deprecationnpmabandonmentresearchtransitive-dependencies

CSO Online — Deprecated npm Packages

Quantifies the 'Practical Deprecation' gap in npm and identifies archived or missing source repositories as high-fidelity signals for maintenance abandonment.

Summary

Out of the top 50,000 most downloaded npm packages, while only 8% are 'officially' deprecated, research by Aqua Security reveals that 'practical' deprecation is significantly more pervasive. When accounting for archived repositories (12%), unavailable or deleted repositories (15%), and missing repository links (21.2%), one in five popular packages is effectively dead. These 10,600+ practically deprecated packages account for a staggering 2.1 billion weekly downloads, representing a massive 'silent' attack surface. The problem is compounded by transitive dependencies: the 'request' package is officially deprecated yet serves over 55,000 dependents, while the 'through' library has not been updated in nine years and has 3,000 dependents despite an archived GitHub repository. The study warns that maintainers often opt to deprecate rather than fix security flaws, leaving downstream users unaware of persistent vulnerabilities.

Related Checks

SOURCE_REPO_ABANDONED

The research highlights that 21.2% of popular packages have archived or deleted repositories, yet continue to receive billions of downloads.

Adverse Outcome

dependency on dead-end code that will never receive another security patch or compatibility update

Because

archiving or deleting a source repository is the definitive signal of maintainer exit, validating the need for automated source-link verification.

PACKAGE_STALE_RELEASE

Packages like 'through' continue to serve 3,000 dependents despite having no new registry releases for over nine years.

Adverse Outcome

long-term accumulation of unmanaged technical debt and security flaws in unmonitored code

Because

the absence of new package versions for years beyond the staleness threshold is a high-fidelity signal of the practical abandonment identified in the Aqua Security report.

Gaps Analysis

Evidence

When the Aqua researchers included a check for archived repositories, the rate... jumped from 8% to 12%... deleted or made private... 15%... absence of a repository link... 21.2%.

Blind Spot

Risk Guard flags missing or inaccessible repositories (SOURCE_REPO_NOT_FOUND) but does not distinguish between archived, deleted, or never-linked repositories as separate abandonment signals.

Actionable Capability

Risk Guard would be better if it differentiated the reason a repository is unavailable (archived vs deleted vs never linked) to provide more specific abandonment indicators.

← Previous Next →