The four sources
- Open Collective — historical totalAmountDonated, often multi-year. Not a run-rate.
- Open Source Pledge — annual payment from the latest public report, devs times dollars per dev.
- GitHub Sponsors — a monthly amount only when the tier is public. That is rare. It is not multiplied by twelve.
- Own programs — a figure from a public page, or a name with no figure.
What was left out
Before this file: 119 spam companies ($643.7k) and 1 self-fund (Supabase, $1.1M). Spam and the Supabase self-fund are already out of this file. Counts are the 2026-10-05 method note, not recomputed here.
Supabase appears as a backer of its own collective. That was read as money moving through the project, not as classic outbound sponsoring, and kept out of the ranking until a manual review says otherwise.
Transparency, in one sentence
Score = 0.6 × (public dollars ÷ the leader) + 0.4 × (sponsorships with a public amount ÷ sponsorships). The leader this collection is $762.4k. A high score on a small total is labeled low volume. The score is never shown alone.
Snapshots
This build holds one snapshot, 5 Oct 2026, hash 9fca312af00a. 838 companies, 3,112 sponsorship lines, $9.3M in the top 200. baseline — next full collection is the 1st of the month. Deltas compare two hashes. They do not forecast the next one.
Internal API
Read-only. Preview key, header X-API-Key: wfo_preview_floor. Health is open. The rest refuse a missing key.
- GET /api/health
- GET /api/v1/leaderboard?sort=public_usd|projects|gh&limit=50&offset=0&include_whales=false
- GET /api/v1/companies/:slug
- GET /api/v1/companies/:slug/sponsorships
- GET /api/v1/deltas?from=&to=
- GET /api/v1/graph/co-sponsorships?min_shared=2
- GET /api/v1/watchlist
- GET /api/v1/watchlist/alerts?since=
- GET /api/v1/export/companies
- GET /api/v1/export/sponsorships
- GET /api/v1/export/snapshots