The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
cs.SE, cs.CR
Submitted: 2025-02-23
Updated: 2026-09-01
Comments: Resubmitted
Code: https://github.com/ossf/alpha-omega
License: http://creativecommons.org/licenses/by-nc-nd/4.0/
The gist: There has been a long-standing hypothesis that a software's popularity is related to its security or insecurity in both research and popular discourse.
Terminology
Abstract
There has been a long-standing hypothesis that a software's popularity is related to its security or insecurity in both research and popular discourse. There are also a few empirical studies that have examined the hypothesis, either explicitly or implicitly. The present work continues with and contributes to this research with a replication-motivated large-scale analysis of software written in the PHP programming language. Two datasets are used: the first contains nearly four hundred thousand open source software packages written in PHP and the second addresses over six thousand WordPress components. According to the results based on vulnerabilities reported, the hypothesis holds: packages having seen reported vulnerabilities over their release histories are generally more popular than packages for which fewer or no vulnerabilities have been reported. With this replication results, the paper contributes to the efforts to strengthen the empirical knowledge basis in cyber and software security. In addition, the paper makes a contribution to the recent discussion on the terminology about software vulnerabilities and the associated construct validity problems that follow.
Sources
- An Overview of Cyber Security Funding for Open Source Software
- Over 100 Bugs in a Row: Security Analysis of the Top-Rated Joomla Extensions
- A Time Series Analysis of Malware Uploads to Programming Language Ecosystems
- Security Issues in Language-based Software Ecosystems
- A Consequentialist Critique of Binary Classification Evaluation: Theory, Practice, and Tools
- Six Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware
Related papers
- Falsification-Based Verification of LLM-Generated Optimization Models: Sound Test Batteries and Their Detection Limits
- GitSkills: A Dataset of Agent Skills on GitHub
- SABER: Benchmarking Operational Safety of LLM Coding Agents in Stateful Project Workspaces
- PackMonitor: Enabling Zero Package Hallucinations Through Decoding-Time Monitoring
- IntentCoding: Amplifying User Intent in Code Generation
- Incentives and Outcomes in Bug Bounties