How the health score works
Every project gets two separate verdicts. The health score answers "will it still be around and maintained?" The license verdict answers "can a business use it freely?" We never average them, so a well-maintained project with a restrictive license can't pass as healthy open source. Health score version v2, recomputed from GitHub data each time it's refreshed (last refreshed on 9 October 2026).
Health score
| Part | Weight | What it measures |
|---|---|---|
| Activity | 45% | Days since the last commit (full marks within 30 days, zero at a year), commits in the past 12 months (log scale, 200+ is full marks) and releases in the past 12 months (6+ is full marks). Projects that never publish GitHub releases aren't penalized for it. |
| Bus factor | 30% | How much of the last 100 commits (past 12 months, bots excluded) came from a single person. 25% or less is full marks, falling to zero when one person writes everything. |
| Responsiveness | 25% | The share of all issues that are closed (90%+ is full marks), and how many of the 30 most recent issues opened 7 to 365 days ago got a reply from someone other than the author or were closed. Not scored when issues are disabled. |
Grades
80 and up is Healthy, 60 to 79 Stable, 40 to 59 Caution, and below 40 At risk. An archived repository scores 0.
License verdict
We read the license, not just GitHub's label. GitHub reports custom and mixed licenses as "Other"; we check those by hand and record the source and the date we checked.
Every project shows a tag first that says what using it asks of your business, then the license itself.
| Tag | What you need to do |
|---|---|
| Free to use | Use, change, host and sell it for any purpose, commercial included, with no license to buy. Keep the copyright notice. |
| Free, share changes | Free for any use, commercial included. Running it in your company, changed or not, asks nothing of you; only if you hand modified copies to others must you publish your changes under the same license. |
| Free, share hosted changes | Free for any use, commercial included. If you change the code and people outside your company use it over the network, you must publish your changes under the same license. |
| Free core, paid extras | The core is free to use. Enterprise features, kept in a separately licensed part of the code, need a paid license in production. |
| Free, no reselling | Free to self-host and use in your business, changes included. You may not sell it or offer it to others as a hosted service that competes with the vendor. |
| Internal use only | Free for use inside your own company. Hosting it for customers, selling it or building it into a product you sell needs a commercial license. |
| Free with conditions | Free to use, but the license adds conditions open source licenses don’t have. Read the notes before you rely on it. |
| Free up to a limit | Free only below usage limits set in the license. Past them, production use needs a paid license. |
| Check the license | We haven’t read this license yet. Treat it as not open source until you have checked it. |
Separately, we say whether the license is open source at all:
| License type | What it means |
|---|---|
| Open source (permissive) | OSI-approved license with few conditions beyond keeping the copyright notice. |
| Open source (copyleft) | OSI-approved license that requires sharing changes under the same license when you distribute (AGPL: also when you offer it over a network). |
| Source-available, not open source | The code is public, but the license restricts how you can use it, usually by banning competing hosted services or capping production use. Not open source. |
| Custom license, not open source | A license written by the vendor, often an open source license with extra conditions added. Not OSI-approved; read the terms before relying on it. |
| License not verified | GitHub could not identify an OSI license (it reports "Other"), usually a custom or mixed license. Treat it as not open source until verified. |
When a project has moved to a stricter license (for example from AGPL to a source-available license), we show "Relicensed" with the year and link to the change.
What we don't claim
We only call a project open source when its license is OSI-approved. The score is a signal, not an audit: read the license and check the project yourself before you depend on it.