Record in aggregate · metrics 1.13.0

The state of crates.io.

Aggregate statistics across every inspected repository publishing to crates.io — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.

Inspected repositories
2,471 of 2,472 indexed
Monthly downloads under inspection
12.5B registry-reported
Median health index
62 Moderate
Good or better
27% index 70 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

50% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 59% of the entire volume.

Repositories
25%56%
Download volume
43%40%
BandRepositoriesDownloads / moVolume share
Excellent49824M6.6%
Good6115.4B43%
Moderate1,3774.9B40%
At risk3621.2B10.0%
Critical7267.9M0.5%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality79
1100
Community & Adoption55
1100
Sustainability & Governance62
1100
Engineering Quality66
1100
Security48
1100
AI Readiness50
1100

Category profile

Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.

Vitality
79
Community & Adoption
55
Sustainability & Governance
62
Engineering Quality
66
Security
48
AI Readinessunweighted
50

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
96% of 2,471
CI workflows
95% of 2,471
License detected
94% of 2,471
Automated tests
84% of 2,471
Documentation directory
43% of 2,471
Contributing guide
39% of 2,471
Linter configuration
24% of 2,471
Security policy
23% of 2,471
Code of conduct
23% of 2,471

Agent-era signals

One-command bootstrap
35% of 2,471
AI agent instructions
31% of 2,471
llms.txt
2.5% of 2,471

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 1,293
56 · 48–62
100 – 999 653
65 · 58–71
1,000 – 9,999 364
73 · 67–77
10,000 and more 161
79 · 73–83

By monthly downloads

Under 10K / month 858
60 · 53–68
10K – 1M 692
63 · 55–71
1M – 100M 279
65 · 56–73
100M and more 21
73 · 66–76

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.1
Signed-Releases
0.8
Fuzzing
1.4
SAST
1.4
Token-Permissions
1.7
Branch-Protection
1.8
Pinned-Dependencies
1.9
Code-Review
2.8
Security-Policy
2.9
Dependency-Update-Tool
4.8
Vulnerabilities
5.6
Contributors
7.0
Maintained
7.3
CI-Tests
7.8
License
9.3
Binary-Artifacts
9.5
Dangerous-Workflow
9.7
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

High-risk jurisdiction exposure
532.1% of the record · 2.3% of 2,274 assessed
Abandonment
311.3% of the record · 1.3% of 2,472 assessed
Malicious dependencies
1<0.1% of the record · 0.3% of 327 assessed
Inorganic growth
00% of the record · 0% of 122 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 0 days of inspection.

Push recency
92%
Last pushRepositoriesShare
Pushed within 30 days2,28192%
31 – 90 days461.9%
91 – 365 days763.1%
Over a year682.8%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

1,467Organization-stewarded median 65
1,004Personal accounts median 57

Maintainer bus factor

72% of inspected repositories depend on a single maintainer for the majority of their commits — including 188 with over a million monthly downloads.

1 maintainer
1,785
2 maintainers
382
3–5 maintainers
234
6+ maintainers
66

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 1,351 reports with a collected dependency graph.

The median repository declares 12 direct dependencies — and resolves to 233 packages in total.

Resolved packages per repository

0
29
1 – 5
95
6 – 20
191
21 – 50
120
51 – 200
200
201 – 500
264
501 – 1,000
188
Over 1,000
264

License landscape

The most common detected licenses across the scope (SPDX identifiers).

Apache-2.0
950
MIT
869
Custom license
259
No license detected
152
GPL-3.0
55
AGPL-3.0
48
BSD-3-Clause
45
MPL-2.0
31
ISC
12
Unlicense
10

Most relied upon

The most-downloaded repositories under inspection publishing to crates.io — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

PyPI · crates.io
84Goodhealth index
pyca/cryptography
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.
Python · Rust★ 7,664↓ 1.4B/moJul 16, 2026
Custom licenseJul 16, 2026 · metrics 1.13.0
npm · crates.io
68Moderatehealth index
mozilla/source-map
Consume and generate source maps.
JavaScript · Rust★ 3,727↓ 1.3B/moJul 22, 2026
Custom licenseJul 22, 2026 · metrics 1.13.0
npm · crates.io
87Excellenthealth index
rollup/rollup
Next-generation ES module bundler
JavaScript · TypeScript★ 26.3K↓ 536M/moJul 22, 2026
Custom licenseJul 22, 2026 · metrics 1.13.0
crates.io
75Goodhealth index
rust-lang/futures-rs
Zero-cost asynchronous programming in Rust
Rust★ 5,881↓ 395M/moJul 18, 2026
Apache-2.0Jul 18, 2026 · metrics 1.13.0
npm · crates.io
70Goodhealth index
parcel-bundler/lightningcss
An extremely fast CSS parser, transformer, bundler, and minifier written in Rust.
Rust★ 7,621↓ 362M/moJul 20, 2026
MPL-2.0Jul 20, 2026 · metrics 1.13.0
PyPI · crates.io
68Moderatehealth index
samuelcolvin/watchfiles
Simple, modern and fast file watching and code reload for Python, written in Rust
Python · Rust★ 2,518↓ 326M/moJul 16, 2026
MITJul 16, 2026 · metrics 1.13.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 1.13.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-07-23 05:46 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.