i clicked on the "only free tools", but this is an interesting idea. how are you planning to implement it? a tool that scans our git, hg, svn and cvs repos and tells us what we have would be quite interesting (although there's the obvious hurdle of trusting third party code enough to ever run it).
i work for a small consultancy that builds bespoke solutions using open source code - we have loads of projects, some ancient (cvs!), and i am sure no-one has a clue what versions of what we used when (sure, it's documented for the client, but we don't have our own central list). now perhaps we should be better organised, but i suspect many other companies are in a similar position.
but if we were going to pay for this, how would it help us make money? is the idea that we can approach ex-clients and scare them with lists of security holes? or are they the target clients - perhaps they should be running this code to audit their systems? and that sounds so useful i am surprised that nothing like this already exists...?