lastseen.deva dated register of software-component continuity

lastseen.dev

Paste a repo, an org, or a package.json. We'll tell you which of your dependencies stopped being maintained — and when we last checked.

no login · no account · free

coverage

595,082 components watched. The daily observation series began 2026-07-29 and grows every day.

MCP servers28,824the full MCP census (2026)npm packages532,036observed · npm is an open registry, no fixed totalGitHub Actions32,761dated observations · 65,289 of 32,760 classifiable from ingested enumeration (ecosyste.ms, 2026-08-03)Docker images1,461endoflife.date product-cycles · Docker Hub has no fixed totallast checked2026-08-03

Known gap: there was no full re-probe on 2026-07-30, so any change of state on that date is bounded to the observations either side of it, not dated to the day itself.

registers

Browse the dated MCP register: 8,388 not-maintained entities (deleted, abandoned, or dormant) across 6,927 owners, observed of the 28,824-entity MCP census. Latest observation 2026-08-03.

methodology

Every reported state is a dated read of the component's public record. The maintenance state is derived from the last public commit on the default branch:

staterule
alivelast commit ≤ 180 days ago
dormantlast commit 180–365 days ago
abandonedlast commit > 365 days ago
archivedthe repository's own archived flag is set
deletedan authoritative HTTP 404
not_observed403 / 429 / timeout / network error — recorded as not-checked

A subject we have not observed is recorded as not-checked — never as gone. Absence of a record is absence of a record, nothing more.

Interval censoring. We assert only the dated reads we actually took. Between two observations we do not guess a state; a gap stays a gap. When a change happens inside an unobserved span, we date it to that span, not to a single day.

What we read. The daily series is a dated read of the public GitHub record; the MCP population was seeded from a public census and re-read the same way. Each row keeps its own source and method. Observations are collected by the Nerq crawl infrastructure.

We publish dated observations, not a composite score and not a prediction.

Verify the supply chain. The lastseen.dev CI Action signs every release with Sigstore — build provenance and an SPDX SBOM, both recorded in the public Rekor transparency log — and pins every action in its own workflows to a full commit SHA, never a mutable tag. Verify a downloaded release with gh attestation verify <file> --owner agentidx. This register can be independently verified, not merely asserted.

about

A free, independent service. No company sits behind it and no account is required to see results. No personal data is processed (privacy). Contact: [email protected]. Operational status.

dispute an observation

To contest an observation, send the component identifier (owner/repo or a package coordinate) and the state you assert, with a public URL showing the current HTTP status and last-commit date, to [email protected]. We re-read the public source and, if it differs, issue a dated correction, shown on the component's page. Target response: 5 business days. Full process: dispute.