Record in aggregate · metrics 2.10.0

The state of PyPI.

Aggregate statistics across every inspected repository publishing to PyPI — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.

Inspected repositories
9,854 of 9,854 indexed
Monthly downloads under inspection
53.5B registry-reported
Median health index
69 Good
Good or better
57% index 65 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

15% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 71% of the entire volume.

Repositories
24%21%21%
Download volume
47%24%
BandRepositoriesDownloads / moVolume share
Exceptional1,13325.4B47%
Excellent2,40712.6B24%
Good2,0347.6B14%
Moderate2,0373.3B6.2%
Weak9641B1.9%
At Risk9183.2B6.0%
Critical361422M0.8%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality74
1100
Community & Adoption56
1100
Sustainability & Governance63
1100
Engineering Quality76
1100
Security51
1100
AI Readiness55
1100

Category profile

Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.

Vitality
74
Community & Adoption
56
Sustainability & Governance
63
Engineering Quality
76
Security
51
AI Readinessunweighted
55

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

License detected
96% of 9,854
README
95% of 9,854
Automated tests
94% of 9,854
CI workflows
89% of 9,854
Documentation directory
67% of 9,854
Linter configuration
59% of 9,854
Contributing guide
46% of 9,854
Code of conduct
26% of 9,854
Security policy
23% of 9,854

Agent-era signals

One-command bootstrap
51% of 9,854
AI agent instructions
27% of 9,854
llms.txt
6.8% of 9,854

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 4,991
60 · 45–75
100 – 999 2,454
77 · 57–88
1,000 – 9,999 1,899
86 · 65–93
10,000 and more 510
94 · 86–97

By monthly downloads

Under 10K / month 2,189
63 · 53–78
10K – 1M 1,560
77 · 62–89
1M – 100M 1,211
78 · 53–92
100M and more 91
94 · 78–97

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.1
Fuzzing
0.5
Signed-Releases
0.9
Branch-Protection
1.4
Pinned-Dependencies
1.6
SAST
1.7
Token-Permissions
1.9
Code-Review
2.6
Security-Policy
2.8
Dependency-Update-Tool
4.5
Maintained
5.8
Vulnerabilities
6.5
CI-Tests
6.8
Contributors
6.9
License
9.5
Binary-Artifacts
9.7
Dangerous-Workflow
9.7
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
8488.6% of the record · 8.6% of 9,854 assessed
High-risk jurisdiction exposure
1451.5% of the record · 1.6% of 8,993 assessed
Malicious dependencies
4<0.1% of the record · <0.1% of 5,352 assessed
Inorganic growth
1<0.1% of the record · 0.2% of 506 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 3 days of inspection.

Push recency
73%
Last pushRepositoriesShare
Pushed within 30 days7,23873%
31 – 90 days6606.7%
91 – 365 days8638.8%
Over a year1,09311%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

5,829Organization-stewarded median 78
4,025Personal accounts median 59

Maintainer bus factor

70% of inspected repositories depend on a single maintainer for the majority of their commits — including 793 with over a million monthly downloads.

1 maintainer
6,876
2 maintainers
1,667
3–5 maintainers
1,022
6+ maintainers
256

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 7,649 reports with a collected dependency graph.

The median repository declares 2 direct dependencies — and resolves to 26 packages in total.

Resolved packages per repository

0
589
1 – 5
1,305
6 – 20
1,646
21 – 50
1,092
51 – 200
1,433
201 – 500
710
501 – 1,000
391
Over 1,000
483

License landscape

The most common detected licenses across the scope (SPDX identifiers).

MIT
3,936
Apache-2.0
2,337
Custom license
1,302
BSD-3-Clause
679
GPL-3.0
409
No license detected
386
AGPL-3.0
234
BSD-2-Clause
145
LGPL-3.0
99
MPL-2.0
88

Most relied upon

The most-downloaded repositories under inspection publishing to PyPI — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

PyPI
98Exceptionalhealth index
pypa/packaging
Core utilities for Python packages
Python★ 746↓ 2.1B/moAug 4, 2026
Custom licenseAug 4, 2026 · metrics 2.10.0
PyPI
98Exceptionalhealth index
urllib3/urllib3
urllib3 is a user-friendly HTTP client library for Python
Python★ 4,052↓ 1.9B/moAug 28, 2026
MITAug 28, 2026 · metrics 2.10.0
PyPI
83Excellenthealth index
kjd/idna
Internationalized Domain Names for Python (IDNA 2008 and UTS #46)
Python★ 288↓ 1.7B/moAug 4, 2026
BSD-3-ClauseAug 4, 2026 · metrics 2.10.0
PyPI
98Exceptionalhealth index
psf/requests
A simple, yet elegant, HTTP library.
Python★ 54.2K↓ 1.7B/moAug 4, 2026
Apache-2.0Aug 4, 2026 · metrics 2.10.0
PyPI
100Exceptionalhealth index
numpy/numpy
The fundamental package for scientific computing with Python.
Python · C★ 32.5K↓ 1.1B/moAug 4, 2026
Custom licenseAug 4, 2026 · metrics 2.10.0
PyPI
98Exceptionalhealth index
pytest-dev/pytest
The pytest framework makes it easy to write small tests, yet scales to support complex functional testing
Python★ 14.5K↓ 1.1B/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 2.10.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-09-08 07:53 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.