depexpira audits days-since-last-release for every package you depend on and flags abandoned ones against a policy you control — before they become an incident.
$ depexpira audit • Auditing 5 dependencies against https://registry.npmjs.org Depexpira freshness report — 5 dependencies · 2026-08-22T08:02:21.822Z package dep wanted latest age status -- --------- ---- ------ ------ ----- --------- ☠ left-pad prod ^1.3.0 1.3.0 3057d abandoned ☠ ms prod ^2.1.3 2.1.3 2082d abandoned ☠ node-uuid dev ^1.4.8 1.4.8 3440d abandoned ok chalk prod ^5.3.0 6.0.0 26d fresh ok semver prod ^7.6.0 7.8.5 63d fresh summary: 2 fresh · 0 aging · 0 stale · 3 abandoned · 0 unknown • worst status: abandoned
Known CVEs get tooling. Quiet abandonment doesn't. Depexpira fixes that in one command.
Every dependency gets a concrete age: days since its last registry release. Resolved versions come straight from your lockfile.
Set warn / stale / abandoned thresholds to match your risk appetite. Ignore the "done by design" packages explicitly.
depexpira audit --fail-on stale exits non-zero when anything crosses the line. Wire it into publish flows.
The freshness auditor cannot itself go stale: no runtime dependencies, Node 18+ built-ins only, offline test suite.
Three thresholds. Move them in depexpira.config.json.
| Status | Meaning | Threshold |
|---|---|---|
| fresh | Released recently — nothing to do | < 365 days |
| aging | Worth watching at your next upgrade pass | ≥ 365 days |
| stale | Likely unmaintained — plan a replacement | ≥ 730 days |
| abandoned | Treat as supply-chain risk | ≥ 1095 days |
No config required. Run it inside any project with a package.json.
$ npm install --global depexpira $ cd your-project $ depexpira audit # commit-friendly report → DEP-FRESHNESS.md $ depexpira audit --format md --write # CI gate $ depexpira audit --fail-on stale && npm publish
Scheduled audits across all your repositories, alerting when a dependency crosses a policy line, org-wide policy-as-code, and dashboard-ready JSON history.
License via Gumroad — link placeholder.
Get Pro