Do we need that type of metric anyways? Surely there are better ways to measure a repo's activity...
There is an opportunity here for a third party to do this well.
Ones that care enough already have their internal tools and processes for security and checking/reviewing libraries.
Ones that don’t care well won’t spend money on it.
So any 3rd party would have to do all with own resources and not getting paid.