International Journal For Multidisciplinary Research
E-ISSN: 2582-2160
•
Impact Factor: 9.24
A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal
Home
Research Paper
Submit Research Paper
Publication Guidelines
Publication Charges
Upload Documents
Track Status / Pay Fees / Download Publication Certi.
Editors & Reviewers
View All
Join as a Reviewer
Get Membership Certificate
Current Issue
Publication Archive
Conference
Publishing Conf. with IJFMR
Upcoming Conference(s) ↓
Conferences Published ↓
IC-AIRCM-T3-2026
SPHERE-2025
AIMAR-2025
SVGASCA-2025
ICCE-2025
Chinai-2023
PIPRDA-2023
ICMRS'23
Contact Us
Plagiarism is checked by the leading plagiarism checker
Call for Paper
Volume 8 Issue 2
March-April 2026
Indexing Partners
Weak Links in the Chain: A Quantitative Analysis of Security Flaws in Open Source Projects
| Author(s) | Ms. Sakshi Bhardwaj, Ms. soumya bhardwaj, Prof. Dr. Nitish Kumar |
|---|---|
| Country | India |
| Abstract | This paper presents a quantitative analysis of security vulnerabilities in open-source projects, leveraging large-scale datasets to examine their prevalence, typology, and broader implications. By analysing diverse projects and their dependency structures, we identify recurring weaknesses and assess the effectiveness of detection and mitigation strategies. Our study integrates static application security testing and software composition analysis to capture both inherent code flaws and supply chain risks, while also considering theoretical perspectives from complexity theory and undecidability in assessing vulnerability management. Furthermore, we investigate the impact of project abandonment on long-term security, demonstrating a correlation between maintenance cessation and the persistence of unresolved vulnerabilities. The findings provide actionable insights for developers, maintainers, and security professionals, highlighting best practices for embedding security throughout the software development lifecycle and underscoring the importance of continuous monitoring and proactive risk management in strengthening the resilience of open-source ecosystems. |
| Keywords | Open-source software security; Vulnerability analysis; Software supply chain risks; Dependency management; Secure software development lifecycle |
| Field | Engineering |
| Published In | Volume 7, Issue 5, September-October 2025 |
| Published On | 2025-10-18 |
| DOI | https://doi.org/10.36948/ijfmr.2025.v07i05.57871 |
Share this

E-ISSN 2582-2160
CrossRef DOI is assigned to each research paper published in our journal.
IJFMR DOI prefix is
10.36948/ijfmr
Downloads
All research papers published on this website are licensed under Creative Commons Attribution-ShareAlike 4.0 International License, and all rights belong to their respective authors/researchers.
Powered by Sky Research Publication and Journals