Record in aggregate · metrics 2.10.0

The state of NuGet.

Aggregate statistics across every inspected repository publishing to NuGet — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.

Inspected repositories
3,102 of 3,102 indexed
Monthly downloads under inspection
6.1M registry-reported
Median health index
69 Good
Good or better
56% index 65 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

8.6% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 100% of the entire volume.

Repositories
29%23%20%
Download volume
65%
BandRepositoriesDownloads / moVolume share
Exceptional107820.9K13%
Excellent900778.5K13%
Good7204M65%
Moderate626461.5K7.5%
Weak39757.6K0.9%
At Risk2462,7790.0%
Critical1064,8960.1%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality79
1100
Community & Adoption50
1100
Sustainability & Governance57
1100
Engineering Quality61
1100
Security58
1100
AI Readiness45
1100

Category profile

Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.

Vitality
79
Community & Adoption
50
Sustainability & Governance
57
Engineering Quality
61
Security
58
AI Readinessunweighted
45

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
97% of 3,102
License detected
96% of 3,102
CI workflows
80% of 3,102
Automated tests
63% of 3,102
Contributing guide
46% of 3,102
Code of conduct
41% of 3,102
Security policy
34% of 3,102
Documentation directory
28% of 3,102
Linter configuration
3.9% of 3,102

Agent-era signals

AI agent instructions
21% of 3,102
llms.txt
5.4% of 3,102
One-command bootstrap
2.7% of 3,102

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 2,263
67 · 48–80
100 – 999 558
65 · 50–81
1,000 – 9,999 256
83 · 66–91
10,000 and more 25
94 · 82–98

By monthly downloads

Under 10K / month 33
71 · 54–82
10K – 1M 12
74 · 57–93
1M – 100M 1
77 · 77–77
100M and more 0

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.0
Fuzzing
0.1
Signed-Releases
0.1
Pinned-Dependencies
0.9
Token-Permissions
1.2
Code-Review
1.4
Branch-Protection
2.1
SAST
3.1
Security-Policy
3.6
Contributors
5.2
Dependency-Update-Tool
5.6
CI-Tests
7.1
Maintained
7.3
Vulnerabilities
9.3
Binary-Artifacts
9.5
License
9.5
Dangerous-Workflow
9.8
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
1454.7% of the record · 4.7% of 3,102 assessed
High-risk jurisdiction exposure
601.9% of the record · 2.1% of 2,926 assessed
Malicious dependencies
30.1% of the record · 0.1% of 2,497 assessed
Inorganic growth
00% of the record · 0% of 44 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 0 days of inspection.

Push recency
87%
Last pushRepositoriesShare
Pushed within 30 days2,68787%
31 – 90 days1414.5%
91 – 365 days1123.6%
Over a year1625.2%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

1,329Organization-stewarded median 65
1,773Personal accounts median 73

Maintainer bus factor

87% of inspected repositories depend on a single maintainer for the majority of their commits — including 1 with over a million monthly downloads.

1 maintainer
2,686
2 maintainers
265
3–5 maintainers
131
6+ maintainers
16

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 2,888 reports with a collected dependency graph.

The median repository declares 6 direct dependencies — and resolves to 11 packages in total.

Resolved packages per repository

0
44
1 – 5
745
6 – 20
1,183
21 – 50
434
51 – 200
266
201 – 500
88
501 – 1,000
70
Over 1,000
58

License landscape

The most common detected licenses across the scope (SPDX identifiers).

MIT
2,178
Apache-2.0
351
Custom license
244
No license detected
114
BSD-3-Clause
64
GPL-3.0
36
MPL-2.0
19
LGPL-3.0
17
BSD-2-Clause
13
AGPL-3.0
12

Most relied upon

The most-downloaded repositories under inspection publishing to NuGet — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

PyPI · NuGet
77Goodhealth index
pythonnet/clr-loader
Loader for different .NET runtimes
Python★ 43↓ 3.1M/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm · Maven · NuGet
78Goodhealth index
renovatebot/pgp
Renovate PGP library
TypeScript · Java · JavaScript★ 0↓ 1M/moSep 11, 2026
Apache-2.0Sep 11, 2026 · metrics 2.10.0
npm · Maven · NuGet +1
92Excellenthealth index
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1,018↓ 745.3K/moJul 28, 2026
Apache-2.0Jul 28, 2026 · metrics 2.10.0
Packagist · crates.io · NuGet
96Exceptionalhealth index
DataDog/dd-trace-php
Datadog PHP Clients
PHP★ 558↓ 665.6K/moAug 22, 2026
Custom licenseAug 22, 2026 · metrics 2.10.0
PyPI · NuGet
59Moderatehealth index
pywinrt/pywinrt
Python projection of Windows runtime (WinRT) types.
C++★ 196↓ 362.3K/moAug 3, 2026
MITAug 3, 2026 · metrics 2.10.0
npm · NuGet
93Exceptionalhealth index
microsoft/sarif-sdk
.NET code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oasis-tcs/sarif-spec)
C# · C★ 225↓ 132K/moSep 11, 2026
Custom licenseSep 11, 2026 · metrics 2.10.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 2.10.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-09-11 06:16 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.