Skip to main content
UNPWNED
Methodology v1.3 · Validated on 525 authorized sites

How we grade
your website.

Full transparency on how your A-F security grade is calculated. No black box, no hidden weights. Everything on this page is how the real scanner works.

THE FORMULA

score = 100
  - (Critical × 25)
  - (High     × 8)
  - (Medium   × 3)
  - (Low      × 1)
  + bonuses (max +4)

HARD CAPS (applied last, no bonus can bypass):
  Critical found      → F
  Cloaking/Ghost page → F
  Unassessed core check → max C
  Any scan            → max 99
  (100/100 never awarded. No scanner can prove it.)

DEEP SCAN PERK:
  Paid public reports that pass Green Light can activate UNPWNED VERIFIED.
  Verified-domain deep scans can activate UNPWNED DEEP VERIFIED.

7 Core Evidence Surfaces

These are the primary surfaces the scanner observes. Categories organize the report; the score deduction comes from each finding's severity in the formula above, not from a hidden category multiplier. For the individual checks inside each surface, see the full check list.

01

Secrets & Credentials

Exposed API keys, database credentials, .env files, and source maps.

02

Browser Security Controls

CSP, HSTS, X-Frame-Options, cookies, and CORS.

03

SSL/TLS Configuration

Certificate validity, protocol support, and externally observable TLS posture.

04

Authentication & APIs

Open API routes, anonymous data access, and authorization evidence.

05

DNS & Email Security

SPF, DMARC, DNSSEC, and positively observed DKIM records.

06

Database & Storage Exposure

Supabase/Firebase access, sensitive files, and verified cloud-storage evidence.

07

Dependencies & CVEs

Version-linked vulnerabilities supported by observed software evidence and NVD/OSV data.

Grade Scale

A+95-99 + 2 bonuses · no medium/high/critical

Excellent. You went beyond the basics.

A88-99 when A+ requirements are not met

Strong. No critical issues, hygiene mostly clean.

B78-87

Good. A few minor gaps to address.

C65-77

Acceptable. Several issues worth fixing.

D50-64

Weak. Multiple meaningful issues.

F<50 or critical/cloaking

Failing. Critical risks present.

Bonuses: What Earns A+

A+ is not automatic. You need a score of 95+, at least 2 of these bonuses, and zero medium, high, or critical findings. Each bonus gives +1 (max +4). We only count bonuses backed by observed evidence.

HSTS Header
Forces browsers to HTTPS.
Strict CSP
Content Security Policy with strict-dynamic or nonce.
Rate Limiting
Detected on API endpoints or forms.
WAF Detected
Backed by a dedicated WAF-provider signal from a completed technology check. A blocked scanner never earns this bonus.

Evidence-Aware Scoring

Platform and organization detection adds context to the report, but it never changes the severity weight of observed evidence. A known brand and an unknown domain receive the same score for the same findings.

Blocked = Unknown Coverage. A blocked check never earns points and is never treated as clean. Effective coverage gives full weight to completed checks and partial weight to inconclusive evidence. A numeric partial result requires at least 50% effective coverage plus at least one authoritative completed check, and never receives a full-site grade.
Platform Detection. Hosting, CDN, framework, and AI-builder signals carry source, evidence, and confidence so weak text matches cannot become trusted fingerprints.
No Brand Exemptions. Platform context improves remediation guidance, not the score math. Findings are weighted from evidence and exploitability.

Official score + grade

Requires current ownership verification, at least 80% effective coverage, and every core security surface completed. Public and standing-authorization profiles are never official-grade eligible.

Partial result

At least 50% effective coverage and one authoritative completed check, but the official threshold or a core security surface is missing. The number scores completed checks only; no full-site grade, benchmark, or badge is issued.

Insufficient coverage

Below 50% effective coverage, or when no authoritative check completed, UNPWNED shows no numeric result. Confirmed findings remain visible.

A partial 100/100 means every completed check passed. It does not mean the whole site received a perfect security score.

Surface Scan vs. Verified Deep Scan

Public · Bounded

Public Check

Publication
ASSESSED ONLY

Browser-equivalent observations for headers, DNS, certificate transparency, technology and related public signals. This profile cannot publish an official letter grade, even when every bounded check completes.

149 bounded checks · 7 scanners
Current owner verified

Surface Scan

Highest possible grade
A+(up to 99)

Current ownership proof unlocks the full outside-in surface profile and official-grade eligibility. Coverage and core-check requirements still apply. See the full list.

428 checks · 22 scanners
Current owner + explicit active authorization

Full Suite

Highest possible grade
A+(up to 99)Deep Verified

The 721-check full suite requires current ownership proof plus separate, explicit active-testing authorization. A paid verified-domain deep report that passes Green Light can activate the UNPWNED DEEP VERIFIED badge. Higher risk of finding issues, but a high score here is more prestigious.

Up to 721 checks after current ownership proof plus explicit active-testing authorization

An outside-in scan cannot prove the absence of every vulnerability, so UNPWNED never awards 100/100. A verified deep scan provides broader evidence because it can safely run additional checks.

First Scan vs. Fix Verification

A grade only tells you where you stand today. The real question is whether your fix actually worked. That is the difference between the first scan and fix verification.

First scan · Free

The What

A bounded first public check shows the severity breakdown and finding titles from completed checks, plus an assessed score when evidence supports one. It never receives an official grade. Current ownership verification is required before a later surface or deep report can become official-grade eligible.

Paid

Verify Your Fix Worked

Re-scan a domain you already scanned and get a before/after comparison of score, grade, and findings, so you can confirm a fix actually landed. Re-scanning a previously scanned domain and the before/after diff are paid features.

Data Sources

Direct

Live Observations

  • → HTTP response analysis
  • → DNS queries
  • → SSL handshake inspection
  • → Content & secret regex
  • → Sitemap cloaking analysis
NVD + OSV

Version Intelligence

  • → NVD / CVE Database
  • → OSV (Google Open-Source Vulns)
  • → Only version-linked matches backed by observed fingerprints

What We Don't Score

Some things matter but aren't security per se. We show them separately. They never drag down your grade.

Privacy Policy presence. This is legal compliance, not security. Tracked under Compliance Checks.
Cookie consent banners. GDPR/CCPA compliance, not attack surface.
SEO quality. Not our scope.

Version History

v1.3
July 2026. Evidence-first accuracy
Removed brand-based score normalization and per-blocked-scanner bonuses. Partial scans now separate the completed-check result from effective coverage and confidence; numeric partial results require at least 50% effective coverage and one authoritative completed check, while official grades require at least 80% and complete core surfaces.
v1.2
June 2026. A+ and coverage calibration
A+ now requires no medium, high, or critical security findings. Coverage is calibrated to 22 surface scanners, 33 deep scanners, 34 for owner-verified deep scans that include path-traversal testing, or 36 when the full active-testing tier is separately authorized.
v1.1
May 2026. Developer-friendly rebalance
Severity weights softened (high 10→8, medium 5→3, low 2→1) so common hygiene gaps don't tank typical small-SaaS sites. Critical raised 20→25 and hard caps now run last (no bonus can bypass an F). Grade thresholds lowered to match the new distribution. A+ required 2+ bonuses and no high/critical findings.
v1.0
April 2026. Initial public methodology
7-category weighted system, A-F grading, infrastructure-aware scoring, surface/deep split.

See your grade

Scan any website in a couple of minutes. No credit card required.