OpenSoft

How the health score works

Every project gets two separate verdicts. The health score answers "will it still be around and maintained?" The license verdict answers "can a business use it freely?" We never average them, so a well-maintained project with a restrictive license can't pass as healthy open source. Health score version v2, recomputed from GitHub data each time it's refreshed (last refreshed on 9 October 2026).

Health score

PartWeightWhat it measures
Activity45%Days since the last commit (full marks within 30 days, zero at a year), commits in the past 12 months (log scale, 200+ is full marks) and releases in the past 12 months (6+ is full marks). Projects that never publish GitHub releases aren't penalized for it.
Bus factor30%How much of the last 100 commits (past 12 months, bots excluded) came from a single person. 25% or less is full marks, falling to zero when one person writes everything.
Responsiveness25%The share of all issues that are closed (90%+ is full marks), and how many of the 30 most recent issues opened 7 to 365 days ago got a reply from someone other than the author or were closed. Not scored when issues are disabled.

Grades

80 and up is Healthy, 60 to 79 Stable, 40 to 59 Caution, and below 40 At risk. An archived repository scores 0.

License verdict

We read the license, not just GitHub's label. GitHub reports custom and mixed licenses as "Other"; we check those by hand and record the source and the date we checked.

Every project shows a tag first that says what using it asks of your business, then the license itself.

TagWhat you need to do
Free to useUse, change, host and sell it for any purpose, commercial included, with no license to buy. Keep the copyright notice.
Free, share changesFree for any use, commercial included. Running it in your company, changed or not, asks nothing of you; only if you hand modified copies to others must you publish your changes under the same license.
Free, share hosted changesFree for any use, commercial included. If you change the code and people outside your company use it over the network, you must publish your changes under the same license.
Free core, paid extrasThe core is free to use. Enterprise features, kept in a separately licensed part of the code, need a paid license in production.
Free, no resellingFree to self-host and use in your business, changes included. You may not sell it or offer it to others as a hosted service that competes with the vendor.
Internal use onlyFree for use inside your own company. Hosting it for customers, selling it or building it into a product you sell needs a commercial license.
Free with conditionsFree to use, but the license adds conditions open source licenses don’t have. Read the notes before you rely on it.
Free up to a limitFree only below usage limits set in the license. Past them, production use needs a paid license.
Check the licenseWe haven’t read this license yet. Treat it as not open source until you have checked it.

Separately, we say whether the license is open source at all:

License typeWhat it means
Open source (permissive)OSI-approved license with few conditions beyond keeping the copyright notice.
Open source (copyleft)OSI-approved license that requires sharing changes under the same license when you distribute (AGPL: also when you offer it over a network).
Source-available, not open sourceThe code is public, but the license restricts how you can use it, usually by banning competing hosted services or capping production use. Not open source.
Custom license, not open sourceA license written by the vendor, often an open source license with extra conditions added. Not OSI-approved; read the terms before relying on it.
License not verifiedGitHub could not identify an OSI license (it reports "Other"), usually a custom or mixed license. Treat it as not open source until verified.

When a project has moved to a stricter license (for example from AGPL to a source-available license), we show "Relicensed" with the year and link to the change.

What we don't claim

We only call a project open source when its license is OSI-approved. The score is a signal, not an audit: read the license and check the project yourself before you depend on it.