This is one of the most common and damaging mistakes I see. Here are some other hidden costs that are often invisible to people:
1. The cost of understanding the 3rd party solution, which increases with the generality of the tool. That is, you are using a tool which solves A, B, C, and D to solve A. Using a well-documented tool helps here, but doesn't eliminate the problem.
2. The cost of upgrades, especially when forced by a security issue.
3. Framework vs library costs. It usually much less costly to import pure functions (think: an assertion library) versus importing a framework which forces a bespoke way of doing things (think: rspec).