Open Source Surface
For providers whose product is itself open source ONLY: does the repository publish the maintainership surface a consumer needs in order to depend on it? A vulnerability-disclosure path, a documented contribution route, a published release history, and a stated code of conduct. Not applied to closed-source products — a company with no CONTRIBUTING.md is not deficient, it is differently shaped. Not applied where the repository could not be read, either: unreadable is not missing.
How it is scored
4 checks worth 40 points, grouped by the artifact each one reads. A facet's sub-score is its awarded points normalized against the points that were actually applicable to that provider — a check needing an artifact the provider does not publish at all is N/A, and leaves both sides of the fraction.
open_source| Check | Rule | Points |
|---|---|---|
| Published vulnerability-disclosure pathWhere an integrator reports a vulnerability in the thing they just put into production. The rarest of the four at 35.0% and the one that most directly affects a consumer, which is why it carries the most points. | a SECURITY policy is present on the provider's own product repository | 14 |
| Documented contribution routeWhether the project is actually open to participation or merely published. 62.4% coverage. | a CONTRIBUTING guide is present on the provider's own product repository | 10 |
| Published release historyVersioned, dated artifacts — the thing a consumer checks before depending on a project. Commonest of the four at 76.0%, but priced above the code of conduct because it carries far more information about whether the project is maintained. | the provider's own product repository publishes releases | 10 |
| Stated code of conductA stated standard for participation. Priced lowest of the four despite being rarer than releases at 49.6%: it is the most template-prone signal in the set, frequently dropped in wholesale, and so says the least about the project that holds it. | a CODE_OF_CONDUCT is present on the provider's own product repository | 6 |
How the catalog distributes on it
Every one of the 1,126 providers this facet is scored on, bucketed by sub-score.
Top providers
The top 500 of 1,018 providers scoring above zero on this facet, ranked by facet sub-score, ties broken by composite.
The other 7 facets
github.com/api-evangelist/<provider>, and each check above names the exact artifact it
reads. Publish the artifact, open a pull request, and the next scoring run picks it up — no gatekeeping
and no fee. The full rubric is at apis.io/rating/, and
prioritized profiling
is the fast lane if you would rather have it done for you.
Scored on rubric v0.17.2 across 27,504 providers · lists rebuilt 2026-09-01 · capped at the top 500 per page.