This paper proposes a strategy for quantitatively identifying the most important open source software (OSS) projects among the millions managed by language-level package managers and, of those, identifying the ones most needing security-related investments.