A public record of open-source software health.
Every repository in the record is measured against the same transparent, versioned methodology — maintainability, engineering quality, security posture, ecosystem adoption, and governance. The method is published, the weights are published, and no repository can pay for a better result.
inspect.software · over 60,000 repositories inspected across nine package ecosystems — npm, PyPI, Packagist, crates.io, RubyGems, Hex, NuGet, the Go module proxy, and Maven Central.
- Transparency is the product. Every metric, weight, formula, and threshold is published in the methodology and the wiki. Every report echoes its inputs so any value can be recomputed by hand.
- Results are independent of payment. Payment buys analysis, privacy, and frequency — never a better number.
- Signals, not warranties. The record states exactly what it measures and no more.
- Versioned and accountable. Methodology changes are dated, explained, and recorded in every report.
- Public good first. Inspection of high public-value open-source software is free and its results are public, permanently.
Every repository in the record carries an embeddable badge — a live health signal served from the public badges repository through GitHub's own content network, updated automatically after every scan:
[](https://inspect.software/software/OWNER/REPO)Each report page provides copy-ready snippets, including a shields.io endpoint variant.
- The public record — every inspected repository with its full report and machine-readable data
- Methodology — metrics, weights, and formulas
- Scoring bands and certification levels
- Certification & pricing — the paid services that fund free public-interest coverage
- Contact — questions, corrections, and data-error reports