×
How to read this guide
This resource exists to help you make a correct, low-regret decision when picking a third-party component. Skim the leaders in a category, then use the five factors and the licensing notes to pressure-test the shortlist against your constraints.
The five decision factors (1–5, higher is better)
- Scale / performance — proven throughput, latency, and horizontal headroom at large volume.
- Cost-efficiency — total cost of ownership relative to value; 5 = cheap/predictable, 1 = expensive or prone to bill-shock.
- Ecosystem / maturity — community size, integrations, hiring pool, documentation, longevity.
- Ops-simplicity — how little operational burden it imposes; 5 = fully managed / trivial, 1 = heavy to run yourself.
- Lock-in-safety — portability and exit cost; 5 = open standard / easily replaced, 1 = deep proprietary lock-in.
Tiers
Leader
Strong
Niche
Leader = the safe default most teams should start from in that subcategory. Strong = a well-founded choice for specific needs. Niche = fits narrow cases, declining, or carries adoption risk.
Licensing — the part that bites later
Permissive
Weak copyleft
Copyleft
Source-available
Proprietary
The five classes are read from the license actually in force, not from a vendor’s description of it. Permissive (MIT, Apache-2.0, BSD) and copyleft (GPL, AGPL, MPL) are both OSI-approved open source, and the badge shows the SPDX id so you can tell which. Source-available (BUSL, SSPL, Elastic-2.0, FSL, Confluent Community) lets you read the code but restricts commercial or hosted use — a real constraint if you resell or host. Proprietary includes managed services built over open-source components; the license line on each card says which.
Where a license here corrects an earlier label, the card says so. The original snapshot classified tools by hand and got some wrong — a few had relicensed since, and others are proprietary services wrapping an open-source engine. The derived class wins and the correction is shown rather than quietly swallowed.
Recent relicensings reshaped this space: Redis returned to AGPL in Redis 8 (2025) after the Valkey fork; HashiCorp (Terraform, Vault, Nomad, Consul) moved to BUSL and is now IBM-owned, spawning OpenTofu and OpenBao; MongoDB and Elasticsearch moved to SSPL, with Elasticsearch adding AGPL back in 2024.
The risk score (0–100, and this one is upside down)
0 is the lowest risk and 100 the highest — the opposite direction to the five ratings above. It is derived, not hand-set, from six factors: how open the license is and whether it changed recently, who governs the project, how mature it is, how expensive it would be to leave, how close the next end-of-life date is, and how long the vendor supports any release at all.
Every card has a “Why this score” disclosure showing each factor and the derivation lines behind it. If a number looks wrong, that panel is where to argue with it.