In this paper, we perform a thorough empirical study to investigate the predictive power of text mining based models and software metrics based models in the context of effort- aware software vulnerability prediction. Our results show that text mining based models are only slightly better than or similar to software metrics based models in the context of effort-aware vulnerability prediction. Furthermore, in most