How we grade
your website.
Full transparency on how your A-F security grade is calculated. No black box, no hidden weights. Everything on this page is how the real scanner works.
THE FORMULA
score = 100 - (Critical × 25) - (High × 8) - (Medium × 3) - (Low × 1) + bonuses (max +4) HARD CAPS (applied last, no bonus can bypass): Critical found → F Cloaking/Ghost page → F Unassessed core check → max C Any scan → max 99 (100/100 never awarded. No scanner can prove it.) DEEP SCAN PERK: Paid public reports that pass Green Light can activate UNPWNED VERIFIED. Verified-domain deep scans can activate UNPWNED DEEP VERIFIED.
7 Core Evidence Surfaces
These are the primary surfaces the scanner observes. Categories organize the report; the score deduction comes from each finding's severity in the formula above, not from a hidden category multiplier. For the individual checks inside each surface, see the full check list.
Secrets & Credentials
Exposed API keys, database credentials, .env files, and source maps.
Browser Security Controls
CSP, HSTS, X-Frame-Options, cookies, and CORS.
SSL/TLS Configuration
Certificate validity, protocol support, and externally observable TLS posture.
Authentication & APIs
Open API routes, anonymous data access, and authorization evidence.
DNS & Email Security
SPF, DMARC, DNSSEC, and positively observed DKIM records.
Database & Storage Exposure
Supabase/Firebase access, sensitive files, and verified cloud-storage evidence.
Dependencies & CVEs
Version-linked vulnerabilities supported by observed software evidence and NVD/OSV data.
Grade Scale
Excellent. You went beyond the basics.
Strong. No critical issues, hygiene mostly clean.
Good. A few minor gaps to address.
Acceptable. Several issues worth fixing.
Weak. Multiple meaningful issues.
Failing. Critical risks present.
Bonuses: What Earns A+
A+ is not automatic. You need a score of 95+, at least 2 of these bonuses, and zero medium, high, or critical findings. Each bonus gives +1 (max +4). We only count bonuses backed by observed evidence.
Evidence-Aware Scoring
Platform and organization detection adds context to the report, but it never changes the severity weight of observed evidence. A known brand and an unknown domain receive the same score for the same findings.
Official score + grade
At least 80% effective coverage and every core security surface completed.
Partial result
At least 50% effective coverage and one authoritative completed check, but the official threshold or a core security surface is missing. The number scores completed checks only; no full-site grade, benchmark, or badge is issued.
Insufficient coverage
Below 50% effective coverage, or when no authoritative check completed, UNPWNED shows no numeric result. Confirmed findings remain visible.
A partial 100/100 means every completed check passed. It does not mean the whole site received a perfect security score.
Surface Scan vs. Verified Deep Scan
Surface Scan
Outside-in requests against the public attack surface, without credentials or internal access. The 800 figure is the full-suite total; a standard surface scan runs the 22 surface scanners, which is 430 of those checks. See the full list.
Deep Scan
Requires domain ownership verification. Same score range as surface scan, but a paid public report that passes Green Light can activate the UNPWNED DEEP VERIFIED badge. Unlocks cloaking detection, ghost page sampling, deep CORS, and HTTP method fuzzing. Higher risk of finding issues, but a high score here is more prestigious.
An outside-in scan cannot prove the absence of every vulnerability, so UNPWNED never awards 100/100. A verified deep scan provides broader evidence because it can safely run additional checks.
First Scan vs. Fix Verification
A grade only tells you where you stand today. The real question is whether your fix actually worked. That is the difference between the first scan and fix verification.
The What
The first scan of a domain shows the severity breakdown and all finding titles, plus a score and grade when coverage supports an official result. It tells you what is wrong, point-in-time.
Verify Your Fix Worked
Re-scan a domain you already scanned and get a before/after comparison of score, grade, and findings, so you can confirm a fix actually landed. Re-scanning a previously scanned domain and the before/after diff are paid features.
Data Sources
Live Observations
- → HTTP response analysis
- → DNS queries
- → SSL handshake inspection
- → Content & secret regex
- → Sitemap cloaking analysis
Version Intelligence
- → NVD / CVE Database
- → OSV (Google Open-Source Vulns)
- → Only version-linked matches backed by observed fingerprints
What We Don't Score
Some things matter but aren't security per se. We show them separately. They never drag down your grade.
Version History
See your grade
Scan any website in a couple of minutes. No credit card required.
