STALE MEASUREMENTPast this project's own 2-release window: the published result was measured with v0.32.0, 9 releases ago. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
MEASURED 16 SEPTEMBER 2026 · FIRST RELEASE 27 JUNE 2026

Every number here, you can check yourself.

6,926 lifetime installs against 7 GitHub stars — measured from pypistats.org and the GitHub API, dated, and explained rather than rounded up. The gap between those two numbers is the most informative thing on this page, so it gets a section of its own.

You will not find a wall of customer logos, because there are no customers yet and borrowed marks would be the first fabricated thing on this site. That is the same standard every figure on /results is held to. A tool that red-teams other people’s claims does not get to inflate its own.

Measured

Distribution, with every qualifier attached

Each number carries what it counts and what it does not, in the same breath. A download count quoted without its mirror share is a number chosen to flatter.

PyPI downloads, lifetime
6,926Excluding mirrors. Including them the figure is 23,954 — the gap is infrastructure, not people.Source: pypistats.org · measured 16 September 2026
PyPI downloads, last 30 days
2,454Excluding mirrors. Most of this is automated: CI runners and dependency resolvers reinstall on every job.Source: pypistats.org · measured 16 September 2026
GitHub stars
77. A star is the cheapest possible signal of human interest, and there are 7 of them.Source: github.com/provael/provael — stargazers · measured 16 September 2026
GitHub forks
0Nobody has forked the repository. A fork is roughly the cheapest signal that someone intends to change or extend the tool.Source: github.com/provael/provael — forks · measured 16 September 2026
Third-party reproductions
0Nobody outside the project has reproduced a published result. The register is at /verification and it is empty.Source: The register at /verification · measured 16 September 2026
The unflattering part

989 installs per star

6,926 downloads against 7 stars is roughly 989 installs per star. That ratio is not a success metric; it is a diagnosis.

A healthy developer tool sits nearer 10:1 or 50:1, because the humans who install it also bookmark it. 989:1 says the installs are overwhelmingly automated — CI runners, dependency resolvers and mirrors re-fetching the package — and that the human network around the project is close to empty.

71% of all-time downloads are mirror traffic, which points the same way.

That is the honest reading. It is published because a project whose entire argument is that its numbers are checkable does not get to quote the flattering half of its own distribution data.

Installs per star: what the ratio is made of · all figures measured 16 September 2026
SignalCountWhat it takes from a human
Installs, all time (no mirrors)6,926Often nothing — a CI job or resolver can produce these unattended.
Installs, all time (incl. mirrors)23,954Nothing. 71% of this is infrastructure copying the package.
Installs, last 30 days2,454Same caveat as the lifetime figures above: mostly automated, over a shorter window.
GitHub stars7One deliberate click by one person. The cheapest human signal there is.
Published third-party reproductions0Hours of someone else's compute and attention. The most expensive signal, and the one that would count most.
Not measured

CI-gate installs, and why there is no number

The published GitHub Action is the most interesting adoption signal this project could have — it means someone wired a red-team gate into a pipeline and left it there. There is no count for it on this page because there is no honest way to measure it: GitHub publishes no per-repository usage figures for an Action, and the tool has no telemetry by design, which is the same property that makes the architecture claim on /trust true.

A number could be estimated from download patterns. It is not, because an estimate presented beside measured figures reads as measured, and this page has no way to mark that difference strongly enough to be safe.

What would move these

The number that matters is the one at zero

Installs are the cheap signal. The expensive one — an independent party reproducing a published result and publishing what they got — sits at 0. The commands, the pinned commit and the register are at /verification, and a result that contradicts ours is as welcome as one that confirms it. If you would rather measure your own policy than reproduce ours, /submit is the four-step path onto the board.