Reference · methodology v1.13.0

The inspect.software wiki

The complete reference behind every published health report: what each category and metric measures, how the numbers are computed, and how the methodology is governed and versioned. Every figure in a report can be traced back to a formula documented here.

Repository metrics

Development activityHow inspect.software measures development activity — push recency, weekly commit cadence, and commit volume. 13.2% of the overall health index.Release disciplineHow inspect.software measures release discipline — whether versioned releases ship, how recently, and on what cadence. 8.8% of the overall health index.Growth AuthenticityHow inspect.software reads a repository's day-by-day star and fork history for growth that organic attention does not produce, and what the Inorganic Growth Policy does about it.PopularityHow inspect.software measures repository popularity — stars, forks, and watchers on a logarithmic scale. 7.2% of the overall health index.Community healthHow inspect.software measures community health — README, license, contributing guide, code of conduct, and issue/PR templates. 6.3% of the overall index.Ecosystem adoptionHow inspect.software measures real package adoption — registry downloads and dependents across npm, PyPI, Packagist, and more. 4.5% of the overall index.Maintainer resilienceHow inspect.software measures bus factor, contributor concentration, and breadth — whether a project can survive losing its top maintainer. 7.2% of the index.ResponsivenessHow inspect.software measures responsiveness — issue resolution and pull-request acceptance rates over a project's lifetime. 6% of the overall index.StewardshipHow inspect.software measures who stands behind a repository — organization vs. personal ownership, verified domain, reach, and track record. 6% of the index.Package maintenanceHow inspect.software measures registry upkeep — publish recency, version history, and deprecation state of published packages. 4.8% of the overall index.Engineering practicesHow inspect.software measures baseline engineering hygiene — CI, tests, linting, pre-commit hooks, and editorconfig. 12% of the overall health index.DocumentationHow inspect.software measures documentation — README, docs directory, documentation site, description, topics, and wiki. 8% of the overall health index.Security postureHow inspect.software measures security posture with the OpenSSF Scorecard — risk-weighted, tool-agnostic checks with a documented fallback. 16% of the index.AI agent contextHow inspect.software measures agent guidance — CLAUDE.md, AGENTS.md, Cursor rules, Copilot instructions, llms.txt, and whether the commit history states its intent. Part of the AI Readiness badge.Dependency advisoriesHow inspect.software matches a repository's resolved dependencies against the OSV advisory database — severity, fix versions, coverage, and the limits of the signal. 30% of the Security category.High-Risk Jurisdiction ExposureHow inspect.software turns public repository-profile evidence into an explainable high-risk jurisdiction exposure signal for repository review.AI verify loopHow inspect.software measures the agent verify loop — one-command bootstrap, tests, lint, type checking, reproducible environments. The heaviest AI Readiness metric.Malicious dependenciesHow inspect.software identifies dependencies reported as malicious packages by the OpenSSF corpus, why they are scored apart from vulnerabilities, and what the finding does and does not claim.AbandonmentHow inspect.software decides a project has been left unmaintained — why silence alone is never the finding, what counts as an unmet obligation, and what holds the assessment back.AI code legibilityHow inspect.software measures code legibility for AI models — type-checkable code and manageable file sizes. Part of the AI Readiness badge.AI interfacesHow inspect.software measures machine-readable interfaces — API schemas, MCP servers, and runnable examples. Part of the AI Readiness badge.