Deprecated but Not Abandoned: A Large-Scale Empirical Study on Growing-User-Demand Deprecated NPM Packages
Zezhou Tang, Yang Zhang, Xinjun Mao, Tanghaoran Zhang, Changrong Xie, Wenyu Xu, Simeng Yao, Yiwen Wu
Abstract
Package deprecation in ecosystems like NPM signals the termination of maintenance, and continued use of such packages poses potential sustainability and security risks to dependent projects. We observe a counter-intuitive phenomenon among widely-used deprecated packages whose user demand continues to grow after deprecation; we define these as Growing-user-demand Deprecated NPM Packages (GDNPs). Despite this clear contradiction between deprecation and growing user demand, the community engagement, reasons, and challenges of GDNPs have not been systematically examined. To bridge this gap, we conduct a mixed-method empirical study that identifies and analyzes 864 GDNPs from 4,011 widely-used deprecated packages, alongside surveys of 76 maintainers and 67 users. We find that GDNPs grow on average by 14.5% per month after deprecation, yet repository-level community engagement eventually drops significantly, revealing an expanding maintenance gap. Quantitatively, GDNPs contribute to over 124 million monthly exposures to high-severity vulnerabilities. Surveys indicate that continued reliance stems primarily from the complexity of the dependency tree and user inertia, leading to reactive maintenance and the accumulation of technical debt. Furthermore, topic modeling of post-deprecation discussions of GDNP repositories shows that community discussions heavily prioritize functional errors while seldom discussing security vulnerabilities, highlighting a misalignment between perceived and actual risk. Based on the results, we provide actionable implications that can facilitate future research and assist stakeholders in improving the maintenance of GDNPs.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Understanding the Response to Open-Source Dependency Abandonment in the npm EcosystemCourtney Miller, Mahmoud Jahanshahi, Audris Mockus, Bogdan Vasilescu et al.ICSE 2025 · 5 citations
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- An Empirical Study on Package-Level Deprecation in Python EcosystemZhiqing Zhong, Shilin He, Haoxuan Wang, Boxi Yu et al.ICSE 2025 · 3 citations
- Not All Dependencies are Equal: An Empirical Study on Production Dependencies in NPMJasmine Latendresse, Suhaib Mujahid, Diego Elias Costa, Emad ShihabASE 2022 · 17 citations
- Core Developer Turnover in the Rust Package Ecosystem: Prevalence, Impact, and AwarenessMeng Fan, Yuxia Zhang, Klaas-Jan Stol, Hui LiuFSE 2025 · 1 citation
