# npm Feedback — Abandoned Packages

**Link:** [https://github.com/npm/feedback/discussions/82](https://github.com/npm/feedback/discussions/82)

## Discussion Description

**joshbressers** - 2021-02-18T18:31:07Z

One of the challenges with any ecosystem is what happens when a package is abandoned.

There are many reasons a package might be abandoned. The maintainer might have moved on to other things, they might have passed away, or they might have lost access to their account.

When a package is abandoned, it can become a security risk. If a vulnerability is found in the package, there is no one to fix it. If the package is a dependency for many other packages, it can become a major problem.

What is the current policy for abandoned packages? What are the plans for the future?

## Answer (Chosen by MylesBorins)

**ruyadorno** - 2021-02-23T18:34:52Z

We currently have a [policy for disputes](https://www.npmjs.com/policies/disputes) which covers cases where a maintainer is unresponsive.

We are also looking into ways to better identify abandoned packages and provide more information to users about the status of a package.
