Concepts

Rating bands

The seven standardized rating bands — exceptional, excellent, good, moderate, weak, at risk, critical — and the letter grades used across every inspect.software health metric and category.

Methodology v2.10.0Updated 2026-08-02

Every value in an inspect.software report — components rolled into metrics, metrics rolled into categories, and the overall health index — lives on one standardized 1–100 scale, higher is better. To make those numbers readable at a glance, each value maps to one of seven standardized bands, used consistently across health, security, and quality measurements. Each band also carries a compact letter grade (C to AAA) for surfaces where a word does not fit.

Critical 1–19 At Risk 20–34 Weak 35–49 Moderate 50–64 Good 65–79 Excellent 80–92 Exceptional 93–100
The seven bands of the standardized scale. Thresholds are part of the versioned methodology.

What each band means

BandGradeRangeMeaning
ExceptionalAAA93–100The record's top tier (≈ top 5%); essentially all checked criteria met
ExcellentAA80–92Strong across the board; minor gaps
GoodA65–79Healthy; gaps are limited and manageable
ModerateBBB50–64Acceptable with notable gaps; review recommended
WeakBB35–49Material weaknesses across several areas
At RiskB20–34Significant weaknesses; adoption warrants caution
CriticalC1–19Severe problems — e.g. abandoned, single-maintainer, no hygiene

Calibrated to the public record

Band floors for the overall health index are not arbitrary round numbers: the index is calibrated against the empirical distribution of the public record (47,516 inspected repositories at the calibration snapshot), so each band states where a repository stands within inspected open source. On the uncalibrated weighted mean, half the record crowded into a 20-point stretch of the scale and the top decile of open source sat in the high 70s — numbers that used the 1–100 range badly and made every band boundary misleading. After calibration the bands split the record into meaningful, comparably sized populations, and Exceptional means what a reader assumes it means: roughly the top 5% of inspected open source.

The calibration curve is a fixed constant of the versioned methodology, not a live percentile — a repository's score moves only when its own evidence moves, never because other repositories were inspected. Recalibration against a newer snapshot is a methodology version bump like any other, recorded in every report.

Certain red-flag policies bound the index regardless of the weighted result: an unresolved High-Risk Jurisdiction exposure holds the index at the top of At Risk (34), and a confirmed malicious dependency or a declared-dead project holds it inside Critical (19).

How bands should be read

  • Bands are coarse on purpose. The difference between 71 and 74 is noise; the difference between good and at risk is information. Procurement and review decisions should key on bands and on the category profile, not on single-point differences. The comparison view is built around this: it states the spread between the records on screen in index points, so a three-point gap can be recognized as one and set aside.
  • Bands apply at every level. A repository can sit in the good band overall while one category sits in critical — the per-category bands exist precisely so that strength in one area cannot silently mask risk in another. (Calibration applies to the overall index; category and metric values map to the same thresholds directly.)
  • Thresholds are versioned. Band boundaries are part of the methodology and only change with a version bump recorded in every report — see methodology versions.

Certification levels

The three bands above Moderate carry the record's certification levels: Certified (Good, grade A), Certified with Excellence (Excellent, grade AA), and Certified AAA (Exceptional). A level is the band the published evidence supports, stated as a certification mark — see how levels are earned and change, and certification & pricing for the paid on-demand path.

Where the bands appear

The bands drive the color coding across the whole record: catalogue cards, the report gauge, category headers, individual metric cards, and the GitHub badge. A repository with no completed inspection yet shows a neutral pending state rather than a band.

Related: the health index explains how the underlying 1–100 values are computed; signals, not warranties explains what they do and do not claim.