Methodology
Each project gets a 0–100 health score answering: "If I adopt this project today, how likely is it to be maintained, supported, and safe a year from now?"
Formula
score = 0.4 × maintenance
+ 0.35 × community
+ 0.25 × quality
Signals are min-max normalized within each category (popularity counts) or mapped through absolute curves (time decays, ratios, flags) before weighting. Scores are not comparable across categories.
Quality (weight 0.25)
| Signal | Weight within bucket |
|---|---|
| tests_present | 0.3 |
| readme_present | 0.2 |
| ci_configured | 0.3 |
| license_osi | 0.2 |
Maintenance (weight 0.4)
| Signal | Weight within bucket |
|---|---|
| release_cadence | 0.15 |
| open_closed_issue_ratio | 0.1 |
| median_issue_close_days | 0.15 |
| days_since_last_commit | 0.25 |
| median_pr_close_days | 0.15 |
| commit_frequency_90d | 0.2 |
Community (weight 0.35)
| Signal | Weight within bucket |
|---|---|
| stars_log | 0.3 |
| forks_log | 0.15 |
| author_track_record | 0.15 |
| contributors_12mo | 0.25 |
| bus_factor | 0.15 |
What this score is NOT
- Not a code-quality judgment.
- Not a security audit (see OpenSSF Scorecard for that).
- Not comparable across categories.
Bot activity (dependabot, renovate, *[bot]) is filtered from all
activity metrics. Archived repos are penalized, not zeroed; projects whose
maintainers still answer issues keep a non-zero maintenance floor.
Scorecards