it demonstrates that paid maintainers implement 55% more security practices than unpaid ones, validating the need for visibility into maintainer health and security practices.
Tidelift case study (October 2024) analyzing a real-world Python pricing-and-forecasting application in a regulated industry over a two-year engagement. At baseline, the customer had zero visibility into who maintained their open source dependencies and limited risk data (CVEs only). After onboarding, 48% of packages were found to have "no assurances found" (independent maintainers with no paid security commitments), 10% of package versions were declared end-of-life, 32% had no discoverable security policy, and 10% had known vulnerable releases. Tidelift recruited maintainers to raise contractual security coverage of independently maintained packages from 24% to 37% by 2024, projecting 80% by 2026. The customer saved an estimated $1.1M in cross-functional team time (engineering, legal, security) that would have been spent researching replacements and re-engineering around abandoned or insecure packages. Paid maintainers implement 55% more critical security practices than unpaid maintainers. A senior IT director quoted minimal package replacement as 3 months, average 6 months, and major framework replacement as one year. The same Python package set is used across 3,166 other applications at this organization.
The study reports that the customer experienced multiple instances of abandoned packages resurfacing transitively through other dependencies, requiring multi-month replacement efforts costing up to a year for major frameworks.
expensive, unplanned emergency replacement efforts or accepting long-term security risk
abandoned packages eventually surface unfixed urgent vulnerabilities, forcing organizations to either undertake costly emergency migrations or carry the risk indefinitely
The case study identifies packages "showing signals that they may go end-of-life or be abandoned" as a key risk vector the customer needed visibility into to proactively manage their supply chain.
investing in a dependency that is quietly deteriorating and will soon become a security liability
a lack of recent human commits is an early warning sign of impending abandonment, allowing teams to proactively migrate before an urgent vulnerability arises
The study highlights that independent maintainers, who represent 48% of the application's packages, have "less support and attention for their work" and represent a high-risk category for abandonment.
project abandonment due to maintainer burnout or sudden departure
a project entirely dependent on a single individual is uniquely vulnerable to that person's availability and continued interest, directly increasing the likelihood of sudden abandonment
The study segments risk by contributor backing, noting that "smaller, independently maintained projects often have fewer avenues for funding" and are "less objectively well-known," contrasting them with lower-risk corporation-backed projects.
maintenance delays and limited capacity to review or fix security vulnerabilities
projects with few unique contributors have lower collective capacity and resilience, meaning they may struggle to quickly triage, fix, and release patches when critical issues are discovered
The study documents that when packages surface unfixed urgent vulnerabilities, the result is "a multi-week or even multi-month cost where the business is still carrying the risk until that risk is eliminated."
active exposure to known exploits in production applications
an unfixed vulnerability means there is no patched version available, forcing the organization to either carry the risk, build a custom mitigation, or undertake an emergency migration
The study reports 10% of package versions were declared end-of-life and highlights that "end of life packages... are important risk vectors that are invisible to SCA tools," describing the condition this check often detects.
depending on a package version that is no longer receiving compatibility updates or security patches
a package that has not been released in years is highly likely to be unmaintained, meaning any future vulnerabilities discovered in it will remain unpatched
The study measured that 32% of the analyzed application's packages had no discoverable security policy, highlighting it as a key metric of unreliability alongside end-of-life status.
uncoordinated, public disclosure of vulnerabilities before a patch is available
the absence of a security policy means researchers lack a defined, private channel to report flaws, increasing the likelihood they will be disclosed publicly as zero-days
The case study highlights that 10% of package versions in the analyzed application were formally declared end-of-life, describing this as an important risk vector often invisible to standard SCA tools.
Risk Guard detects staleness and abandonment through commit and release inactivity, but does not explicitly check for formal package deprecation or end-of-life declarations in registries or repositories.
Risk Guard would be better if it detected and flagged formal package deprecation or end-of-life status from registry metadata or source repository notices.