Record in aggregate · metrics 2.10.0

The state of npm.

Aggregate statistics across every inspected repository publishing to npm — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.

Inspected repositories
19,569 of 19,570 indexed
Monthly downloads under inspection
471B registry-reported
Median health index
65 Good
Good or better
53% index 65 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

59% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 42% of the entire volume.

Repositories
22%23%24%
Download volume
20%20%17%
BandRepositoriesDownloads / moVolume share
Exceptional1,55455.3B12%
Excellent4,32768.8B15%
Good4,44569.7B15%
Moderate4,71892.2B20%
Weak2,29592.4B20%
At Risk1,69482B17%
Critical53610.7B2.3%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality76
1100
Community & Adoption49
1100
Sustainability & Governance60
1100
Engineering Quality70
1100
Security50
1100
AI Readiness59
1100

Category profile

Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.

Vitality
76
Community & Adoption
49
Sustainability & Governance
60
Engineering Quality
70
Security
50
AI Readinessunweighted
59

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
96% of 19,569
License detected
90% of 19,569
Automated tests
87% of 19,569
CI workflows
86% of 19,569
Linter configuration
58% of 19,569
Documentation directory
45% of 19,569
Contributing guide
43% of 19,569
Code of conduct
27% of 19,569
Security policy
24% of 19,569

Agent-era signals

AI agent instructions
35% of 19,569
One-command bootstrap
18% of 19,569
llms.txt
8.7% of 19,569

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 12,506
60 · 47–73
100 – 999 3,765
78 · 62–87
1,000 – 9,999 2,417
86 · 69–92
10,000 and more 881
93 · 83–96

By monthly downloads

Under 10K / month 6,877
60 · 48–73
10K – 1M 4,360
77 · 59–86
1M – 100M 1,720
83 · 60–93
100M and more 1,119
51 · 35–77

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.1
Fuzzing
0.4
Signed-Releases
0.7
Branch-Protection
1.4
Token-Permissions
1.8
SAST
1.9
Code-Review
2.2
Pinned-Dependencies
2.2
Security-Policy
3.0
Vulnerabilities
3.8
Dependency-Update-Tool
4.8
Contributors
6.3
Maintained
6.3
CI-Tests
7.0
License
8.9
Dangerous-Workflow
9.6
Binary-Artifacts
9.7
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
1,1495.9% of the record · 5.9% of 19,570 assessed
High-risk jurisdiction exposure
2621.3% of the record · 1.5% of 17,392 assessed
Malicious dependencies
570.3% of the record · 0.5% of 11,558 assessed
Inorganic growth
4<0.1% of the record · 0.9% of 434 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 3 days of inspection.

Push recency
82%
Last pushRepositoriesShare
Pushed within 30 days16,01182%
31 – 90 days1,2756.5%
91 – 365 days9094.6%
Over a year1,3747.0%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

12,012Organization-stewarded median 73
7,557Personal accounts median 57

Maintainer bus factor

75% of inspected repositories depend on a single maintainer for the majority of their commits — including 1,922 with over a million monthly downloads.

1 maintainer
14,552
2 maintainers
2,964
3–5 maintainers
1,644
6+ maintainers
292

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 13,844 reports with a collected dependency graph.

The median repository declares 6 direct dependencies — and resolves to 508 packages in total.

Resolved packages per repository

0
266
1 – 5
593
6 – 20
1,140
21 – 50
764
51 – 200
1,461
201 – 500
2,626
501 – 1,000
3,085
Over 1,000
3,909

License landscape

The most common detected licenses across the scope (SPDX identifiers).

MIT
10,691
Apache-2.0
3,152
No license detected
1,892
Custom license
1,817
AGPL-3.0
484
GPL-3.0
395
BSD-3-Clause
309
ISC
220
MPL-2.0
117
GPL-2.0
97

Most relied upon

The most-downloaded repositories under inspection publishing to npm — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

npm
99Exceptionalhealth index
typescript-eslint/typescript-eslint
:sparkles: Monorepo for all the tooling which enables ESLint to support TypeScript
TypeScript★ 16.4K↓ 3.8B/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm
90Excellenthealth index
npm/node-semver
The semver parser for node (the one npm uses)
JavaScript★ 5,459↓ 3.5B/moAug 29, 2026
ISCAug 29, 2026 · metrics 2.10.0
npm
53Moderatehealth index
jridgewell/sourcemaps
Monorepo for various sourcemap libraries
TypeScript · JavaScript★ 52↓ 3.3B/moAug 29, 2026
No licenseAug 29, 2026 · metrics 2.10.0
npm
98Exceptionalhealth index
babel/babel
🐠 Babel is a compiler for writing next generation JavaScript.
TypeScript · JavaScript★ 44K↓ 3.3B/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm
94Exceptionalhealth index
eslint/js
Monorepo for the JS language tools.
JavaScript★ 2,387↓ 3.1B/moAug 29, 2026
BSD-2-ClauseAug 29, 2026 · metrics 2.10.0
npm
77Goodhealth index
isaacs/minimatch
a glob matcher in javascript
JavaScript · TypeScript★ 3,518↓ 2.9B/moAug 29, 2026
BlueOak-1.0.0Aug 29, 2026 · metrics 2.10.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 2.10.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-09-06 06:32 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.