Early Access v0.9

PredictAbandonment.Before YourBuild Fails.

AI-powered survival scoring across npm, PyPI, Cargo & Go. Know which packages are dying 60–90 days before your CI fails. Replacement suggestions, burnout detection, SBOM export & CI gate — free plan included.

Free plan foreverNo credit card10 AI featuresResults in <60s
os-sentinel-terminal
> 
>
>
Try:
NPM RegistryPyPICrates.ioGitHub APIGitLabBitbucketMaven CentralGo ModulesNPM RegistryPyPICrates.ioGitHub APIGitLabBitbucketMaven CentralGo Modules
90%
of production code is open source
500+
avg. direct deps per app
60–90d
early prediction window
10
AI features built in

How OSSentinel monitors your dependencies

Connect your repo in seconds. OSSentinel fetches real GitHub signals, runs survival analysis, and returns a ranked risk board — no configuration required.

[ System Architecture ]
01
01

Create a free account

Sign up with email or GitHub OAuth in under 30 seconds. No credit card needed. 3 full scans included every month, forever.

02
02

Paste any GitHub repo

Enter a GitHub URL or owner/repo identifier. OSSentinel auto-detects package.json, requirements.txt, Cargo.toml, go.mod, and pyproject.toml.

03
03

AI-powered signal analysis

15 real-time GitHub signals — commit velocity, maintainer activity, issue drift, funding gaps, and more — are computed and fed into a Gradient Boosted Survival model with SHAP explainability.

04
04

Act before the crisis

The Risk Board ranks every dependency by Survival Probability Score (SPS 0–100). AI-generated remediation advice tells your team exactly what to do: pin, fork, or migrate.

Survival Score Tiers

CRITICAL0–25

Migrate this sprint

HIGH26–50

Plan migration this quarter

MEDIUM51–70

Add to tech-debt backlog

LOW71–100

Healthy — annual review

15 predictive abandonment signals — including AI.

12 GitHub-derived signals grounded in peer-reviewed OSS survival research (arXiv 2025, IEEE ESEM 2019, CHAOSS) plus 3 AI signals powered by GPT-4o-mini — including maintainer burnout sentiment analysis.

Critical

Commit Velocity Decay

Exponential decay fit across 30/60/90-day windows. The single strongest predictor of OSS abandonment.

Critical

Maintainer Activity Interval

Days since any maintainer action — commits, PRs, issue responses. Sustained latency signals imminent burnout.

High

Funding Gap Detection

Tracks FUNDING.yml, GitHub Sponsors, and OpenCollective. Projects that lose backing rarely recover.

High

Issue Resolution Drift

A growing pile of unanswered security issues is an early high-weight abandonment signal our model weights heavily.

High

Key Person Concentration

Truck-factor risk: if >80% of commits come from one contributor, a single departure ends the project.

Medium

PR Merge Rate

Falling merge rates mean community patches pile up unreviewed — a leading indicator of maintainer disengagement.

Medium

Fork-to-Star Ratio Trend

Rising forks vs. stars signals the community self-maintaining a stagnant project — a vote of no confidence.

Medium

Release Cadence Drift

Compares current release frequency against historical baseline. Silent repositories near major version milestones are high-risk.

AI Signal

Maintainer Burnout (AI)

GPT-4o-mini sentiment analysis on maintainer issue responses detects frustration language, capacity limits, and disengagement patterns.

Medium

Contributor Count (30d)

Fewer than 2 active contributors in 30 days places the project on a single-point-of-failure trajectory.

Critical

Open Security Issues

Unresolved CVE-tagged or security-labelled issues with no maintainer response trigger immediate CRITICAL elevation.

Output

Survival Probability Score

All 15 signals fed into a Gradient Boosted Survival Analysis model with SHAP explainability — one number, 0–100.

AI-Powered Intelligence

9 AI features built in.

Every AI feature is gated by plan, secured with Clerk auth, and powered by GPT-4o-mini — designed to convert raw risk signals into engineer-ready actions.

Growth+

Replacement Suggester

Curated + GPT-4o-mini alternatives for every at-risk package. One click to get install commands and migration rationale.

Growth+

GitHub PR Bot

Automatically comments on pull requests with SPS scores when new dependencies are introduced.

Growth+

90-Day Forecast

Historical SPS trajectory chart with AI narrative. Know if a package is declining, stable, or recovering — 3 months out.

Growth+

Burnout Detector

Sentiment analysis on maintainer issue responses. Detect frustration language, capacity limits, and disengagement 60+ days early.

Professional+

NL Query

Ask your dependency data in plain English: 'Show my most at-risk npm packages with fewer than 2 contributors.'

Professional+

Executive PDF

Board-level dependency health report generated on demand. Portfolio KPIs, risk inventory, and AI executive summary.

Professional+

Slack & Teams Alerts

Real-time tier-crossing notifications to Slack or Microsoft Teams when a package moves from MEDIUM to HIGH risk.

Enterprise

SBOM Export

CycloneDX 1.5 or SPDX 2.3 software bill of materials enriched with OSSentinel SPS scores and risk tiers.

All tiers

Onboarding Assistant

Streaming AI chat that guides new users through their first scan, explains SPS scores, and answers any dependency health question.

Simple, transparent pricing

Start free — no credit card needed. Unlock AI replacement suggestions, PR bot, and burnout detection from $39/month. Scale to executive reports, Slack alerts, and SBOM export when your organisation needs it.

Free

Start monitoring OSS dependency health instantly. No credit card required.

$0/month
4 scans/month · 1 repo · 5 signals
Get Started Free
  • [+]4 dependency scans per month
  • [+]1 public GitHub repo
  • [+]5 core abandonment signals
  • [+]Visual risk board with SPS scores
  • [+]Direct dependencies only
  • [+]AI onboarding assistant
  • [-]AI remediation & replacement suggestions
  • [-]GitHub PR bot integration
  • [-]Executive PDF reports
  • [-]Slack & Teams alerts

Starter

AI-powered risk summaries, scan history, and actionable remediation for solo developers.

$9/month
₹799/mo · India pricing
25 scans/month · 5 repos · AI insights
Start for $9/mo
  • [+]25 dependency scans per month
  • [+]Up to 5 public & private repos
  • [+]10 abandonment signals
  • [+]AI portfolio health summary
  • [+]AI onboarding assistant
  • [+]Scan history & trend tracking
  • [-]AI replacement suggestions
  • [-]90-day trajectory forecast
  • [-]Executive PDF report
Most Popular

Growth

Full 15-signal analysis, AI replacement suggestions, and maintainer burnout detection.

$39/month
₹3,499/mo · India pricing
150 scans/month · 20 repos · PR bot
Start Growing
  • [+]150 dependency scans per month
  • [+]Up to 20 public & private repos
  • [+]All 15 predictive signals
  • [+]AI dependency replacement suggester
  • [+]90-day trajectory forecast (AI narrative)
  • [+]Maintainer burnout detector
  • [+]GitHub PR bot with risk comments
  • [+]Real-time webhook alerts
  • [+]Migration intelligence reports
  • [-]Natural language query
  • [-]Executive PDF report
  • [-]SBOM export

Professional

Org-wide monitoring with NL query, executive PDF report, and Slack/Teams alerts.

$119/month
₹9,999/mo · India pricing
500 scans/month · 100 repos · PDF Reports
Go Professional
  • [+]500 dependency scans per month
  • [+]Up to 100 public & private repos
  • [+]All 15 predictive signals
  • [+]Natural language package query (AI)
  • [+]Executive PDF report generation
  • [+]Slack & Microsoft Teams alerts
  • [+]Everything in Growth plan
  • [-]SBOM export (CycloneDX / SPDX)
  • [-]SSO / SAML

Enterprise

Custom deployment, SBOM export, SSO, SOC 2 compliance, and dedicated support for large organisations.

Custom
Unlimited scans · private · on-prem · SSO
Contact Sales
  • [+]Everything in Professional
  • [+]SBOM export (CycloneDX 1.5 / SPDX 2.3)
  • [+]SSO / SAML integration
  • [+]SOC 2 Type II compliance
  • [+]On-prem / air-gapped deployment
  • [+]GitLab, Bitbucket, Azure DevOps
  • [+]Dedicated SLA & support engineer
  • [+]Custom signal weighting
Knowledge Base

Frequently asked questions

Everything you need to know about OSS dependency monitoring with OSSentinel.

OSSentinel fetches 15 real-time signals from the GitHub API — including commit velocity decay, maintainer activity intervals, issue response latency, PR merge rate, key-person concentration, and funding gap detection. These are combined using a Gradient Boosted Survival Analysis (GBSA) model trained on historical OSS abandonment data, producing a 0–100 SPS for each dependency.

No. OSSentinel only reads public repository metadata via the GitHub GraphQL API — commit history, issues, pull requests, and release data. For private repos (Business & Enterprise), we use a read-only GitHub App token and never access raw source code.

OSSentinel currently supports npm (Node.js), PyPI (Python), Cargo (Rust), and Go modules. Maven (Java) and NuGet (.NET) are on the roadmap. We auto-detect the manifest format from your repo root.

OSSentinel ships 9 AI features: (1) Dependency Replacement Suggester — curated + GPT-4o-mini alternatives; (2) GitHub PR Bot — comments on PRs with SPS scores for new deps; (3) Natural Language Query — ask questions like 'show my most at-risk npm packages'; (4) 90-Day Trajectory Forecast — historical SPS trend with AI narrative; (5) Executive PDF Report — board-level dependency health document; (6) Maintainer Burnout Detector — sentiment analysis on issue responses; (7) SBOM Export — CycloneDX 1.5 / SPDX 2.3 enriched with SPS; (8) Slack & Teams Alerts — tier-crossing notifications; (9) Onboarding Assistant — streaming chat for first-time setup.

Your 4-scan quota resets monthly. You can upgrade to Starter ($9/month · ₹799) for 25 scans, Growth ($39/month · ₹3,499) for 150 scans and full AI features, or wait for your reset. No data is lost — previous scan results remain visible in Scan History.

Yes. The Growth plan ($39/month · ₹3,499) supports up to 20 repos, 150 scans, AI replacement suggester, PR bot, and burnout detector. Professional ($119/month · ₹9,999) adds natural language query, executive PDF reports, and Slack/Teams alerts.

We love hearing from users. Click 'Suggest a Feature' in the navigation or email us directly — our roadmap is shaped entirely by engineering teams using OSSentinel in production.

Community Roadmap

Shape what we build next

OSSentinel's roadmap is driven by engineering teams in production. Got an idea for a new signal, integration, or workflow? We read every submission.

Suggest a Feature

We typically respond within 48 hours

Start monitoring today.

> 
>
>