Record in aggregate · metrics 2.10.0

The state of Packagist.

Aggregate statistics across every inspected repository publishing to Packagist — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.

Inspected repositories
7,390 of 7,390 indexed
Monthly downloads under inspection
5.2B registry-reported
Median health index
57 Moderate
Good or better
33% index 65 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

36% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 37% of the entire volume.

Repositories
19%36%21%
Download volume
31%24%16%
BandRepositoriesDownloads / moVolume share
Exceptional128489M9.5%
Excellent8951.6B31%
Good1,4391.2B24%
Moderate2,639836M16%
Weak1,524579M11%
At Risk651391M7.6%
Critical11440.9M0.8%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality64
1100
Community & Adoption47
1100
Sustainability & Governance64
1100
Engineering Quality62
1100
Security42
1100
AI Readiness34
1100

Category profile

Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.

Vitality
64
Community & Adoption
47
Sustainability & Governance
64
Engineering Quality
62
Security
42
AI Readinessunweighted
34

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
96% of 7,390
License detected
91% of 7,390
Automated tests
81% of 7,390
CI workflows
78% of 7,390
Contributing guide
50% of 7,390
Linter configuration
48% of 7,390
Documentation directory
23% of 7,390
Code of conduct
22% of 7,390
Security policy
17% of 7,390

Agent-era signals

One-command bootstrap
10% of 7,390
llms.txt
9.7% of 7,390
AI agent instructions
8.9% of 7,390

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 5,338
54 · 45–63
100 – 999 1,354
65 · 54–78
1,000 – 9,999 625
77 · 60–88
10,000 and more 73
88 · 78–94

By monthly downloads

Under 10K / month 2,943
53 · 44–63
10K – 1M 3,623
59 · 48–71
1M – 100M 649
71 · 51–84
100M and more 3
80 · 77–87

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.0
Fuzzing
0.0
SAST
0.5
Pinned-Dependencies
0.9
Signed-Releases
1.1
Branch-Protection
1.4
Token-Permissions
1.4
Code-Review
1.9
Security-Policy
2.4
Dependency-Update-Tool
3.3
Maintained
4.0
CI-Tests
5.2
Contributors
7.6
License
8.9
Vulnerabilities
9.2
Dangerous-Workflow
9.8
Binary-Artifacts
10.0
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
3624.9% of the record · 4.9% of 7,390 assessed
High-risk jurisdiction exposure
2473.3% of the record · 3.4% of 7,174 assessed
Malicious dependencies
4<0.1% of the record · 0.3% of 1,579 assessed
Inorganic growth
00% of the record · 0% of 166 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 0 days of inspection.

Push recency
80%
Last pushRepositoriesShare
Pushed within 30 days5,91080%
31 – 90 days5337.2%
91 – 365 days7049.5%
Over a year2433.3%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

5,872Organization-stewarded median 57
1,518Personal accounts median 57

Maintainer bus factor

61% of inspected repositories depend on a single maintainer for the majority of their commits — including 395 with over a million monthly downloads.

1 maintainer
4,504
2 maintainers
1,800
3–5 maintainers
945
6+ maintainers
121

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 6,391 reports with a collected dependency graph.

The median repository declares 2 direct dependencies — and resolves to 11 packages in total.

Resolved packages per repository

0
105
1 – 5
1,386
6 – 20
2,923
21 – 50
768
51 – 200
726
201 – 500
193
501 – 1,000
144
Over 1,000
146

License landscape

The most common detected licenses across the scope (SPDX identifiers).

MIT
3,704
Custom license
1,450
No license detected
680
BSD-3-Clause
461
GPL-2.0
293
Apache-2.0
289
GPL-3.0
173
AFL-3.0
65
LGPL-3.0
62
OSL-3.0
55

Most relied upon

The most-downloaded repositories under inspection publishing to Packagist — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

npm · RubyGems · Packagist
87Excellenthealth index
handlebars-lang/handlebars.js
Minimal templating on steroids.
JavaScript★ 18.7K↓ 168M/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
npm · Packagist
77Goodhealth index
moment/moment
Parse, validate, manipulate, and display dates in javascript.
JavaScript★ 47.9K↓ 140M/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
npm · Packagist
80Excellenthealth index
PrismJS/prism
Lightweight, robust, elegant syntax highlighting.
JavaScript★ 13K↓ 109M/moAug 12, 2026
MITAug 12, 2026 · metrics 2.10.0
npm · Packagist
78Goodhealth index
moment/moment-timezone
Timezone support for moment.js
JavaScript★ 3,876↓ 71.8M/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
npm · Packagist
84Excellenthealth index
chartjs/Chart.js
Simple HTML5 Charts using the <canvas> tag
JavaScript · TypeScript★ 67.6K↓ 53.4M/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
npm · Packagist
98Exceptionalhealth index
swagger-api/swagger-ui
Swagger UI is a collection of HTML, JavaScript, and CSS assets that dynamically generate beautiful documentation from a Swagger-compliant API.
JavaScript★ 29K↓ 50.3M/moAug 5, 2026
Apache-2.0Aug 5, 2026 · metrics 2.10.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 2.10.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-09-06 06:32 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.