Software teams are often asked to act on scores they cannot inspect. When a score can block a release, prioritize an upgrade, or support an audit response, an unexplained number becomes a liability.
Vibgrate has published the methodology behind DriftScore, its measure of maintainability drift; RiskScore, its measure of current security exposure; and DriftRisk™, the combined view.
The open-access paper documents the scoring factors, data sources, formulas, evidence hierarchy, and 25 primary references behind the measures. It also identifies the calibration weights derived from Vibgrate scan data that remain proprietary. Teams can inspect and challenge the published method rather than take the scores on trust.
The software risk and drift scoring methodology whitepaper was first published on July 10, 2026, and archived on Zenodo on July 13, 2026. It is free to read without signing up, available in HTML and PDF, and licensed under CC BY 4.0. The concept DOI identifies the evolving work, while each archived release has its own version-specific DOI for precise citation.
The source document is also maintained in the open-source Vibgrate CLI repository, where its revision history can be inspected and compared.
Teams can test the published method by running the Vibgrate CLI against their own repositories and comparing the reported factors and scores with the definitions and formulas in the paper.