OpenSoft

How the health score works

Every project gets two separate verdicts. The health score answers "will it still be around and maintained?" The license verdict answers "can a business use it freely?" We never average them, so a well-maintained project with a restrictive license can't pass as healthy open source. Health score version v2, recomputed every night from GitHub data.

Health score

PartWeightWhat it measures
Activity45%Days since the last commit (full marks within 30 days, zero at a year), commits in the past 12 months (log scale, 200+ is full marks) and releases in the past 12 months (6+ is full marks). Projects that never publish GitHub releases aren't penalized for it.
Bus factor30%How much of the last 100 commits (past 12 months, bots excluded) came from a single person. 25% or less is full marks, falling to zero when one person writes everything.
Responsiveness25%The share of all issues that are closed (90%+ is full marks), and how many of the 30 most recent issues opened 7 to 365 days ago got a reply from someone other than the author or were closed. Not scored when issues are disabled.

Grades

80 and up is Healthy, 60 to 79 Stable, 40 to 59 Caution, and below 40 At risk. An archived repository scores 0.

License verdict

We read the license, not just GitHub's label. GitHub reports custom and mixed licenses as "Other"; we check those by hand and record the source and the date we checked.

VerdictWhat it means for a business
Open source (permissive)OSI-approved license with few conditions beyond keeping the copyright notice.
Open source (copyleft)OSI-approved license that requires sharing changes under the same license when you distribute (AGPL: also when you offer it over a network).
Source-available, not open sourceThe code is public, but the license restricts how you can use it, usually by banning competing hosted services or capping production use. Not open source.
Custom license, not open sourceA license written by the vendor, often an open source license with extra conditions added. Not OSI-approved; read the terms before relying on it.
License not verifiedGitHub could not identify an OSI license (it reports "Other"), usually a custom or mixed license. Treat it as not open source until verified.

When a project has moved to a stricter license (for example from AGPL to a source-available license), we show "Relicensed" with the year and link to the change.

What we don't claim

We only call a project open source when its license is OSI-approved. The score is a signal, not an audit: read the license and check the project yourself before you depend on it.