Benchmarks ecosystem-wide security adoption and exposes critical blind spots in automated security metrics for empty or ephemeral repositories.
An evaluation of the OpenSSF Scorecard tool across npm and PyPI found that 13 of its 18 metrics map directly to NIST SSDF practices, but adoption across ecosystems is low: only 3.2% of npm packages have a `SECURITY.md` file, and 90% have branch protection disabled. The study identified significant blind spots in automated security tools, which frequently give 'false confidence' scores of 10/10 to empty repositories or those missing GitHub workflows. Most critically, the research found that 74.5% of malware packages were authored by accounts that published only one package, suggesting that ephemeral projects are a more common threat vector than the compromise of established maintainer accounts. Furthermore, 86% of npm packages were determined to be unmaintained based on 90-day activity windows, posing a systemic risk of unpatched vulnerabilities.
The research found that 'Dangerous Workflow' patterns identified by Scorecard are directly exploitable for reverse shell attacks and malicious code injection.
compromise of CI/CD runners and exfiltration of repository credentials through vulnerable GitHub Actions
identifying dangerous workflow patterns is an effective proactive measure for detecting potential malicious delivery vectors in the supply chain.
The study confirms that 86% of npm packages are unmaintained, with a high correlation to unpatched code and insecure dependencies.
dependency on stagnant libraries that lack a responsive team to address newly discovered security flaws
90-day activity monitoring is a proven high-fidelity signal for maintenance neglect in fast-moving package ecosystems.
Scorecard reports a score of 10 for Dangerous-Workflow... in empty repositories because the repositories did not have any GitHub workflows... tool lacks the verification of GitHub workflow's existence.
Risk Guard may give 'Perfect' scores for missing features (like workflows or CI) rather than penalizing their absence as a lack of security maturity.
Risk Guard would be better if it distinguished between 'Feature Passing' and 'Feature Missing', ensuring that absent security controls result in a penalty rather than a default pass.