supply-chain · severity medium
Package maintenance
Share of widely-depended-on packages with no release for over two years — still installed everywhere, no longer maintained.
Measured every Sunday · last updated
How it is measured
Bulk registry metadata; last release date. active < 365 days, stale < 730, abandoned ≥ 730.
Why it matters
A widely-depended-on package with no release in two years is installed everywhere and maintained by nobody — no security fixes are coming, and the dependency graph gives no warning. Being unmaintained is invisible at install time.
Limits of this measurement
A mature, complete library can be legitimately quiet; release cadence is a proxy for maintenance, not proof of abandonment.
The base rate
Measured over the full population of packages, from public bulk sources.
Every segment
Pick one to see the citable answer, with its trend and methodology.
Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.