Package maintenance · the most-downloaded packages
What share of the most-downloaded packages have had no release in over two years?
20.75% of the most-downloaded packages (95% CI 18.08–23.7%), measured across 800 packages on 2026-08-09.
Measured every Sunday since 2026-08-01 — 4 observations to date. Last measured 2026-08-09.
How this is measured
Bulk registry metadata; last release date. active < 365 days, stale < 730, abandoned ≥ 730.
Built entirely from public bulk feeds — no target is contacted. Aggregate-only. 95% Wilson confidence intervals. Population: the most-downloaded packages per ecosystem plus a native-build stratum, from public registry metadata. Snapshot: packages-top400.
Licensed CC BY 4.0 — reuse with attribution to Quiet Failures. Download: JSON · CSV.
Why it matters
A widely-depended-on package with no release in two years is installed everywhere and maintained by nobody — no security fixes are coming, and the dependency graph gives no warning. Being unmaintained is invisible at install time.
Limits of this measurement
A mature, complete library can be legitimately quiet; release cadence is a proxy for maintenance, not proof of abandonment.
The same check, other segments
- packages with a native build step100%
- long-tail (packages)100%
- npm (packages)60.18%
- all packages41.46%
- top100m+ (packages)21.46%
- pypi (packages)9.5%