How we grade
your website.
Full transparency on how your A-F security grade is calculated. No black box, no hidden weights. Everything on this page is how the real scanner works.
THE FORMULA
score = 100 - (Critical × 25) - (High × 8) - (Medium × 3) - (Low × 1) + bonuses (max +4) CSP configuration findings count once, at their highest severity (max -8). Missing enforced CSP is high (-8). CSP reporting advice is informational (-0). HARD CAPS (applied last, no bonus can bypass): Critical found → F Cloaking/Ghost page → F Any scan → max 99 (100/100 never awarded. No scanner can prove it.) DEEP SCAN PERK: Paid public reports that pass Green Light can activate UNPWNED VERIFIED. Verified-domain deep scans can activate UNPWNED DEEP VERIFIED.
7 Core Evidence Surfaces
These are the primary surfaces the scanner observes. Categories organize the report. Severity determines deductions, with CSP configuration findings counted as one control family. Every individual CSP finding and its remediation remain visible. For the individual checks inside each surface, see the full check list.
Secrets & Credentials
Exposed API keys, database credentials, .env files, and source maps.
Browser Security Controls
CSP, HSTS, X-Frame-Options, cookies, and CORS.
SSL/TLS Configuration
Certificate validity, protocol support, and externally observable TLS posture.
Authentication & APIs
Open API routes, anonymous data access, and authorization evidence.
DNS & Email Security
SPF, DMARC, DNSSEC, and positively observed DKIM records.
Database & Storage Exposure
Supabase/Firebase access, sensitive files, and verified cloud-storage evidence.
Dependencies & CVEs
Version-linked vulnerabilities supported by observed software evidence and NVD/OSV data.
Grade Scale
Excellent. You went beyond the basics.
Strong. No critical issues, hygiene mostly clean.
Good. A few minor gaps to address.
Acceptable. Several issues worth fixing.
Weak. Multiple meaningful issues.
Failing. Critical risks present.
Bonuses: What Earns A+
A+ is not automatic. You need a score of 95+, at least 2 of these bonuses, and zero medium, high, or critical findings. Each bonus gives +1 (max +4). We only count bonuses backed by authoritative observed evidence. If a bonus-bearing check is unresolved, a new official grade stays pending instead of falling because a bonus could not be confirmed.
Evidence-Aware Scoring
Platform and organization detection adds context to the report, but it never changes the severity weight of observed evidence. A known brand and an unknown domain receive the same score for the same findings.
Official score + grade
Requires current ownership verification, at least 80% effective coverage, every core security surface completed, and authoritative evidence from every bonus-bearing check. Public and standing-authorization profiles are never official-grade eligible.
Verification pending
At least 50% effective coverage and one authoritative completed check, but the official threshold, a core security surface, or authoritative bonus evidence is missing. A displayed number reflects confirmed security findings without a coverage deduction; no official UNPWNED grade, benchmark, or badge is issued, and the last official result is not replaced.
Official result pending
Below 50% effective coverage, or when no authoritative check completed, UNPWNED does not publish a numeric result. This is an evidence threshold, not a score deduction. Confirmed findings remain visible.
A pending 99/100 means no confirmed finding reduced the score in the resolved evidence. Unresolved areas are still unknown, not clean.
Surface Scan vs. Verified Deep Scan
Public Check
Browser-equivalent observations for headers, DNS, certificate transparency, technology and related public signals. This profile cannot publish an official letter grade, even when every bounded check completes.
Surface Scan
Current ownership proof unlocks the full outside-in surface profile and official-grade eligibility. Coverage and core-check requirements still apply. See the full list.
Current Deep Scan
The currently enabled Deep Scan runs up to 702 configured checks after current ownership proof. A paid verified-domain deep report that passes Green Light can activate the UNPWNED DEEP VERIFIED badge. Higher risk of finding issues, but a high score here is more prestigious.
An outside-in scan cannot prove the absence of every vulnerability, so UNPWNED never awards 100/100. A verified deep scan provides broader evidence because it can safely run additional checks.
First Scan vs. Fix Verification
A grade only tells you where you stand today. The real question is whether your fix actually worked. That is the difference between the first scan and fix verification.
The What
A bounded first public check shows the severity breakdown and finding titles from completed checks, plus an assessed score when evidence supports one. It never receives an official grade. Current ownership verification is required before a later surface or deep report can become official-grade eligible.
Verify Your Fix Worked
Re-scan a domain you already scanned and get a before/after comparison of score, grade, and findings, so you can confirm a fix actually landed. Re-scanning a previously scanned domain and the before/after diff are paid features.
Data Sources
Live Observations
- → HTTP response analysis
- → DNS queries
- → SSL handshake inspection
- → Content & secret regex
- → Sitemap cloaking analysis
Version Intelligence
- → NVD / CVE Database
- → OSV (Google Open-Source Vulns)
- → Only version-linked matches backed by observed fingerprints
What We Don't Score
Some things matter but aren't security per se. We show them separately. They never drag down your grade.
Version History
See your grade
Scan any website in a couple of minutes. No credit card required.
