Abstract In recent years, the widespread applications of open-source software (OSS) have brought great convenience for developers. However, it is always facing unavoidable security risks, such as code defects and vulnerabilities. To find out OSS risks in time, we carry an empirical study to identify indicators evaluating OSS. achieve a comprehensive understanding assessment, collect 56 papers f...