Skip to main content
Press releasePublished

Vibgrate publishes open methodology for measuring software drift and risk

Vibgrate has published the data sources, scoring factors, formulas, and limitations behind DriftScore, RiskScore, and DriftRisk™. The methodology is available under CC BY 4.0 and permanently archived on Zenodo.

Software teams are often asked to act on scores they cannot inspect. When a score can block a release, prioritize an upgrade, or support an audit response, an unexplained number becomes a liability.

Vibgrate has published the methodology behind DriftScore, its measure of maintainability drift; RiskScore, its measure of current security exposure; and DriftRisk™, the combined view.

The open-access paper documents the scoring factors, data sources, formulas, evidence hierarchy, and 25 primary references behind the measures. It also identifies the calibration weights derived from Vibgrate scan data that remain proprietary. Teams can inspect and challenge the published method rather than take the scores on trust.

The software risk and drift scoring methodology whitepaper was first published on July 10, 2026, and archived on Zenodo on July 13, 2026. It is free to read without signing up, available in HTML and PDF, and licensed under CC BY 4.0. The concept DOI identifies the evolving work, while each archived release has its own version-specific DOI for precise citation.

The source document is also maintained in the open-source Vibgrate CLI repository, where its revision history can be inspected and compared.

Teams can test the published method by running the Vibgrate CLI against their own repositories and comparing the reported factors and scores with the definitions and formulas in the paper.

A drift score only matters if the method holds up to scrutiny. By publishing the sources, formulas, and limitations, we give teams a way to examine the results before relying on them.
Peter ChapmanFounder, Vibgrate

Facts and primary sources

  • The methodology is openly archived on Zenodo (published July 10, 2026; deposited July 13, 2026). The evolving work has concept DOI 10.5281/zenodo.21336304, the deposited version has version DOI 10.5281/zenodo.21336305, and the work is licensed under CC BY 4.0. Use the version-specific DOI when citing a particular release. View the methodology on Zenodo
  • The source document is maintained in the open-source Vibgrate CLI repository. Its revision history can be inspected and compared publicly. View the published methodology on GitHub

About Vibgrate

Vibgrate is a software intelligence platform that helps teams find aging dependencies, assess security exposure, and plan modernization. Its free CLI maps codebases and produces DriftScore, a transparent measure of dependency, framework, and runtime drift. Vibgrate Cloud adds portfolio visibility, governance workflows, and verifiable evidence for security and regulatory decisions. Vibgrate Evidence preserves version-specific component and release records so teams can reproduce historical exposure findings. Vibgrate AI Context gives coding agents version-matched documentation and precise repository context while reducing unnecessary token use. Vibgrate publishes its scoring methodology openly, allowing researchers to inspect the evidence, assumptions, and formulas behind its results.

25-word boilerplate

Vibgrate helps software teams find aging dependencies, assess security exposure, and plan modernization using verifiable evidence produced by its free code-scanning CLI and cloud platform.

50-word boilerplate

Vibgrate is a code drift intelligence platform for software teams. Its free CLI maps a codebase and identifies drift across dependencies, frameworks, and runtimes. Vibgrate Cloud turns the same scan data into portfolio visibility, governance workflows, security prioritization, and verifiable evidence for modernization decisions, regulatory reporting, and ongoing software assurance.

Press inquiries

Peter Chapman, Founder · press@vibgrate.com