Record in aggregate · metrics 2.10.0

The state of NuGet.

Aggregate statistics across every inspected repository publishing to NuGet — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.

Inspected repositories
2,169 of 2,169 indexed
Monthly downloads under inspection
6M registry-reported
Median health index
60 Moderate
Good or better
44% index 65 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

8.8% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 100% of the entire volume.

Repositories
17%24%25%16%
Download volume
67%
BandRepositoriesDownloads / moVolume share
Exceptional75684.7K11%
Excellent360777.7K13%
Good5304M67%
Moderate551463.7K7.7%
Weak35357.6K1.0%
At Risk2192,7790.0%
Critical814,8960.1%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality73
1100
Community & Adoption49
1100
Sustainability & Governance59
1100
Engineering Quality54
1100
Security53
1100
AI Readiness48
1100

Category profile

Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.

Vitality
73
Community & Adoption
49
Sustainability & Governance
59
Engineering Quality
54
Security
53
AI Readinessunweighted
48

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
96% of 2,169
License detected
95% of 2,169
CI workflows
75% of 2,169
Automated tests
51% of 2,169
Contributing guide
35% of 2,169
Documentation directory
34% of 2,169
Code of conduct
27% of 2,169
Security policy
19% of 2,169
Linter configuration
4.7% of 2,169

Agent-era signals

AI agent instructions
26% of 2,169
llms.txt
5.2% of 2,169
One-command bootstrap
3.3% of 2,169

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 1,509
57 · 44–73
100 – 999 434
65 · 50–80
1,000 – 9,999 202
81 · 65–90
10,000 and more 24
94 · 89–98

By monthly downloads

Under 10K / month 32
69 · 53–80
10K – 1M 11
71 · 56–92
1M – 100M 1
77 · 77–77
100M and more 0

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.0
Fuzzing
0.1
Signed-Releases
0.1
Pinned-Dependencies
1.1
Token-Permissions
1.4
Branch-Protection
1.5
Code-Review
1.5
SAST
2.2
Security-Policy
2.2
Dependency-Update-Tool
4.5
Contributors
5.5
CI-Tests
6.3
Maintained
6.8
Vulnerabilities
9.1
Binary-Artifacts
9.4
License
9.4
Dangerous-Workflow
9.7
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
813.7% of the record · 3.7% of 2,169 assessed
High-risk jurisdiction exposure
532.4% of the record · 2.6% of 2,005 assessed
Malicious dependencies
2<0.1% of the record · 0.1% of 1,463 assessed
Inorganic growth
00% of the record · 0% of 45 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 0 days of inspection.

Push recency
88%
Last pushRepositoriesShare
Pushed within 30 days1,91988%
31 – 90 days572.6%
91 – 365 days843.9%
Over a year1095.0%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

1,123Organization-stewarded median 63
1,046Personal accounts median 57

Maintainer bus factor

84% of inspected repositories depend on a single maintainer for the majority of their commits — including 1 with over a million monthly downloads.

1 maintainer
1,820
2 maintainers
220
3–5 maintainers
111
6+ maintainers
14

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 1,985 reports with a collected dependency graph.

The median repository declares 8 direct dependencies — and resolves to 15 packages in total.

Resolved packages per repository

0
34
1 – 5
325
6 – 20
868
21 – 50
374
51 – 200
203
201 – 500
76
501 – 1,000
54
Over 1,000
51

License landscape

The most common detected licenses across the scope (SPDX identifiers).

MIT
1,392
Apache-2.0
280
Custom license
207
No license detected
105
BSD-3-Clause
58
GPL-3.0
30
MPL-2.0
17
LGPL-3.0
14
BSD-2-Clause
12
AGPL-3.0
10

Most relied upon

The most-downloaded repositories under inspection publishing to NuGet — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

PyPI · NuGet
77Goodhealth index
pythonnet/clr-loader
Loader for different .NET runtimes
Python★ 43↓ 3.1M/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm · Maven · NuGet
77Goodhealth index
renovatebot/pgp
Renovate PGP library
TypeScript · Java · JavaScript★ 0↓ 907.2K/moJul 18, 2026
Apache-2.0Jul 18, 2026 · metrics 2.10.0
npm · Maven · NuGet +1
92Excellenthealth index
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1,018↓ 745.3K/moJul 28, 2026
Apache-2.0Jul 28, 2026 · metrics 2.10.0
Packagist · crates.io · NuGet
96Exceptionalhealth index
DataDog/dd-trace-php
Datadog PHP Clients
PHP★ 558↓ 665.6K/moAug 22, 2026
Custom licenseAug 22, 2026 · metrics 2.10.0
PyPI · NuGet
59Moderatehealth index
pywinrt/pywinrt
Python projection of Windows runtime (WinRT) types.
C++★ 196↓ 362.3K/moAug 3, 2026
MITAug 3, 2026 · metrics 2.10.0
npm · NuGet
63Moderatehealth index
microsoft/node-api-dotnet
Advanced interoperability between .NET and JavaScript in the same process.
C#★ 778↓ 55.6K/moJul 21, 2026
MITJul 21, 2026 · metrics 2.10.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 2.10.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-09-06 06:32 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.