Skip to content
OpenLib
Indexing 1,247,392 packages · updated 12s

Open-source · Cross-ecosystem · Continuously indexed

The open library for 1.2M+ modern developers.

A curated, continuously indexed catalog of open-source packages, APIs, and docs — ranked by real production usage, license fitness, and maintainer reputation, so engineers stop guessing which dependency to trust.

  • Average query: 180ms
  • 380K+ developers
  • SOC 2 Type I
openlib.net/search
All ecosystems npm PyPI Maven crates.io Go
  • 01
    undicinpmMIT
    96
  • 02
    httpxPyPIBSD-3
    93
  • 03
    okhttpMavenApache-2.0
    91
  • 04
    reqwestcrates.ioMIT/Apache-2.0
    88
  • 05
    net/httpGo modulesBSD-3
    84
Showing 5 of 1,247,392 packages Avg. response: 180ms

Method · 0–100 score

How we score every package on a 0–100 Production Readiness Index.

Stars lie. We weight four signals that predict whether a dependency will actually survive contact with production traffic. No vibes, no sponsorships — just reproducible math, open methodology, and a downloadable audit trail.

Read the full methodology →
01

Download velocity

Weekly install counts across npm, PyPI, Maven, crates.io, Go modules, and RubyGems, normalized by ecosystem size and de-duplicated against CI mirror traffic.

Signal weight · 30%
02

Issue half-life

Median time from a bug report being filed to a merged fix on main. We track this per repo, per label, and per severity tier — not just "open vs closed".

Signal weight · 25%
03

Bus-factor

Distribution of commits across maintainers over the last 24 months. A project where 80% of the work comes from one GitHub handle scores lower than one with a healthy core team.

Signal weight · 20%
04

CVE history

Lifetime count of advisories weighted by severity, time-to-patch, and whether fixes shipped in a minor or major bump. Refreshed every 15 minutes from upstream feeds.

Signal weight · 25%

This week · 2026-W18

Top of the index this week.

Five packages engineers are pulling into production right now — ranked by PRI, refreshed every 15 minutes from real usage across the catalog.

See full leaderboard →
  1. 01
    zod npm MIT ▲ 2
    TypeScript-first schema validation · 38.4M weekly downloads · 412 contributors
    98
  2. 02
    pydantic PyPI MIT
    Data validation using Python type hints · 29.1M weekly downloads · 612 contributors
    96
  3. 03
    tokio crates.io MIT ▲ 1
    Async runtime for Rust · 24.7M weekly downloads · 318 contributors
    94
  4. 04
    spring-boot Maven Apache-2.0 ▼ 3
    Production-grade Java framework · 18.2M weekly downloads · 904 contributors
    92
  5. 05
    rails RubyGems MIT ▲ 4
    Full-stack web framework · 9.8M weekly downloads · 1,247 contributors
    91

Ecosystems · Integrations

One index across every major package ecosystem.

Plus the surfaces that already ship it — IDE plugin stores, landscape feeds, and the public API you can hit from CI.

Powers the dependency-discovery layer behind

  • JetBrains Marketplace
  • CNCF Landscape · Emerging Projects feed
  • GitHub Octoverse partner directory
  • Stack Overflow Blog · 2024 resource list

By the numbers

Used daily by 380,000+ developers at companies you already trust.

From two-person startups to Fortune 500 platform teams — engineers rely on OpenLib to evaluate dependencies before they ship. Six years of independent, ad-light operation.

1.2M+ Packages indexed across 6 ecosystems
380K+ Registered developers worldwide
41K Paying Pro accounts as of Jan 2026
9.4M Public API requests served per day
180ms Average query latency, full index
99.97% API uptime, trailing 12 months

Trusted by engineering teams at

  • Stripe
  • Vercel
  • Datadog
  • Cloudflare
  • Shopify
Award Best Developer Experience Tool DevToolsDay 2024 · Amsterdam
Listed GitHub Octoverse 2024 Top-3 dependency-discovery resource
Backed $14M Series A Index Ventures · March 2022

Founder note

"We watched senior engineers spend half a Sprint evaluating dependencies that turned out to be unmaintained, copyleft-encumbered, or one GitHub handle away from disappearing. That is not a research problem — it's a trust problem. OpenLib exists because the cost of guessing wrong on a dependency is paid in production, on your users, at 3am."

Lena Voss & Marco Reis Co-founders · ex-GitHub & ex-Snyk engineers · Berlin, 2019