Quantifies the 'Practical Deprecation' gap in npm and identifies archived or missing source repositories as high-fidelity signals for maintenance abandonment.
Out of the top 50,000 most downloaded npm packages, while only 8% are 'officially' deprecated, research by Aqua Security reveals that 'practical' deprecation is significantly more pervasive. When accounting for archived repositories (12%), unavailable or deleted repositories (15%), and missing repository links (21.2%), one in five popular packages is effectively dead. These 10,600+ practically deprecated packages account for a staggering 2.1 billion weekly downloads, representing a massive 'silent' attack surface. The problem is compounded by transitive dependencies: the 'request' package is officially deprecated yet serves over 55,000 dependents, while the 'through' library has not been updated in nine years and has 3,000 dependents despite an archived GitHub repository. The study warns that maintainers often opt to deprecate rather than fix security flaws, leaving downstream users unaware of persistent vulnerabilities.
The research highlights that 21.2% of popular packages have archived or deleted repositories, yet continue to receive billions of downloads.
dependency on dead-end code that will never receive another security patch or compatibility update
archiving or deleting a source repository is the definitive signal of maintainer exit, validating the need for automated source-link verification.
Packages like 'through' continue to serve 3,000 dependents despite having no new registry releases for over nine years.
long-term accumulation of unmanaged technical debt and security flaws in unmonitored code
the absence of new package versions for years beyond the staleness threshold is a high-fidelity signal of the practical abandonment identified in the Aqua Security report.
When the Aqua researchers included a check for archived repositories, the rate... jumped from 8% to 12%... deleted or made private... 15%... absence of a repository link... 21.2%.
Risk Guard flags missing or inaccessible repositories (SOURCE_REPO_NOT_FOUND) but does not distinguish between archived, deleted, or never-linked repositories as separate abandonment signals.
Risk Guard would be better if it differentiated the reason a repository is unavailable (archived vs deleted vs never linked) to provide more specific abandonment indicators.