Dependency health, measured
Every application rests on a substrate of open-source it didn’t write, and can’t see.
Substrate gives any open-source package a 0–100 health score from live data, maintenance, security, recency and adoption. Compare two packages, or scan a whole package.json to find which of your dependencies quietly stopped being maintained.
Scored live, moments ago
Run your own →- 97reactActively maintained
- 61momentNo release in 2.6 years
- 30requestDeprecated · 53M downloads/mo
The risk isn’t the code you wrote.
A typical Node application ships around a thousand packages, and a team wrote perhaps forty of them. The rest arrived transitively, were reviewed once at install time, and have not been looked at since.
- 38 you wrote
- 922 you inherited
- 22 going stale
- 21 at risk
Three things Substrate does
Score a package, scan your whole stack for risk, and get pointed to healthier replacements when something is dying.
Dependency Health Score
A 0–100 score for any package, with every input shown.
Enter a package and get a single 0–100 health score, built from four visible sub-scores: recency, maintenance, security and adoption. No black box, the inputs and weights are published, so you can argue with them. Try it in the compare tool.
Read more →02Risk Radar
Paste a package.json, score your whole stack at once.
Scan an entire package.json and every dependency is scored and ranked worst-first, including the transitive ones you never chose directly. The free scan is point-in-time; continuous monitoring and alerting is the paid tier. Try it on the scan page.
Read more →03Migration Advisor
For dying packages, names healthier replacements.
When a dependency scores badly, Substrate names healthier alternatives and links straight to a comparison that proves the replacement is better. Where the migration is large, our consulting team picks up the work.
Read more →Start with two packages you already argue about.
The compare tool is free, needs no account, and runs against live public data. If it surfaces something uncomfortable, that is usually where a conversation with us starts.