supply-chain · severity medium

Package maintenance

Share of widely-depended-on packages with no release for over two years — still installed everywhere, no longer maintained.

Measured every Sunday · last updated

How it is measured

Bulk registry metadata; last release date. active < 365 days, stale < 730, abandoned ≥ 730.

Why it matters

A widely-depended-on package with no release in two years is installed everywhere and maintained by nobody — no security fixes are coming, and the dependency graph gives no warning. Being unmaintained is invisible at install time.

Limits of this measurement

A mature, complete library can be legitimately quiet; release cadence is a proxy for maintenance, not proof of abandonment.

The base rate

Measured over the full population of packages, from public bulk sources.

All packages 40.9% fail · n=1,083
active (<1y): 50.42%stale (1–2y): 8.68%abandoned (2y+): 40.9%
active (<1y) · 50.42%stale (1–2y) · 8.68%abandoned (2y+) · 40.9%

Every segment

Pick one to see the citable answer, with its trend and methodology.

Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.