Package maintenance · top100m+ (packages)
What share of packages in top100m+ have had no release in over two years?
22.62% of packages in top100m+ (95% CI 19.6–25.96%), measured across 663 packages on 2026-10-01.
Measured every Sunday since 2026-08-01 — 15 observations to date. Last measured 2026-10-01.
How this is measured
Bulk registry metadata; last release date. active < 365 days, stale < 730, abandoned ≥ 730.
Built entirely from public bulk feeds — no target is contacted. Aggregate-only. 95% Wilson confidence intervals. Population: the most-downloaded packages per ecosystem plus a native-build stratum, from public registry metadata. Snapshot: packages-top400.
Licensed CC BY 4.0 — reuse with attribution to Quiet Failures. Download: JSON · CSV.
Why it matters
A widely-depended-on package with no release in two years is installed everywhere and maintained by nobody — no security fixes are coming, and the dependency graph gives no warning. Being unmaintained is invisible at install time.
Limits of this measurement
A mature, complete library can be legitimately quiet; release cadence is a proxy for maintenance, not proof of abandonment.
The same check, other segments
- packages with a native build step98.23%
- long-tail (packages)98.22%
- npm (packages)59.15%
- all packages40.9%
- the most-downloaded packages20.62%
- top10m+ (packages)12.23%
- pypi (packages)9.75%