Dependency health, measured

Every application rests on a substrate of open-source it didn’t write, and can’t see.

Substrate gives any open-source package a 0–100 health score from live data, maintenance, security, recency and adoption. Compare two packages, or scan a whole package.json to find which of your dependencies quietly stopped being maintained.

Scored live, moments ago

Run your own →
  • 97reactActively maintained
  • 61momentNo release in 2.6 years
  • 30requestDeprecated · 53M downloads/mo

The risk isn’t the code you wrote.

A typical Node application ships around a thousand packages, and a team wrote perhaps forty of them. The rest arrived transitively, were reviewed once at install time, and have not been looked at since.

  • 38 you wrote
  • 922 you inherited
  • 22 going stale
  • 21 at risk

Three things Substrate does

Score a package, scan your whole stack for risk, and get pointed to healthier replacements when something is dying.

Start with two packages you already argue about.

The compare tool is free, needs no account, and runs against live public data. If it surfaces something uncomfortable, that is usually where a conversation with us starts.