Maintainer bus factor

79% of inspected repositories depend on a single maintainer for the majority of their commits — including 830 with over a million monthly downloads.

1 maintainer
4,668
2 maintainers
744
3–5 maintainers
405
6+ maintainers
89

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 4,462 reports with a collected dependency graph.

The median repository declares 11 direct dependencies — and resolves to 82 packages in total.

Resolved packages per repository

0
189
1 – 5
542
6 – 20
834
21 – 50
472
51 – 200
684
201 – 500
750
501 – 1,000
481
Over 1,000
510

License landscape

The most common detected licenses across the scope (SPDX identifiers).

Apache-2.0
2,364
MIT
2,017
Custom license
573
No license detected
354
GPL-3.0
113
MPL-2.0
111
BSD-3-Clause
101
AGPL-3.0
95
Unlicense
41
BSD-2-Clause
30

Most relied upon

The most-downloaded repositories under inspection publishing to crates.io — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

npm · crates.io
77Goodhealth index
mozilla/source-map
Consume and generate source maps.
JavaScript · Rust★ 3,724↓ 1.4B/moAug 4, 2026
Custom licenseAug 4, 2026 · metrics 2.10.0
npm · crates.io
94Exceptionalhealth index
tailwindlabs/tailwindcss
A utility-first CSS framework for rapid UI development.
TypeScript · Rust★ 96.4K↓ 1.1B/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
npm · crates.io
95Exceptionalhealth index
pnpm/pnpm
Fast, disk space efficient package manager
Rust · TypeScript★ 36K↓ 581M/moAug 5, 2026
MITAug 5, 2026 · metrics 2.10.0
PyPI · crates.io
90Excellenthealth index
crate-py/rpds
Python bindings to the Rust rpds crate for persistent data structures
Rust · Python★ 64↓ 536M/moSep 9, 2026
MITSep 9, 2026 · metrics 2.10.0
npm · crates.io
98Exceptionalhealth index
rollup/rollup
Next-generation ES module bundler
JavaScript · TypeScript★ 26.3K↓ 528M/moAug 4, 2026
Custom licenseAug 4, 2026 · metrics 2.10.0
PyPI · crates.io
88Excellenthealth index
pydantic/jiter
Fast iterable JSON parser.
Rust★ 545↓ 426M/moAug 29, 2026
MITAug 29, 2026 · metrics 2.10.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 2.10.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-09-11 06:16 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.