RepoPilot

anomalyco/opencode vs mularahul/keyviz

anomalyco/opencode shows stronger signals overall

As of June 2026, opencode shows healthier maintenance signals than keyviz. opencode rates Healthy overall while keyviz rates Mixed. opencode was committed to today with 18+ active contributors, while keyviz last saw a commit 2 months ago with 2+ active contributors. opencode is MIT-licensed while keyviz is GPL-3.0-licensed. Neither has known critical or high-severity CVEs in its dependency tree.

Informational only. RepoPilot summarises public signals at the time of analysis. Not professional, security, or legal advice.

anomalyco/opencode

Healthy

Healthy across the board

HealthyDependency

Permissive license, no critical CVEs, actively maintained — safe to depend on.

HealthyFork & modify

Has a license, tests, and CI — clean foundation to fork and modify.

HealthyLearn from

Documented and popular — useful reference codebase to read through.

HealthyDeploy as-is

No critical CVEs, sane security posture — runnable as-is.

  • Last commit today
  • 18 active contributors
  • Distributed ownership (top contributor 38% of recent commits)
  • MIT licensed
  • CI configured
  • Tests present

Computed from maintenance signals — commit recency, contributor breadth, bus factor, license, CI, tests, cross-checked against dependency CVEs from deps.dev and OpenSSF Scorecard

mularahul/keyviz

Mixed

Single-maintainer risk — review before adopting

ConcernsDependency

copyleft license (GPL-3.0) — review compatibility; top contributor handles 97% of recent commits…

HealthyFork & modify

Has a license, tests, and CI — clean foundation to fork and modify.

HealthyLearn from

Documented and popular — useful reference codebase to read through.

HealthyDeploy as-is

No critical CVEs, sane security posture — runnable as-is.

  • Small team — 2 contributors active in recent commits
  • Single-maintainer risk — top contributor 97% of recent commits
  • GPL-3.0 is copyleft — check downstream compatibility
  • No test directory detected
  • Scorecard: default branch unprotected (0/10)
  • Last commit 6w ago
  • 2 active contributors
  • GPL-3.0 licensed
  • CI configured

What would improve this?

  • Use as dependency ConcernsMixed if: relicense under MIT/Apache-2.0 (rare for established libs)

Computed from maintenance signals — commit recency, contributor breadth, bus factor, license, CI, tests, cross-checked against OpenSSF Scorecard

Signal-by-signal breakdown

opencodekeyviz
Stars179,5949,248
Last committoday2mo ago
LicenseMITGPL-3.0
Open issues7,02352
Has tests
Has CI
Test coverage1%0%
Dependency CVEsNo CVEsNo CVEs
Architecture grade
Cycles
Bottom-lineHealthy signalsMixed signals

Want the full analysis? anomalyco/opencode · mularahul/keyviz

Ask AI about anomalyco/opencode vs mularahul/keyviz

Open the chat with a comparison question pre-filled.