Record in aggregate · metrics 1.13.0

The state of Hex.

Aggregate statistics across every inspected repository publishing to Hex — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.

Inspected repositories
1,096 of 1,096 indexed
Monthly downloads under inspection
253M registry-reported
Median health index
51 Moderate
Good or better
7% index 70 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

56% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 63% of the entire volume.

Repositories
48%41%
Download volume
33%44%
BandRepositoriesDownloads / moVolume share
Excellent127M11%
Good7183.5M33%
Moderate528112M44%
At risk45126.6M10%
Critical454.7M1.8%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality48
1100
Community & Adoption51
1100
Sustainability & Governance62
1100
Engineering Quality55
1100
Security38
1100
AI Readiness29
1100

Category profile

Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.

Vitality
48
Community & Adoption
51
Sustainability & Governance
62
Engineering Quality
55
Security
38
AI Readinessunweighted
29

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
98% of 1,096
Automated tests
97% of 1,096
License detected
92% of 1,096
CI workflows
83% of 1,096
Contributing guide
20% of 1,096
Code of conduct
17% of 1,096
Documentation directory
11% of 1,096
Security policy
3.8% of 1,096
Linter configuration
1.9% of 1,096

Agent-era signals

One-command bootstrap
13% of 1,096
AI agent instructions
9.7% of 1,096
llms.txt
0.3% of 1,096

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 673
49 · 41–57
100 – 999 347
54 · 46–61
1,000 – 9,999 75
64 · 53–71
10,000 and more 1
78 · 78–78

By monthly downloads

Under 10K / month 480
49 · 41–57
10K – 1M 506
53 · 45–61
1M – 100M 33
64 · 50–70
100M and more 0

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.0
SAST
0.4
Signed-Releases
0.5
Branch-Protection
0.6
Pinned-Dependencies
0.7
Fuzzing
0.9
Security-Policy
1.3
Token-Permissions
1.7
Code-Review
2.3
Dependency-Update-Tool
2.7
Maintained
3.7
CI-Tests
3.9
Vulnerabilities
6.3
Contributors
6.6
License
9.1
Binary-Artifacts
10.0
Dangerous-Workflow
10.0
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

High-risk jurisdiction exposure
242.2% of the record · 2.3% of 1,045 assessed
Abandonment
131.2% of the record · 1.2% of 1,096 assessed
Inorganic growth
1<0.1% of the record · 2.6% of 39 assessed
Malicious dependencies
00% of the record · 0% of 5 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 42 days of inspection.

Push recency
43%19%23%
Last pushRepositoriesShare
Pushed within 30 days46843%
31 – 90 days20919%
91 – 365 days25723%
Over a year16215%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

625Organization-stewarded median 55
471Personal accounts median 46

Maintainer bus factor

78% of inspected repositories depend on a single maintainer for the majority of their commits — including 13 with over a million monthly downloads.

1 maintainer
857
2 maintainers
173
3–5 maintainers
62
6+ maintainers
3

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 863 reports with a collected dependency graph.

The median repository declares 0 direct dependencies — and resolves to 0 packages in total.

Resolved packages per repository

0
733
1 – 5
10
6 – 20
18
21 – 50
28
51 – 200
39
201 – 500
17
501 – 1,000
14
Over 1,000
4

License landscape

The most common detected licenses across the scope (SPDX identifiers).

MIT
536
Apache-2.0
273
Custom license
163
No license detected
90
BSD-2-Clause
10
BSD-3-Clause
9
GPL-3.0
3
ISC
3
MPL-2.0
2
Unlicense
2

Most relied upon

The most-downloaded repositories under inspection publishing to Hex — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

npm · Hex
68Moderatehealth index
supabase/phoenix
Peace of mind from prototype to production
Elixir · JavaScript★ 3↓ 50.2M/moJul 19, 2026
MITJul 19, 2026 · metrics 1.13.0
Go · Hex · Maven +4
79Goodhealth index
cucumber/messages
A message protocol for representing results and other information from Cucumber
C#★ 40↓ 30.1M/moJul 13, 2026
MITJul 13, 2026 · metrics 1.13.0
npm · PyPI · Packagist +4
82Goodhealth index
cucumber/gherkin
A parser and compiler for the Gherkin language.
C★ 372↓ 27.8M/moJul 19, 2026
MITJul 19, 2026 · metrics 1.13.0
npm · Hex · crates.io +2
87Excellenthealth index
taskforcesh/bullmq
BullMQ - Message Queue and Batch processing for NodeJS, Python, Elixir and PHP based on Redis
TypeScript · Rust · Elixir★ 9,127↓ 27M/moJul 16, 2026
MITJul 16, 2026 · metrics 1.13.0
crates.io · Go · Hex +4
64Moderatehealth index
statsig-io/statsig-server-core
No repository description published.
Rust★ 24↓ 7.3M/moJul 13, 2026
ISCJul 13, 2026 · metrics 1.13.0
PyPI · crates.io · Go +1
75Goodhealth index
ethereum/c-kzg-4844
A minimal implementation of the Polynomial Commitments API for EIP-4844 and EIP-7594, written in C.
C · Rust★ 171↓ 7M/moJul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 1.13.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 1.13.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-07-23 05:46 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.