DefaultRank report · 2026-10-02
AI writes code for last year's stack
We took the package.json of 209 apps that 6 AI models built for us, and checked every dependency against the npm registry on 2026-10-02. Almost every app starts life with something out of date.
Every app ships something old
209 of 209 AI-built apps install at least one package that is a major version or more behind npm's latest.
Of an app's dependencies are behind
On average, 69% of the dependencies in an AI-built app are at least one major version behind (judged where a version could be compared).
of Next.js apps start below v16
Next.js 16 is the latest major. The versions AI models actually pinned: 16.x (latest): 1 · 15.x: 43 · 14.x: 68.
The freshest and stalest model
gpt-6.1-sol puts 50% of its dependencies on the latest major; claude-sonnet-5.5 manages 23%.
Packages AI installs out of date
Packages used by at least 10 AI-built apps, sorted by how many apps pinned an older major.
| Package | Apps | Majors the models pinned | Latest | Behind |
|---|---|---|---|---|
typescript | 209 | 5.x: 209 | 7.0.2 | 100% |
zod | 156 | 4.x (latest): 1 · 3.x: 155 | 4.6.5 | 99% |
next | 112 | 16.x (latest): 1 · 15.x: 43 · 14.x: 68 | 16.3.8 | 99% |
@prisma/client | 98 | 6.x: 35 · 5.x: 63 | 7.10.0 | 100% |
@types/react | 130 | 19.x (latest): 46 · 18.x: 84 | 19.3.0 | 65% |
@types/react-dom | 128 | 19.x (latest): 44 · 18.x: 84 | 19.3.0 | 66% |
react | 129 | 19.x (latest): 46 · 18.x: 83 | 19.3.0 | 64% |
react-dom | 129 | 19.x (latest): 46 · 18.x: 83 | 19.3.0 | 64% |
express | 89 | 5.x (latest): 7 · 4.x: 82 | 5.2.1 | 92% |
@types/bcryptjs | 72 | 3.x (latest): 1 · 2.x: 71 | 3.0.0 | 99% |
resend | 69 | 4.x: 52 · 3.x: 17 | 6.32.0 | 100% |
bcryptjs | 80 | 3.x (latest): 12 · 2.x: 68 | 3.0.3 | 85% |
@types/express | 89 | 5.x (latest): 28 · 4.x: 61 | 5.0.6 | 69% |
dotenv | 56 | 16.x: 56 | 18.0.5 | 100% |
stripe | 53 | 18.x: 5 · 17.x: 25 · 16.x: 11 · 15.x: 11 · 14.x: 1 | 23.0.0 | 100% |
Which model writes the freshest dependencies
Share of each model's dependencies on npm's latest major version.
Deprecated packages
39% of AI-built apps include a package that npm marks as deprecated, but these are mostly harmless: type-definition stubs for libraries that now ship their own types, or modules that became part of Node itself.
@types/bcryptjs(72 apps): This is a stub types definition. bcryptjs provides its own type definitions, so you do not need this installed.@types/uuid(16 apps): This is a stub types definition. uuid provides its own type definitions, so you do not need this installed.crypto(1 app): This package is no longer supported. It's now a built-in Node module. If you've depended on crypto, you should switch to the one that's buil
How to read this
- “Behind” means the version range the model wrote starts at a lower major version than npm's
latesttag on 2026-10-02. A newer major isn't always the right choice (for example when a framework hasn't caught up), but it's the default a new project would get. - Packages whose
latesttag is a pre-release, and ranges likelatestor*, are not judged. Neither is@types/node, which tracks the Node.js version you run, not npm's newest. - Apps come from 7 build prompts run 5 times per model with low reasoning effort, on 2026-10-01. Coding agents that look up current docs may do better.
Full prompts and models: methodology. Aggregated data: freshness.json.
Is your package.json out of date?
Paste it into the free checker. It runs in your browser and only asks the public npm registry about package names.