deprecationnpmabandonmentresearchtransitive-dependencies

Aqua Nautilus — Deprecated npm Packages

Quantifies the 'Practical Deprecation' gap in npm and identifies archived or missing source repositories as high-fidelity signals for maintenance abandonment.

Summary

Research into the top 50,000 npm packages reveals a 'deceptive deprecation gap': while 8.2% are officially deprecated on the npm registry, the real number of effectively dead packages is 21.2% when accounting for archived (12.8%), deleted or private (15.0%), and unlinked source repositories (21.2%). These practically deprecated packages account for 2.1 billion weekly downloads, representing a massive 'silent' attack surface. A critical security concern is that maintainers often deprecate packages instead of reporting vulnerabilities or assigning CVEs to avoid the burden of remediation. For example, the 'request' package is deprecated yet has 55,000 direct dependents, while 'through' has been github-archived for nine years with 3,000 dependents. The study identifies 'no repository linked' and 'unresponsive maintainers' as primary criteria for identifying orphaned packages that are susceptible to threat actor takeovers.

Related Checks

SOURCE_REPO_ABANDONED

The research highlights that 21.2% of popular packages have archived or deleted repositories, yet continue to receive billions of downloads.

Adverse Outcome

dependency on dead-end code that will never receive another security patch or compatibility update

Because

archiving or deleting a source repository is the definitive signal of maintainer exit, validating the need for automated source-link verification.

PACKAGE_STALE_RELEASE

Packages like 'through' continue to serve 3,000 dependents despite having no new registry releases for over nine years.

Adverse Outcome

long-term accumulation of unmanaged technical debt and security flaws in unmonitored code

Because

the absence of new package versions for years beyond the staleness threshold is a high-fidelity signal of the practical abandonment identified in the Aqua Security report.

Gaps Analysis

Evidence

When the Aqua researchers included a check for archived repositories, the rate... jumped from 8% to 12%... deleted or made private... 15%... absence of a repository link... 21.2%.

Blind Spot

Risk Guard flags missing or inaccessible repositories (SOURCE_REPO_NOT_FOUND) but does not distinguish between archived, deleted, or never-linked repositories as separate abandonment signals.

Actionable Capability

Risk Guard would be better if it differentiated the reason a repository is unavailable (archived vs deleted vs never linked) to provide more specific abandonment indicators.

← Previous Next →