Real numbers, honestly labeled — including what each one does and doesn't prove.
"Distinct installs" counts a random, non-identifying ID sent only when someone opts in with
rulereceipt check --telemetry — never rule text, file paths, or results, and off by default. See
Privacy.
If the install count looks too small, it is not a mistake. These two numbers can differ by orders of magnitude, and the smaller one is the real one. An install is somebody choosing to tell us; a download is mostly a machine copying a file. We publish both because a tool that checks whether claims have evidence behind them cannot quietly show you the flattering number.
"npm downloads" is the raw number npm reports — it counts CI pipelines and automated security scanners too, not just people. Shown for transparency, not as a user count.
This counter only moves when someone runs
rulereceipt check --share — an opt-in flag, off by default. See
Privacy.