Skip to content
production / main000%
Technical Audit Platform
DEBT-01RISK MODELSESSION-AWARE / EVIDENCE-FIRST0 EXTERNAL ARTIFACTS

Technical Debt Calculator

Measure debt through change cost and release risk, not line count, and reduce the output to the first three cleanup priorities.

DEBT-01 / OBSERVED EVIDENCE WORKBENCH
SELF + OBSERVED DIMENSIONS + RISK → EFFECTIVE
TEST COVERAGE
SELF 70%
No coverage evidence
OUTDATED DEPS
SELF 5
No update evidence
HOTSPOTS
SELF 3
No churn evidence
EFFECTIVE
48/100
SELF
48/100
OBSERVED Δ
0
EXT. RISK
+0
OBSERVED EVIDENCE / 0

0 OSV · 0 SARIF · SBOM — · COVERAGE — · OUTDATED — · HOTSPOTS —

Coverage, outdated-dependency and git-hotspot evidence replace only their matching self-report dimensions. SBOM is inventory. OSV/SARIF risk pressure remains separate.

Open Evidence Lab →
AC / EVIDENCE REPORT
AC-DEBT-01-20260810100456 · METHOD 3.2-maintenance-evidence

PDF / human · MD / repo · JSON / automation

ANALYSIS SUBJECT
SELF-REPORTED
TARGET NOT PROVIDED
TARGET
Self-report + security + SBOM + coverage + dependency update + git churn evidence
SCOPE
AC Debt Pressure v3.2
EVIDENCE BASIS
SELF-REPORTED
DEBT-01 / EVIDENCE FILE

Technical Debt Calculator

48/100 · self 48/100 · observed 0 · risk +0

EVIDENCE COVERAGE
45/100
CONFIDENCE
LOW
CLAIM BOUNDARY

Self-reported values remain visible. LCOV/Cobertura replaces only testCoverage, npm outdated replaces only outdatedDeps, and git churn hotspot evidence replaces only hotspots. OSV/SARIF risk pressure is added separately. SBOM is inventory; an outdated dependency is not automatically a vulnerability; hotspot classification is not proof of a defect.

01

Executive brief

No OSV/SARIF risk evidence; external risk pressure is +0.
No coverage evidence; test confidence uses the self-reported 70%.
No dependency-update evidence; outdatedDeps uses the self-reported 5.
No git-hotspot evidence; hotspots uses the self-reported 3.
No SBOM inventory is attached.
02

Findings and decision points

F-DEBT-1MEDIUM CONFIDENCE

Deploy friction

+9.6 self-reported pressure

EVIDENCE → E-INPUT-2
F-DEBT-2MEDIUM CONFIDENCE

Change hotspots

+9.0 self-reported pressure

EVIDENCE → E-INPUT-6
F-DEBT-3MEDIUM CONFIDENCE

Test confidence

+8.4 self-reported pressure

EVIDENCE → E-INPUT-1
F-DEBT-4MEDIUM CONFIDENCE

Documentation

+8.0 self-reported pressure

EVIDENCE → E-INPUT-4
F-DEBT-5MEDIUM CONFIDENCE

Dependencies

+7.5 self-reported pressure

EVIDENCE → E-INPUT-5
F-DEBT-6MEDIUM CONFIDENCE

Incident frequency

+5.0 self-reported pressure

EVIDENCE → E-INPUT-3
03

Evidence ledger

E-INPUT-1USER INPUT
testCoverage
70

User-reported operational metric.

CONF LOW
E-INPUT-2USER INPUT
manualDeploySteps
3

User-reported operational metric.

CONF LOW
E-INPUT-3USER INPUT
incidentsPerMonth
1

User-reported operational metric.

CONF LOW
E-INPUT-4USER INPUT
docsCoverage
50

User-reported operational metric.

CONF LOW
E-INPUT-5USER INPUT
outdatedDeps
5

User-reported operational metric.

CONF LOW
E-INPUT-6USER INPUT
hotspots
3

User-reported operational metric.

CONF LOW
04

Method, assumptions and boundaries

ASSUMPTIONS
LIMITATIONS
  • Coverage describes only the files and test execution represented by the report; it does not prove test quality or production correctness.
  • npm outdated reports update state; being outdated alone is not a vulnerability or an automatic upgrade requirement.
  • Git hotspot count is a heuristic for files in the upper quartile of both change frequency and line churn within the imported history window; it is not proof of defects or architectural failure.
  • An SBOM is not a vulnerability scan. DORA and actual code-ownership signals are not yet used in this calculation.
05

Recommended next move

A01Resolve the highest-severity OSV/SARIF findings and largest effective pressure components first.
A02Add LCOV or Cobertura to replace the testCoverage self-report with observed evidence.
A03Add npm outdated --json to replace outdatedDeps self-report with the observed update inventory.
A04Add git churn evidence to replace hotspots self-report with observed repository history.
A05Add a CycloneDX or SPDX SBOM to put the dependency inventory into the evidence chain.
This report is decision support. Observations, derivations, user inputs and heuristics are deliberately separated.
EVIDENCE BRIDGE
OSV · SARIF · CycloneDX · SPDX · npm outdated · Git churn · LCOV · Cobertura

Do not only estimate technical debt; add repository evidence.

OSV/SARIF risks are added as separate observed pressure. LCOV/Cobertura replaces only testCoverage, npm outdated replaces only outdatedDeps, and Git churn hotspot analysis replaces only hotspots. CycloneDX/SPDX is inventory; an outdated dependency is not automatically a vulnerability and a hotspot is not proof of a defect.

Open Evidence Lab
WHEN TO USE IT
  • Measure technical debt beyond TODO counts
  • Connect deployment friction and incidents to change cost
  • Choose the first three areas worth cleaning up
METHOD / INTERPRETATION

What does technical debt mean here?

Debt is less about code looking old and more about how expensive and risky change has become. Test confidence, deployment steps, incidents, documentation, stale dependencies and hotspots act as proxy signals for that operational pressure.

Why only the top three areas?

Trying to clean an entire codebase at once creates another project. The tool surfaces the three highest-pressure areas so refactoring stays bounded, measurable and compatible with product delivery.

BOUNDARY

Without repository history, real test results and production telemetry, this score is not an objective certification of code quality.

If this output needs to become a real technical decision, move it into the FORGE flow.

Open FORGE

AVAILABLE FOR PROJECTS · PRODUCT & SYSTEMS ARCHITECT · TAKEOVER / STABILIZE / OPERATE · WEB · ANDROID · WINDOWS · AHMET CANAL

Contact

Has your product grown faster than its system?

Send the current situation, your biggest blocker and the outcome you want. We will clarify scope together.

Availability

Open to new consulting and project-based work.

GROWTH / SIGNAL LOOP

Move from reading to a decision.

Booking, feedback and system notes in one low-friction exit.

CNV-01

Technical call

If there is a fit, move directly to a 20-minute call.

CNV-02

Decision blocker

Tell me what is still missing with one signal.