Website Security Score: What It Means
A quick, plain-language explanation of the 0–100 score and A–F grade Nivaronix returns for a scanned website, and what actually moves it.
Get your own score
Scan any public website for free and see its score, grade, and every finding behind it.
How the score is built
Every scan starts at a base score of 100. Each issue found ("finding") has a severity — Critical, High, Medium, Low, or Info — and each severity subtracts a fixed number of points from the category it belongs to (SSL/TLS, Headers, Redirects, Cookies, DNS, or Technology). Each category can only cost the score up to its own maximum, so one noisy category cannot single-handedly collapse an otherwise clean score. What is left after those deductions is the score. The full arithmetic, category weights, and deduction values are documented on the methodology page.
How scores map to grades
The score maps to a letter grade using fixed thresholds — the same thresholds for every scan:
| Score | Grade | General meaning |
|---|---|---|
| 90–100 | A | No or very few low-impact findings across checked categories. |
| 80–89 | B | Some findings present, none severe enough to push the score below 80. |
| 70–79 | C | Noticeable findings, likely including at least one Medium or High severity issue. |
| 60–69 | D | Multiple or higher-severity findings across one or more categories. |
| 0–59 | F | Significant findings — often Critical or High severity, or several Medium findings in a single category. |
"General meaning" describes the typical pattern of findings behind each grade band, not a guaranteed cause — the exact mix of findings behind any given score can vary. The thresholds themselves, and the deduction values that produce the score, are fixed and exact as coded.
What a low score does not mean
A low score means the scan found configuration issues in the categories it checks — it is not a claim that a site has been breached, is actively malicious, or has been penetration tested. Likewise, a check that could not complete for a given target is never treated as a passing result: it is reported as Not measured, not scored as if it had succeeded.
Frequently asked questions
What is a website security score?
A website security score is a 0–100 number produced by scanning a site's externally observable configuration — SSL/TLS, HTTP security headers, redirects, cookies, DNS, and detectable technologies — and deducting points for issues found, based on their severity. Nivaronix's score starts at 100 and subtracts capped, per-category deductions; it does not involve AI or machine learning, it is a fixed calculation.
What is a good website security score?
80 or above (grade B or A) generally reflects a site with no significant unresolved configuration issues in the categories checked. A score below 70 (grade D or F) usually means at least one Medium-or-higher severity finding, or several findings clustered in one category, and is worth investigating.
Can my score go down without me changing anything?
Yes, in one specific case: if a check that previously could not complete now runs successfully and finds an issue, the score can change even though nothing about your site changed in that window — because the earlier scan's "Not measured" result was excluded from scoring rather than treated as a pass.
Is a security score the same as a penetration test?
No. A security score reflects a set of external configuration checks. It is not a penetration test, does not attempt exploitation, and does not authenticate into your application. See the full methodology for exactly what is and is not checked.
Go deeper
- Full methodology — categories, severity model, exact score calculation, and scan limitations.
- How is a website security score calculated? — a shorter, search-focused guide.
- Run a free website security scan