Assumptions to Evidence: Evaluating Security Practices Adoption and Their Impact on Outcomes in the npm Ecosystem

Published in arxiv, 2025

This paper evaluates how the adoption of software security practices correlates with security outcomes across 145,000 npm packages. Using OpenSSF Scorecard metrics to measure practice adoption, we examine three outcome indicators: vulnerability count, mean time to remediate vulnerabilities (MTTR), and mean time to update dependencies (MTTU). We find that aggregated adoption of security practices is associated with 5.2 fewer vulnerabilities, 216.8 days faster MTTR, and 52.3 days faster MTTU, with repository maturity, maintenance activity, size, contributor count, and download volume moderating this effect.