Provides a high-profile case study of 'maintainer burnout' and the systemic risk of critical libraries that secure half the web being maintained by a single underfunded individual.
The 'core-js' library, a modular standard library providing polyfills for modern browser features, secures over 50% of the world's most visited websites and is used by 13 million developers—yet it is facing a critical sustainability crisis. Despite over nine billion total downloads and 43 million weekly requests, its primary maintainer, Denis Pushkarev, reported receiving only $57 per month in donations before Western financial sanctions on Russia further cut off funds. Attempts to solicit support via Patreon links resulted in a 'continuous stream of hate', prompting Pushkarev to consider changing the project's license to a paid, closed-source model. This situation illustrates the extreme fragility of critical internet infrastructure that relies on a single, under-resourced individual who receives minimal reward for maintaining a project used indirectly by nearly every web framework and transpiler.
The library, used by 13 million developers, is written and maintained almost entirely by a single individual who is threatening to walk away.
sudden loss of security maintenance for the foundational polyfills used by half of the global internet
detecting single-contributor bottlenecks is the most predictive signal for the 'sustainability crisis' currently threatening the JavaScript ecosystem.
core-js is on hundreds of millions of websites and over 50% of the world’s most visited websites... donations... $57 / month.
Risk Guard evaluates technical signals but does not track the 'Financial Health' or 'Maintainer Morale' of the individuals behind critical digital infrastructure.
Risk Guard would be better if it identified 'Underfunded Infrastructure' by correlating package importance (downloads) with known maintainer funding levels (e.g., from Open Collective).