If we had a vuln threat intelligence feed, we could also give a score to applications/frameworks, like if a framework or library or some piece of tech has a high amount of outstanding CVEs or historical CVEs, we could give the project a risk score assignment.
https://vulncheck.com