Securing the Open Frontier: A Bibliometric and Thematic Analysis of Research on Open-Source Enterprise Resource Planning (ERP) Software Security
DOI:
https://doi.org/10.59461/ijitra.v5i3.240Keywords:
Open-Source software; enterprise resource planning; ERP security, bibliometric analysis, thematic analysis, software security engineering.Abstract
Open-Source enterprise resource planning (ERP) systems provide organizations with flexible, customizable and potentially cost-effective alternatives to proprietary ERP platforms. However, their increasing deployment in mission-critical organizational environments introduces significant security challenges involving authentication, authorization, software vulnerabilities, privacy, configuration, maintenance, governance and third-party components. In addition, their community-driven development model, exposed source code, and heterogeneous deployment environments raise distinctive risk management concerns that remain fragmented across the literature. This study conducted a bibliometric and thematic analysis of the research landscape on OS-ERP security, drawing on a curated Scopus-derived citation corpus (n = 40 documents, 2007–2026) retrieved through Harzing’s Publish or Perish. After deduplication and relevance screening, documents were classified into nine thematic clusters spanning security and access control, resilience and cloud infrastructure, adoption and risk, ERP selection methods, implementation case studies, and architectural transformation. Descriptive bibliometrics including annual output, document type, citation impact, and lead-author productivity were computed, and thematic co-occurrence in titles was used to trace the field’s intellectual structure and evolution across four time period. Results show that security-specific scholarship (17.5% of the corpus) remains a minority relative to adoption and implementation studies (over half of the corpus), that citation impact is concentrated in a small set of foundational access-control and risk papers, and that thematic emphasis has shifted since 2019 toward multi-criteria selection methods and architectural modernization (microservices, IoT integration) rather than deep security engineering. The discussion situates these findings against the broader open-source software (OSS) security literature and identifies a persistent gap between the demonstrated adoption benefits of OS-ERP and the comparatively immature body of empirical security research addressing it. The paper concludes with recommendations for practitioners, researchers, and OS-ERP community maintainers, and proposes a future research agenda centred on empirical security benchmarking, secure-by-design ERP architectures, and longitudinal vulnerability studies.
Published
Issue
Section
License
Copyright (c) 2026 Dr. Wanjiru Njuki, Dr. Stephen Kahara Wanjau

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.