MALTA: Maintenance-Aware Technical Lag, Estimation to Address Software Abandonment
Shane K. Panter, Nasir U. Eisty

TL;DR
This paper introduces MALTA, a new framework with maintenance-aware metrics that better identify abandoned or high-risk open-source packages, addressing limitations of existing Version Lag metrics.
Contribution
MALTA provides a novel scoring framework with three metrics that improve detection of abandoned packages compared to traditional Version Lag measures.
Findings
MALTA achieves an AUC of 0.783 in classifying maintenance status.
62.2% of packages deemed low risk by Version Lag are reclassified as high risk by MALTA.
Most discordant packages have been inactive for over 2019 days, with some repositories archived.
Abstract
Context: Open-source ecosystems rely on sustained package maintenance. When maintenance slows or stops, Technical Lag (TL), the gap between installed and latest dependency versions accumulates, creating security and sustainability risks. However, some existing TL metrics, such as Version Lag, struggle to distinguish between actively maintained and abandoned packages, leading to a systematic underestimation of risk. Objective: We investigate the relationship between Version Lag and software abandonment by (i) identifying which repository-level signals reliably distinguish sustained maintenance from long-term decline, (ii) quantifying how Version Lag magnitude and persistence differ across maintenance states, and (iii) evaluating how maintenance-aware metrics change the identification of high-risk dependencies. Method: We introduce Maintenance-Aware Lag and Technical Abandonment (MALTA),…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware Engineering Research · Software System Performance and Reliability · Software Reliability and Analysis Research
