supply-chain · severity medium

Package maintenance

Share of widely-depended-on packages with no release for over two years — still installed everywhere, no longer maintained.

Measured every Sunday · last updated

How it is measured

Bulk registry metadata; last release date. active < 365 days, stale < 730, abandoned ≥ 730.

Why it matters

A widely-depended-on package with no release in two years is installed everywhere and maintained by nobody — no security fixes are coming, and the dependency graph gives no warning. Being unmaintained is invisible at install time.

Limits of this measurement

A mature, complete library can be legitimately quiet; release cadence is a proxy for maintenance, not proof of abandonment.

The base rate

Measured over the full population of packages, from public bulk sources.

All packages 41.46% fail · n=1,083
active: 50.88%stale: 7.66%abandoned: 41.46%
active · 50.88%stale · 7.66%abandoned · 41.46%

Every segment

Pick one to see the citable answer, with its trend and methodology.

Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.