Skip to main content
UNPWNED
Methodology v1.5 · Validated on 57 authorized sites

How we grade
your website.

Full transparency on how your A-F security grade is calculated. No black box, no hidden weights. Everything on this page is how the real scanner works.

THE FORMULA

score = 100
  - (Critical × 25)
  - (High     × 8)
  - (Medium   × 3)
  - (Low      × 1)
  + bonuses (max +4)

CSP configuration findings count once, at their highest severity (max -8).
Missing enforced CSP is high (-8). CSP reporting advice is informational (-0).

HARD CAPS (applied last, no bonus can bypass):
  Critical found      → F
  Cloaking/Ghost page → F
  Any scan            → max 99
  (100/100 never awarded. No scanner can prove it.)

DEEP SCAN PERK:
  Paid public reports that pass Green Light can activate UNPWNED VERIFIED.
  Verified-domain deep scans can activate UNPWNED DEEP VERIFIED.

7 Core Evidence Surfaces

These are the primary surfaces the scanner observes. Categories organize the report. Severity determines deductions, with CSP configuration findings counted as one control family. Every individual CSP finding and its remediation remain visible. For the individual checks inside each surface, see the full check list.

01

Secrets & Credentials

Exposed API keys, database credentials, .env files, and source maps.

02

Browser Security Controls

CSP, HSTS, X-Frame-Options, cookies, and CORS.

03

SSL/TLS Configuration

Certificate validity, protocol support, and externally observable TLS posture.

04

Authentication & APIs

Open API routes, anonymous data access, and authorization evidence.

05

DNS & Email Security

SPF, DMARC, DNSSEC, and positively observed DKIM records.

06

Database & Storage Exposure

Supabase/Firebase access, sensitive files, and verified cloud-storage evidence.

07

Dependencies & CVEs

Version-linked vulnerabilities supported by observed software evidence and NVD/OSV data.

Grade Scale

A+95-99 + 2 bonuses · no medium/high/critical

Excellent. You went beyond the basics.

A88-99 when A+ requirements are not met

Strong. No critical issues, hygiene mostly clean.

B78-87

Good. A few minor gaps to address.

C65-77

Acceptable. Several issues worth fixing.

D50-64

Weak. Multiple meaningful issues.

F<50 or critical/cloaking

Failing. Critical risks present.

Bonuses: What Earns A+

A+ is not automatic. You need a score of 95+, at least 2 of these bonuses, and zero medium, high, or critical findings. Each bonus gives +1 (max +4). We only count bonuses backed by authoritative observed evidence. If a bonus-bearing check is unresolved, a new official grade stays pending instead of falling because a bonus could not be confirmed.

HSTS Header
Forces browsers to HTTPS.
Strict CSP
Content Security Policy with strict-dynamic or nonce.
Rate Limiting
Detected on API endpoints or forms.
WAF Detected
Backed by a dedicated WAF-provider signal from a completed technology check. A blocked scanner never earns this bonus.

Evidence-Aware Scoring

Platform and organization detection adds context to the report, but it never changes the severity weight of observed evidence. A known brand and an unknown domain receive the same score for the same findings.

✓Coverage and findings are reported separately. A pending assessed score reflects resolved evidence. The current methodology keeps the established coverage denominator and classifier, while unresolved areas remain unknown. A new official grade also waits until every bonus-bearing check is authoritative.
✓Platform Detection. Hosting, CDN, framework, and AI-builder signals carry source, evidence, and confidence so weak text matches cannot become trusted fingerprints.
✓No Brand Exemptions. Platform context improves remediation guidance, not the score math. Findings are weighted from evidence and exploitability.

Official score + grade

Requires current ownership verification, at least 80% effective coverage, every core security surface completed, and authoritative evidence from every bonus-bearing check. Public and standing-authorization profiles are never official-grade eligible.

Verification pending

At least 50% effective coverage and one authoritative completed check, but the official threshold, a core security surface, or authoritative bonus evidence is missing. A displayed number reflects confirmed security findings without a coverage deduction; no official UNPWNED grade, benchmark, or badge is issued, and the last official result is not replaced.

Official result pending

Below 50% effective coverage, or when no authoritative check completed, UNPWNED does not publish a numeric result. This is an evidence threshold, not a score deduction. Confirmed findings remain visible.

A pending 99/100 means no confirmed finding reduced the score in the resolved evidence. Unresolved areas are still unknown, not clean.

Surface Scan vs. Verified Deep Scan

Public · Bounded

Public Check

Publication
ASSESSED ONLY

Browser-equivalent observations for headers, DNS, certificate transparency, technology and related public signals. This profile cannot publish an official letter grade, even when every bounded check completes.

149 bounded checks · 7 scanners
Current owner verified

Surface Scan

Highest possible grade
A+(up to 99)

Current ownership proof unlocks the full outside-in surface profile and official-grade eligibility. Coverage and core-check requirements still apply. See the full list.

428 checks · 22 scanners
Current owner + explicit active authorization

Current Deep Scan

Highest possible grade
A+(up to 99)Deep Verified

The currently enabled Deep Scan runs up to 702 configured checks after current ownership proof. A paid verified-domain deep report that passes Green Light can activate the UNPWNED DEEP VERIFIED badge. Higher risk of finding issues, but a high score here is more prestigious.

Up to 702 configured Deep checks after current ownership proof

An outside-in scan cannot prove the absence of every vulnerability, so UNPWNED never awards 100/100. A verified deep scan provides broader evidence because it can safely run additional checks.

First Scan vs. Fix Verification

A grade only tells you where you stand today. The real question is whether your fix actually worked. That is the difference between the first scan and fix verification.

First scan · Free

The What

A bounded first public check shows the severity breakdown and finding titles from completed checks, plus an assessed score when evidence supports one. It never receives an official grade. Current ownership verification is required before a later surface or deep report can become official-grade eligible.

Paid

Verify Your Fix Worked

Re-scan a domain you already scanned and get a before/after comparison of score, grade, and findings, so you can confirm a fix actually landed. Re-scanning a previously scanned domain and the before/after diff are paid features.

Data Sources

Direct

Live Observations

  • → HTTP response analysis
  • → DNS queries
  • → SSL handshake inspection
  • → Content & secret regex
  • → Sitemap cloaking analysis
NVD + OSV

Version Intelligence

  • → NVD / CVE Database
  • → OSV (Google Open-Source Vulns)
  • → Only version-linked matches backed by observed fingerprints

What We Don't Score

Some things matter but aren't security per se. We show them separately. They never drag down your grade.

Privacy Policy presence. This is legal compliance, not security. Tracked under Compliance Checks.
Cookie consent banners. GDPR/CCPA compliance, not attack surface.
SEO quality. Not our scope.

Version History

v1.5
September 2026. Consistent configuration scoring
Missing enforced CSP and permissive script policies are configuration risks rated high. CSP configuration findings contribute one deduction at their highest severity, up to 8 points, so adding restrictions does not increase the deduction merely by revealing multiple policy weaknesses. Reporting advice is informational. A permissive CSP alone is not proof of an exploited injection flaw; independently confirmed critical findings retain their full deduction and F cap. This version applies to newly calculated results. Historical scores retain their original methodology, and score trends compare matching versions.
CSS-hidden content by itself is informational and carries no security deduction. It can support legitimate navigation and accessibility. Separate evidence of cloaking or ghost pages keeps its existing severity and score caps.
v1.4
August 2026. Findings determine the score
Removed score and grade reductions caused only by scanner coverage gaps. Confirmed findings and authoritative evidence-backed bonuses determine the assessed score. Coverage still determines whether a numeric result is supported. A new official grade also requires every bonus-bearing check to be authoritative, so missing bonus evidence cannot lower, replace, or retroactively reclassify a valid official v1.3 result. Unresolved areas remain unknown rather than clean.
v1.3
July 2026. Evidence-first accuracy
Removed brand-based score normalization and per-blocked-scanner bonuses. Limited scans separated the completed-check result from effective coverage and confidence; numeric limited results required at least 50% effective coverage and one authoritative completed check, while official grades required at least 80% and complete core surfaces.
v1.2
June 2026. A+ and coverage calibration
A+ now requires no medium, high, or critical security findings. Coverage is calibrated to 22 surface scanners, 33 deep scanners, 34 for owner-verified deep scans that include path-traversal testing, or 36 when the full active-testing tier is separately authorized.
v1.1
May 2026. Developer-friendly rebalance
Severity weights softened (high 10→8, medium 5→3, low 2→1) so common hygiene gaps don't tank typical small-SaaS sites. Critical raised 20→25 and hard caps now run last (no bonus can bypass an F). Grade thresholds lowered to match the new distribution. A+ required 2+ bonuses and no high/critical findings.
v1.0
April 2026. Initial public methodology
7-category weighted system, A-F grading, infrastructure-aware scoring, surface/deep split.

See your grade

Scan any website in a couple of minutes. No credit card required.