Every value in an inspect.software report — components rolled into metrics, metrics rolled into categories, and the overall health index — lives on one standardized 1–100 scale, higher is better. To make those numbers readable at a glance, each value maps to one of seven standardized bands, used consistently across health, security, and quality measurements. Each band also carries a compact letter grade (C to AAA) for surfaces where a word does not fit.
What each band means
| Band | Grade | Range | Meaning |
|---|---|---|---|
| Exceptional | AAA | 93–100 | The record's top tier (≈ top 5%); essentially all checked criteria met |
| Excellent | AA | 80–92 | Strong across the board; minor gaps |
| Good | A | 65–79 | Healthy; gaps are limited and manageable |
| Moderate | BBB | 50–64 | Acceptable with notable gaps; review recommended |
| Weak | BB | 35–49 | Material weaknesses across several areas |
| At Risk | B | 20–34 | Significant weaknesses; adoption warrants caution |
| Critical | C | 1–19 | Severe problems — e.g. abandoned, single-maintainer, no hygiene |
Calibrated to the public record
Band floors for the overall health index are not arbitrary round numbers: the index is calibrated against the empirical distribution of the public record (47,516 inspected repositories at the calibration snapshot), so each band states where a repository stands within inspected open source. On the uncalibrated weighted mean, half the record crowded into a 20-point stretch of the scale and the top decile of open source sat in the high 70s — numbers that used the 1–100 range badly and made every band boundary misleading. After calibration the bands split the record into meaningful, comparably sized populations, and Exceptional means what a reader assumes it means: roughly the top 5% of inspected open source.
The calibration curve is a fixed constant of the versioned methodology, not a live percentile — a repository's score moves only when its own evidence moves, never because other repositories were inspected. Recalibration against a newer snapshot is a methodology version bump like any other, recorded in every report.
Certain red-flag policies bound the index regardless of the weighted result: an unresolved High-Risk Jurisdiction exposure holds the index at the top of At Risk (34), and a confirmed malicious dependency or a declared-dead project holds it inside Critical (19).
How bands should be read
- Bands are coarse on purpose. The difference between 71 and 74 is noise; the difference between good and at risk is information. Procurement and review decisions should key on bands and on the category profile, not on single-point differences. The comparison view is built around this: it states the spread between the records on screen in index points, so a three-point gap can be recognized as one and set aside.
- Bands apply at every level. A repository can sit in the good band overall while one category sits in critical — the per-category bands exist precisely so that strength in one area cannot silently mask risk in another. (Calibration applies to the overall index; category and metric values map to the same thresholds directly.)
- Thresholds are versioned. Band boundaries are part of the methodology and only change with a version bump recorded in every report — see methodology versions.
Certification levels
The three bands above Moderate carry the record's certification levels: Certified (Good, grade A), Certified with Excellence (Excellent, grade AA), and Certified AAA (Exceptional). A level is the band the published evidence supports, stated as a certification mark — see how levels are earned and change, and certification & pricing for the paid on-demand path.
Where the bands appear
The bands drive the color coding across the whole record: catalogue cards, the report gauge, category headers, individual metric cards, and the GitHub badge. A repository with no completed inspection yet shows a neutral pending state rather than a band.
Related: the health index explains how the underlying 1–100 values are computed; signals, not warranties explains what they do and do not claim.