How the health score works
Every project gets two separate verdicts. The health score answers "will it still be around and maintained?" The license verdict answers "can a business use it freely?" We never average them, so a well-maintained project with a restrictive license can't pass as healthy open source. Health score version v2, recomputed every night from GitHub data.
Health score
| Part | Weight | What it measures |
|---|---|---|
| Activity | 45% | Days since the last commit (full marks within 30 days, zero at a year), commits in the past 12 months (log scale, 200+ is full marks) and releases in the past 12 months (6+ is full marks). Projects that never publish GitHub releases aren't penalized for it. |
| Bus factor | 30% | How much of the last 100 commits (past 12 months, bots excluded) came from a single person. 25% or less is full marks, falling to zero when one person writes everything. |
| Responsiveness | 25% | The share of all issues that are closed (90%+ is full marks), and how many of the 30 most recent issues opened 7 to 365 days ago got a reply from someone other than the author or were closed. Not scored when issues are disabled. |
Grades
80 and up is Healthy, 60 to 79 Stable, 40 to 59 Caution, and below 40 At risk. An archived repository scores 0.
License verdict
We read the license, not just GitHub's label. GitHub reports custom and mixed licenses as "Other"; we check those by hand and record the source and the date we checked.
| Verdict | What it means for a business |
|---|---|
| Open source (permissive) | OSI-approved license with few conditions beyond keeping the copyright notice. |
| Open source (copyleft) | OSI-approved license that requires sharing changes under the same license when you distribute (AGPL: also when you offer it over a network). |
| Source-available, not open source | The code is public, but the license restricts how you can use it, usually by banning competing hosted services or capping production use. Not open source. |
| Custom license, not open source | A license written by the vendor, often an open source license with extra conditions added. Not OSI-approved; read the terms before relying on it. |
| License not verified | GitHub could not identify an OSI license (it reports "Other"), usually a custom or mixed license. Treat it as not open source until verified. |
When a project has moved to a stricter license (for example from AGPL to a source-available license), we show "Relicensed" with the year and link to the change.
What we don't claim
We only call a project open source when its license is OSI-approved. The score is a signal, not an audit: read the license and check the project yourself before you depend on it.