The NPM Dilemma: Too Many Packages or Too Few Standards?

  • Tech Stack: Python, PyDriller, Synk API, Selenium, BeautifulSoup, Statistical tests (MWU, chi-square, etc)
  • Github URL: Project Link

Extracted metadata from package.json via NPM Registry API & Git stats from Pydriller for analyzing 70k packages.

Established a classification framework leveraging code & activity metrics, applying statistical tests (MWU, chi-square) to uncover crucial predictors for vulnerability metrics, empowering developers with actionable security insights.