Download velocity
Weekly install counts across npm, PyPI, Maven, crates.io, Go modules, and RubyGems, normalized by ecosystem size and de-duplicated against CI mirror traffic.
Signal weight · 30%Open-source · Cross-ecosystem · Continuously indexed
A curated, continuously indexed catalog of open-source packages, APIs, and docs — ranked by real production usage, license fitness, and maintainer reputation, so engineers stop guessing which dependency to trust.
Method · 0–100 score
Stars lie. We weight four signals that predict whether a dependency will actually survive contact with production traffic. No vibes, no sponsorships — just reproducible math, open methodology, and a downloadable audit trail.
Read the full methodology →Weekly install counts across npm, PyPI, Maven, crates.io, Go modules, and RubyGems, normalized by ecosystem size and de-duplicated against CI mirror traffic.
Signal weight · 30%Median time from a bug report being filed to a merged fix on main. We track this per repo, per label, and per severity tier — not just "open vs closed".
Signal weight · 25%Distribution of commits across maintainers over the last 24 months. A project where 80% of the work comes from one GitHub handle scores lower than one with a healthy core team.
Signal weight · 20%Lifetime count of advisories weighted by severity, time-to-patch, and whether fixes shipped in a minor or major bump. Refreshed every 15 minutes from upstream feeds.
Signal weight · 25%This week · 2026-W18
Five packages engineers are pulling into production right now — ranked by PRI, refreshed every 15 minutes from real usage across the catalog.
Ecosystems · Integrations
Plus the surfaces that already ship it — IDE plugin stores, landscape feeds, and the public API you can hit from CI.
Powers the dependency-discovery layer behind
By the numbers
From two-person startups to Fortune 500 platform teams — engineers rely on OpenLib to evaluate dependencies before they ship. Six years of independent, ad-light operation.
Trusted by engineering teams at
Founder note
"We watched senior engineers spend half a Sprint evaluating dependencies that turned out to be unmaintained, copyleft-encumbered, or one GitHub handle away from disappearing. That is not a research problem — it's a trust problem. OpenLib exists because the cost of guessing wrong on a dependency is paid in production, on your users, at 3am."