npmabandonmentdependency-graphresearch

Snyk — npm Package Behavior

Provides empirical baseline data on npm dependency depth and abandonment rates, highlighting the widespread use of unmaintained 'zombie' packages.

Summary

In 2019, the npm ecosystem surpassed 960,000 packages, with 250,000 added in 2018 alone. Research shows that 28% of npm packages are 'orphans' with no dependencies or dependents (vs 36% in PyPI), while the average dependency chain depth is 4.39 packages deep (vs 1.7 in PyPI). A critical finding is that 61% of npm packages (approx. 496,000) had not published a release in 12 months, effectively qualifying as abandoned by standard maintenance metrics. Despite this, abandoned packages like 'wordwrap' and 'is-object' continue to receive hundreds of millions of annual downloads, creating a massive, unmonitored attack surface for the JavaScript community.

Related Checks

SOURCE_REPO_STALE

61% of npm packages are found to be 'abandoned' using a 12-month no-release metric, yet many of these remain high-traffic dependencies.

Adverse Outcome

dependency on unmonitored code that may contain latent vulnerabilities with no maintainer to provide fixes

Because

the high prevalence of 12-month inactivity across npm makes staleness a primary filter for identifying potential maintenance neglect.

Gaps Analysis

Evidence

61% of packages on npm did not publish a release in the last 12 months... distinguishing between unmaintained and feature-complete packages which simply reached a maturity stage is not an easy task.

Blind Spot

Risk Guard uses a 12-month stale threshold but does not distinguish between 'Mature/Stable' packages and 'Abandoned/Risky' ones based on download velocity.

Actionable Capability

Risk Guard would be better if it correlated 'Stale' status with 'Download Velocity' to identify high-usage abandoned packages that pose the greatest risk.

← Previous Next →