Record in aggregate · metrics 2.10.0

The state of Maven.

Aggregate statistics across every inspected repository publishing to Maven — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.

Inspected repositories
2,218 of 2,219 indexed
Monthly downloads under inspection
996M registry-reported
Median health index
71 Good
Good or better
60% index 65 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

4.4% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 86% of the entire volume.

Repositories
26%21%18%
Download volume
70%25%
BandRepositoriesDownloads / moVolume share
Exceptional273696M70%
Excellent587245M25%
Good46611.9M1.2%
Moderate3893M0.3%
Weak1852.2M0.2%
At Risk20738M3.8%
Critical111841.5K0.1%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality79
1100
Community & Adoption57
1100
Sustainability & Governance66
1100
Engineering Quality66
1100
Security52
1100
AI Readiness59
1100

Category profile

Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.

Vitality
79
Community & Adoption
57
Sustainability & Governance
66
Engineering Quality
66
Security
52
AI Readinessunweighted
59

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
95% of 2,218
License detected
94% of 2,218
Automated tests
92% of 2,218
CI workflows
82% of 2,218
Contributing guide
46% of 2,218
Documentation directory
42% of 2,218
Code of conduct
31% of 2,218
Security policy
23% of 2,218
Linter configuration
23% of 2,218

Agent-era signals

AI agent instructions
30% of 2,218
One-command bootstrap
17% of 2,218
llms.txt
7.2% of 2,218

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 1,111
59 · 44–75
100 – 999 547
80 · 65–88
1,000 – 9,999 388
88 · 75–94
10,000 and more 172
90 · 62–96

By monthly downloads

Under 10K / month 211
60 · 50–78
10K – 1M 175
80 · 69–90
1M – 100M 47
92 · 86–96
100M and more 1
96 · 96–96

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.1
Fuzzing
0.6
Signed-Releases
0.7
Branch-Protection
1.4
Pinned-Dependencies
1.7
Token-Permissions
1.9
SAST
2.3
Code-Review
3.0
Security-Policy
3.4
Vulnerabilities
5.4
Dependency-Update-Tool
5.5
CI-Tests
7.0
Maintained
7.1
Contributors
7.4
Binary-Artifacts
8.7
License
9.2
Dangerous-Workflow
9.5
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
1848.3% of the record · 8.3% of 2,219 assessed
High-risk jurisdiction exposure
492.2% of the record · 2.4% of 2,047 assessed
Malicious dependencies
30.1% of the record · 0.2% of 1,316 assessed
Inorganic growth
1<0.1% of the record · 1.3% of 76 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 2 days of inspection.

Push recency
83%
Last pushRepositoriesShare
Pushed within 30 days1,83483%
31 – 90 days1084.9%
91 – 365 days944.2%
Over a year1828.2%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

1,692Organization-stewarded median 77
526Personal accounts median 54

Maintainer bus factor

60% of inspected repositories depend on a single maintainer for the majority of their commits — including 12 with over a million monthly downloads.

1 maintainer
1,320
2 maintainers
467
3–5 maintainers
328
6+ maintainers
91

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 1,843 reports with a collected dependency graph.

The median repository declares 8 direct dependencies — and resolves to 82 packages in total.

Resolved packages per repository

0
301
1 – 5
56
6 – 20
188
21 – 50
229
51 – 200
431
201 – 500
210
501 – 1,000
151
Over 1,000
277

License landscape

The most common detected licenses across the scope (SPDX identifiers).

Apache-2.0
1,029
MIT
464
Custom license
272
No license detected
144
GPL-3.0
82
AGPL-3.0
47
BSD-3-Clause
35
EPL-2.0
31
MPL-2.0
26
LGPL-3.0
22

Most relied upon

The most-downloaded repositories under inspection publishing to Maven — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

npm · Maven · RubyGems
96Exceptionalhealth index
react/react-native
A framework for building native applications using React
C++ · Kotlin · JavaScript★ 126.3K↓ 178M/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
PyPI · Maven
98Exceptionalhealth index
pytorch/pytorch
Tensors and Dynamic neural networks in Python with strong GPU acceleration
Python · C++★ 102.2K↓ 95.6M/moAug 4, 2026
Custom licenseAug 4, 2026 · metrics 2.10.0
npm · crates.io · Maven +1
100Exceptionalhealth index
microsoft/onnxruntime
ONNX Runtime: cross-platform, high performance ML inferencing and training accelerator
C++★ 21.3K↓ 52.8M/moAug 5, 2026
MITAug 5, 2026 · metrics 2.10.0
npm · Maven
94Exceptionalhealth index
ionic-team/capacitor
Build cross-platform Native Progressive Web Apps for iOS, Android, and the Web ⚡️
TypeScript · Java · Swift★ 16.2K↓ 49.3M/moAug 5, 2026
MITAug 5, 2026 · metrics 2.10.0
crates.io · Maven
96Exceptionalhealth index
smithy-lang/smithy-rs
Code generation for the AWS SDK for Rust, as well as server and generic smithy client generation.
Rust · Kotlin★ 657↓ 40.7M/moAug 23, 2026
Apache-2.0Aug 23, 2026 · metrics 2.10.0
npm · Maven · RubyGems
88Excellenthealth index
appandflow/react-native-safe-area-context
A flexible way to handle safe area insets in JS. Also works on Android and Web!
TypeScript · Objective-C · Kotlin★ 2,753↓ 35.6M/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 2.10.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-09-06 09:17 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.