OSS Risk Radar surfaces operationally fragile dependencies — scored by ML and grounded in public maintenance signals.
43
Maintenance signals per repo
4
Risk buckets
12mo
Inactivity outlook
Start an analysis
Analysis typically completes in 30–90 seconds.
From a repository URL to a calibrated, evidence-backed risk score — in under two minutes.
Score a set of repositories and rank them by predicted 12-month inactivity risk, so the most fragile ones surface first.
A machine-learning model trained on historical maintenance outcomes — it scores operational fragility, not just known CVEs.
Repository health, release cadence, contributor count, OpenSSF checks, and scorecard data — unified in one view.
Every score shows whether it used full-history or cold-start signals plus an evidence-support value, so low-signal cases stay visible.
Forward-looking maintenance score predicts packages likely to go unmaintained within the next year.
Every score is traceable to raw observed signals. No black box — full auditability for security review.