Record in aggregate · metrics 1.13.0

The state of Maven.

Aggregate statistics across every inspected repository publishing to Maven — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.

Inspected repositories
874 of 875 indexed
Monthly downloads under inspection
518M registry-reported
Median health index
65 Moderate
Good or better
37% index 70 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

26% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 67% of the entire volume.

Repositories
33%41%16%
Download volume
17%56%23%
BandRepositoriesDownloads / moVolume share
Excellent3389.5M17%
Good286291M56%
Moderate35514.1M2.7%
At risk141120M23%
Critical592.6M0.5%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality82
1100
Community & Adoption62
1100
Sustainability & Governance65
1100
Engineering Quality68
1100
Security49
1100
AI Readiness50
1100

Category profile

Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.

Vitality
82
Community & Adoption
62
Sustainability & Governance
65
Engineering Quality
68
Security
49
AI Readinessunweighted
50

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
95% of 874
Automated tests
93% of 874
License detected
93% of 874
CI workflows
82% of 874
Contributing guide
51% of 874
Documentation directory
45% of 874
Code of conduct
34% of 874
Linter configuration
31% of 874
Security policy
24% of 874

Agent-era signals

AI agent instructions
33% of 874
One-command bootstrap
22% of 874
llms.txt
2.2% of 874

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 388
56 · 46–65
100 – 999 193
70 · 60–76
1,000 – 9,999 151
74 · 65–80
10,000 and more 142
74 · 58–81

By monthly downloads

Under 10K / month 131
56 · 49–67
10K – 1M 80
69 · 63–75
1M – 100M 30
80 · 74–83
100M and more 1
40 · 40–40

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.1
Fuzzing
0.7
Signed-Releases
0.7
Branch-Protection
1.8
Token-Permissions
1.8
Pinned-Dependencies
1.9
SAST
2.5
Code-Review
3.3
Security-Policy
3.5
Vulnerabilities
4.7
Dependency-Update-Tool
5.3
CI-Tests
7.2
Maintained
7.2
Contributors
7.6
Binary-Artifacts
8.6
License
9.2
Dangerous-Workflow
9.5
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
424.8% of the record · 4.8% of 875 assessed
High-risk jurisdiction exposure
263.0% of the record · 3.3% of 801 assessed
Malicious dependencies
10.1% of the record · 0.7% of 149 assessed
Inorganic growth
10.1% of the record · 1.3% of 79 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 1 day of inspection.

Push recency
84%
Last pushRepositoriesShare
Pushed within 30 days73784%
31 – 90 days343.9%
91 – 365 days303.4%
Over a year738.4%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

681Organization-stewarded median 68
193Personal accounts median 52

Maintainer bus factor

55% of inspected repositories depend on a single maintainer for the majority of their commits — including 7 with over a million monthly downloads.

1 maintainer
475
2 maintainers
200
3–5 maintainers
143
6+ maintainers
51

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 697 reports with a collected dependency graph.

The median repository declares 14 direct dependencies — and resolves to 129 packages in total.

Resolved packages per repository

0
83
1 – 5
19
6 – 20
51
21 – 50
82
51 – 200
159
201 – 500
96
501 – 1,000
66
Over 1,000
141

License landscape

The most common detected licenses across the scope (SPDX identifiers).

Apache-2.0
352
MIT
210
Custom license
114
No license detected
64
GPL-3.0
39
AGPL-3.0
25
BSD-3-Clause
18
MPL-2.0
15
EPL-2.0
9
GPL-2.0
7

Most relied upon

The most-downloaded repositories under inspection publishing to Maven — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

PyPI · npm · Packagist +2
40At riskhealth index
google/flatbuffers
FlatBuffers: Memory Efficient Serialization Library
C++ · Rust★ 26.2K↓ 120M/moJul 20, 2026
Apache-2.0Jul 20, 2026 · metrics 1.13.0
PyPI · Maven
86Excellenthealth index
dmlc/xgboost
Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library, for Python, R, Java, Scala, C++ and more. Runs on single machine, Hadoop, Spark, Dask, Flink and DataFlow
C++ · Python · Cuda★ 28.6K↓ 47.5M/moJul 18, 2026
Apache-2.0Jul 18, 2026 · metrics 1.13.0
Maven · npm
81Goodhealth index
ionic-team/capacitor
Build cross-platform Native Progressive Web Apps for iOS, Android, and the Web ⚡️
TypeScript★ 16.1K↓ 43.7M/moJul 14, 2026
MITJul 14, 2026 · metrics 1.13.0
Go · Hex · Maven +4
79Goodhealth index
cucumber/messages
A message protocol for representing results and other information from Cucumber
C#★ 40↓ 30.1M/moJul 13, 2026
MITJul 13, 2026 · metrics 1.13.0
npm · Maven · RubyGems
74Goodhealth index
AppAndFlow/react-native-safe-area-context
A flexible way to handle safe area insets in JS. Also works on Android and Web!
TypeScript · Objective-C · Kotlin★ 2,743↓ 29.8M/moJul 22, 2026
MITJul 22, 2026 · metrics 1.13.0
PyPI · npm · Go +1
93Excellenthealth index
apache/airflow
Apache Airflow - A platform to programmatically author, schedule, and monitor workflows
Python★ 46.2K↓ 28.9M/moJul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 1.13.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 1.13.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-07-23 05:46 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.