Skip to main content
Methodology v1.3 · Validated on 505 authorized sites

How we grade
your website.

Full transparency on how your A-F security grade is calculated. No black box, no hidden weights. Everything on this page is how the real scanner works.

THE FORMULA

score = 100
  - (Critical × 25)
  - (High     × 8)
  - (Medium   × 3)
  - (Low      × 1)
  + bonuses (max +4)

HARD CAPS (applied last, no bonus can bypass):
  Critical found      → F
  Cloaking/Ghost page → F
  Unassessed core check → max C
  Any scan            → max 99
  (100/100 never awarded. No scanner can prove it.)

DEEP SCAN PERK:
  Paid public reports that pass Green Light can activate UNPWNED VERIFIED.
  Verified-domain deep scans can activate UNPWNED DEEP VERIFIED.

7 Core Evidence Surfaces

These are the primary surfaces the scanner observes. Categories organize the report; the score deduction comes from each finding's severity in the formula above, not from a hidden category multiplier. For the individual checks inside each surface, see the full check list.

01

Secrets & Credentials

Exposed API keys, database credentials, .env files, and source maps.

02

Browser Security Controls

CSP, HSTS, X-Frame-Options, cookies, and CORS.

03

SSL/TLS Configuration

Certificate validity, protocol support, and externally observable TLS posture.

04

Authentication & APIs

Open API routes, anonymous data access, and authorization evidence.

05

DNS & Email Security

SPF, DMARC, DNSSEC, and positively observed DKIM records.

06

Database & Storage Exposure

Supabase/Firebase access, sensitive files, and verified cloud-storage evidence.

07

Dependencies & CVEs

Version-linked vulnerabilities supported by observed software evidence and NVD/OSV data.

Grade Scale

A+95-99 + 2 bonuses · no medium/high/critical

Excellent. You went beyond the basics.

A88-99 when A+ requirements are not met

Strong. No critical issues, hygiene mostly clean.

B78-87

Good. A few minor gaps to address.

C65-77

Acceptable. Several issues worth fixing.

D50-64

Weak. Multiple meaningful issues.

F<50 or critical/cloaking

Failing. Critical risks present.

Bonuses: What Earns A+

A+ is not automatic. You need a score of 95+, at least 2 of these bonuses, and zero medium, high, or critical findings. Each bonus gives +1 (max +4). We only count bonuses backed by observed evidence.

HSTS Header
Forces browsers to HTTPS.
Strict CSP
Content Security Policy with strict-dynamic or nonce.
Rate Limiting
Detected on API endpoints or forms.
WAF Detected
Backed by a dedicated WAF-provider signal from a completed technology check. A blocked scanner never earns this bonus.

Evidence-Aware Scoring

Platform and organization detection adds context to the report, but it never changes the severity weight of observed evidence. A known brand and an unknown domain receive the same score for the same findings.

Blocked = Unknown Coverage. A blocked check never earns points and is never treated as clean. Effective coverage gives full weight to completed checks and partial weight to inconclusive evidence. A numeric partial result requires at least 50% effective coverage plus at least one authoritative completed check, and never receives a full-site grade.
Platform Detection. Hosting, CDN, framework, and AI-builder signals carry source, evidence, and confidence so weak text matches cannot become trusted fingerprints.
No Brand Exemptions. Platform context improves remediation guidance, not the score math. Findings are weighted from evidence and exploitability.

Official score + grade

At least 80% effective coverage and every core security surface completed.

Partial result

At least 50% effective coverage and one authoritative completed check, but the official threshold or a core security surface is missing. The number scores completed checks only; no full-site grade, benchmark, or badge is issued.

Insufficient coverage

Below 50% effective coverage, or when no authoritative check completed, UNPWNED shows no numeric result. Confirmed findings remain visible.

A partial 100/100 means every completed check passed. It does not mean the whole site received a perfect security score.

Surface Scan vs. Verified Deep Scan

First scan · Free

Surface Scan

Highest possible grade
A+(up to 99)

Outside-in requests against the public attack surface, without credentials or internal access. The 800 figure is the full-suite total; a standard surface scan runs the 22 surface scanners, which is 430 of those checks. See the full list.

430 checks · 2 minutes
Paid · Verified

Deep Scan

Highest possible grade
A+(up to 99)Deep Verified

Requires domain ownership verification. Same score range as surface scan, but a paid public report that passes Green Light can activate the UNPWNED DEEP VERIFIED badge. Unlocks cloaking detection, ghost page sampling, deep CORS, and HTTP method fuzzing. Higher risk of finding issues, but a high score here is more prestigious.

All surface checks + deep inspection

An outside-in scan cannot prove the absence of every vulnerability, so UNPWNED never awards 100/100. A verified deep scan provides broader evidence because it can safely run additional checks.

First Scan vs. Fix Verification

A grade only tells you where you stand today. The real question is whether your fix actually worked. That is the difference between the first scan and fix verification.

First scan · Free

The What

The first scan of a domain shows the severity breakdown and all finding titles, plus a score and grade when coverage supports an official result. It tells you what is wrong, point-in-time.

Paid

Verify Your Fix Worked

Re-scan a domain you already scanned and get a before/after comparison of score, grade, and findings, so you can confirm a fix actually landed. Re-scanning a previously scanned domain and the before/after diff are paid features.

Data Sources

Direct

Live Observations

  • → HTTP response analysis
  • → DNS queries
  • → SSL handshake inspection
  • → Content & secret regex
  • → Sitemap cloaking analysis
NVD + OSV

Version Intelligence

  • → NVD / CVE Database
  • → OSV (Google Open-Source Vulns)
  • → Only version-linked matches backed by observed fingerprints

What We Don't Score

Some things matter but aren't security per se. We show them separately. They never drag down your grade.

Privacy Policy presence. This is legal compliance, not security. Tracked under Compliance Checks.
Cookie consent banners. GDPR/CCPA compliance, not attack surface.
SEO quality. Not our scope.

Version History

v1.3
July 2026. Evidence-first accuracy
Removed brand-based score normalization and per-blocked-scanner bonuses. Partial scans now separate the completed-check result from effective coverage and confidence; numeric partial results require at least 50% effective coverage and one authoritative completed check, while official grades require at least 80% and complete core surfaces.
v1.2
June 2026. A+ and coverage calibration
A+ now requires no medium, high, or critical security findings. Coverage is calibrated to 22 surface scanners, 33 deep scanners, or 34 for owner-verified deep scans that include path-traversal testing.
v1.1
May 2026. Developer-friendly rebalance
Severity weights softened (high 10→8, medium 5→3, low 2→1) so common hygiene gaps don't tank typical small-SaaS sites. Critical raised 20→25 and hard caps now run last (no bonus can bypass an F). Grade thresholds lowered to match the new distribution. A+ required 2+ bonuses and no high/critical findings.
v1.0
April 2026. Initial public methodology
7-category weighted system, A-F grading, infrastructure-aware scoring, surface/deep split.

See your grade

Scan any website in a couple of minutes. No credit card required.