Health-index distribution
Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.
Aggregate statistics across every inspected repository publishing to Packagist — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.
Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.
Combined monthly downloads by band, against repository counts.
67% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 27% of the entire volume.
| Band | Repositories | Downloads / mo | Volume share |
|---|---|---|---|
| Excellent | 15 | 98M | 2.5% |
| Good | 505 | 1.2B | 31% |
| Moderate | 1,740 | 1.6B | 42% |
| At risk | 775 | 822M | 21% |
| Critical | 126 | 153M | 3.9% |
The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.
Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.
Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.
Signals read by the unweighted AI Readiness category.
Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.
Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.
Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.
A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.
How recently each inspected repository last saw a push, at inspection time.
Half of the inspected repositories saw a push within 0 days of inspection.
| Last push | Repositories | Share |
|---|---|---|
| Pushed within 30 days | 2,708 | 86% |
| 31 – 90 days | 128 | 4.0% |
| 91 – 365 days | 255 | 8.1% |
| Over a year | 70 | 2.2% |
Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.
60% of inspected repositories depend on a single maintainer for the majority of their commits — including 284 with over a million monthly downloads.
Declared direct dependencies against the full resolved graph (direct plus transitive), across the 2,495 reports with a collected dependency graph.
The median repository declares 2 direct dependencies — and resolves to 13 packages in total.
The most common detected licenses across the scope (SPDX identifiers).
The most-downloaded repositories under inspection publishing to Packagist — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.