"Solution, keep it in house, audit all third party code and stop being a muppet (yes you so called IT experts out there)"

I wish I was obscenely rich too!

Although, if I was, would I be wasting my life in IT?)

Code needs to be 'fit for purpose'. If the 'purpose' is e.g. a website to advertise a product that will earn your company £50K p.a. you can't afford code audits of JQuery, Ruby or whatever the current flavour of the month is. If you insist on the audit, we'll either go bust or we'll forget the 3rd party stuff and dig out the old copy of Dreamweaver and hand code it in plain HTML.

Other than taking extreme care of sensitive data, there's no perfect solution.

