Provides empirical baseline data on npm dependency depth and abandonment rates, highlighting the widespread use of unmaintained 'zombie' packages.
In 2019, the npm ecosystem surpassed 960,000 packages, with 250,000 added in 2018 alone. Research shows that 28% of npm packages are 'orphans' with no dependencies or dependents (vs 36% in PyPI), while the average dependency chain depth is 4.39 packages deep (vs 1.7 in PyPI). A critical finding is that 61% of npm packages (approx. 496,000) had not published a release in 12 months, effectively qualifying as abandoned by standard maintenance metrics. Despite this, abandoned packages like 'wordwrap' and 'is-object' continue to receive hundreds of millions of annual downloads, creating a massive, unmonitored attack surface for the JavaScript community.
61% of npm packages are found to be 'abandoned' using a 12-month no-release metric, yet many of these remain high-traffic dependencies.
dependency on unmonitored code that may contain latent vulnerabilities with no maintainer to provide fixes
the high prevalence of 12-month inactivity across npm makes staleness a primary filter for identifying potential maintenance neglect.
61% of packages on npm did not publish a release in the last 12 months... distinguishing between unmaintained and feature-complete packages which simply reached a maturity stage is not an easy task.
Risk Guard uses a 12-month stale threshold but does not distinguish between 'Mature/Stable' packages and 'Abandoned/Risky' ones based on download velocity.
Risk Guard would be better if it correlated 'Stale' status with 'Download Velocity' to identify high-usage abandoned packages that pose the greatest risk.