github.com/Risk-Guard/public-test — Feb 25, 2026
This SBOM introduces $2.3M in incremental annual engineering overhead above industry baseline, bringing total adjusted overhead to $4.8M (9.5% of target revenue). The primary driver is a 3.2× maintenance burden from unmaintained dependencies.
5 critical packages require immediate review. Dependency failure probability is 2.7× peer average. Security breach exposure is favorable at 3.1× below comparable companies.
Asset identity and company profile
Cost Model
Adjust assumptionsEvery company running open source carries these costs
Calculated from this company's profile: 50 developers × $150K fully-loaded, $50,000,000 revenue, 100,000 customer records, United States.
Incidents
Low-probability, high-impact events. You don't budget for these — you price the exposure.
Engineering Drag
of $7,500,000 engineering budget
Ongoing overhead. Time your developers spend maintaining dependencies instead of building product.
EAL = Expected Annual Loss (probability × per-incident cost). Developer costs assume $150,000/yr fully-loaded.
Expected costs based on scan results vs. industry average for this company profile
| Category | Baseline | Drag | Adjusted | Delta |
|---|---|---|---|---|
| Maintenance Burden | $945,000 | 3.2× | $3,061,261 | +$2,116,261 |
| Security Patches | $1,425,000 | 1.1× | $1,609,612 | +$184,612 |
| License Remediation | $42,550 | 2.1× | $89,045 | +$46,495 |
| Total | $2,412,550 | $4,759,918 | +$2,347,368 |
| Incident Type | Per-Incident Cost | Baseline Prob. | Adjusted Prob. | EAL |
|---|---|---|---|---|
| Security Breach | $10,220,000 | 80.0% | 26.0% | $2,656,865 |
| Dependency Failure | $75,000 | 12.0% | 32.1% | $24,045 |
| IP Litigation | $1,000,000 | 6.0% | 8.2% | $82,124 |
EAL = Expected Annual Loss (probability × per-incident cost). Baseline assumes industry average for this company profile.
Critical findings driving the numbers above
| Check | Packages | Detail |
|---|---|---|
| SOURCE_NO_LICENSE | 4 | Without a license, the code is under exclusive copyright by default, making any use potentially infringing importlib-metadata · rdoc · zipp · minitest |
| PACKAGE_NAME_MISMATCH | 1 | A name mismatch between published package and source repository enables package impersonation or substitution attacks. f-ask |
Full findings table (380 findings across 211 packages) available in the appendix.
380 findings across 211 packages