Record in aggregate · metrics 2.10.0

The state of the record.

Aggregate statistics across the public record — how software health distributes, where the download volume concentrates, and which engineering practices are common or rare. Figures describe the inspected record, not the entirety of open source.

Inspected repositories
63,188 of 65,360 indexed
Monthly downloads under inspection
545B registry-reported
Median health index
60 Moderate
Good or better
42% index 65 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

54% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 69% of the entire volume.

Repositories
17%20%25%16%
Download volume
16%18%18%16%
BandRepositoriesDownloads / moVolume share
Exceptional3,40779.3B15%
Excellent10,54088.4B16%
Good12,78782.5B15%
Moderate15,98899B18%
Weak10,38595.9B18%
At Risk7,62288.3B16%
Critical2,45911.5B2.1%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality70
1100
Community & Adoption45
1100
Sustainability & Governance59
1100
Engineering Quality65
1100
Security47
1100
AI Readiness52
1100

Category profile

Median category score across the scope. Categories are documented in the methodology wiki.

Vitality
70
Community & Adoption
45
Sustainability & Governance
59
Engineering Quality
65
Security
47
AI Readinessunweighted
52

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
94% of 63,188
License detected
91% of 63,188
Automated tests
85% of 63,188
CI workflows
81% of 63,188
Linter configuration
42% of 63,188
Documentation directory
39% of 63,188
Contributing guide
37% of 63,188
Code of conduct
23% of 63,188
Security policy
19% of 63,188

Agent-era signals

One-command bootstrap
29% of 63,188
AI agent instructions
24% of 63,188
llms.txt
4.5% of 63,188

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 42,654
54 · 39–67
100 – 999 12,069
71 · 54–84
1,000 – 9,999 6,766
83 · 63–91
10,000 and more 1,699
92 · 81–96

By monthly downloads

Under 10K / month 12,923
59 · 45–71
10K – 1M 10,111
67 · 53–81
1M – 100M 4,280
75 · 51–89
100M and more 1,225
53 · 36–80

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.1
Fuzzing
0.6
Signed-Releases
0.9
Branch-Protection
1.3
SAST
1.5
Pinned-Dependencies
1.7
Token-Permissions
1.8
Code-Review
2.1
Security-Policy
2.5
Dependency-Update-Tool
4.1
Maintained
5.4
Contributors
6.1
CI-Tests
6.4
Vulnerabilities
6.6
License
9.0
Dangerous-Workflow
9.7
Binary-Artifacts
9.8
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
4,0796.5% of the record · 6.5% of 63,190 assessed
High-risk jurisdiction exposure
1,0991.7% of the record · 2.0% of 56,193 assessed
Malicious dependencies
670.1% of the record · 0.3% of 24,430 assessed
Inorganic growth
25<0.1% of the record · 1.4% of 1,762 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 3 days of inspection.

Push recency
79%
Last pushRepositoriesShare
Pushed within 30 days49,73279%
31 – 90 days3,7746.0%
91 – 365 days4,1336.5%
Over a year5,5498.8%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

37,005Organization-stewarded median 65
26,183Personal accounts median 53

Maintainer bus factor

74% of inspected repositories depend on a single maintainer for the majority of their commits — including 3,712 with over a million monthly downloads.

1 maintainer
46,684
2 maintainers
9,817
3–5 maintainers
5,246
6+ maintainers
937

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 45,530 reports with a collected dependency graph.

The median repository declares 3 direct dependencies — and resolves to 26 packages in total.

Resolved packages per repository

0
4,858
1 – 5
6,158
6 – 20
10,240
21 – 50
5,277
51 – 200
6,940
201 – 500
4,344
501 – 1,000
3,594
Over 1,000
4,119

License landscape

The most common detected licenses across the scope (SPDX identifiers).

MIT
29,393
Apache-2.0
13,043
Custom license
6,844
No license detected
5,858
BSD-3-Clause
1,959
GPL-3.0
1,638
AGPL-3.0
1,091
MPL-2.0
652
GPL-2.0
579
BSD-2-Clause
525

Ecosystems compared

Each ecosystem's slice of the record. A repository publishing to several ecosystems counts in each. Every row opens that ecosystem's full statistics.

EcosystemInspectedMedian healthBand mixGood or betterDownloads / mo
npm19,067 65 Good52%470B
Go17,870 56 Moderate33%1.3B
PyPI9,700 69 Good56%53.4B
Packagist7,121 57 Moderate34%5.2B
crates.io5,614 65 Good53%29.4B
RubyGems3,079 62 Moderate46%1.4B
Maven2,104 73 Good60%986M
NuGet1,931 60 Moderate44%6M
Hex1,257 51 Moderate22%286M

Most relied upon

The most-downloaded repositories under inspection — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

npm
99Exceptionalhealth index
typescript-eslint/typescript-eslint
:sparkles: Monorepo for all the tooling which enables ESLint to support TypeScript
TypeScript★ 16.4K↓ 3.8B/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm
90Excellenthealth index
npm/node-semver
The semver parser for node (the one npm uses)
JavaScript★ 5,459↓ 3.5B/moAug 29, 2026
ISCAug 29, 2026 · metrics 2.10.0
npm
53Moderatehealth index
jridgewell/sourcemaps
Monorepo for various sourcemap libraries
TypeScript · JavaScript★ 52↓ 3.3B/moAug 29, 2026
No licenseAug 29, 2026 · metrics 2.10.0
npm
98Exceptionalhealth index
babel/babel
🐠 Babel is a compiler for writing next generation JavaScript.
TypeScript · JavaScript★ 44K↓ 3.3B/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm
94Exceptionalhealth index
eslint/js
Monorepo for the JS language tools.
JavaScript★ 2,387↓ 3.1B/moAug 29, 2026
BSD-2-ClauseAug 29, 2026 · metrics 2.10.0
npm
77Goodhealth index
isaacs/minimatch
a glob matcher in javascript
JavaScript · TypeScript★ 3,518↓ 2.9B/moAug 29, 2026
BlueOak-1.0.0Aug 29, 2026 · metrics 2.10.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 2.10.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-09-01 14:25 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.