Understanding Your Security Score
How Barrion calculates and presents your security score.
Every Barrion scan produces a security score that summarizes the overall security posture of your web application. This page explains how the score is calculated, what the grades mean, and how to improve your results.
Score Range
Your security score is a number from 0 to 100, where 100 represents a perfect score with all checks passing. The score is calculated as the ratio of earned points to the maximum possible points across all evaluated security checks.
Letter Grades
Each numeric score maps to a letter grade:
| Grade | Score Range | Interpretation |
|---|---|---|
| A | 90 -- 100 | Excellent security posture. Most or all checks are passing. |
| B | 80 -- 89 | Good security posture with minor issues to address. |
| C | 70 -- 79 | Moderate security posture. Several checks need attention. |
| D | 50 -- 69 | Poor security posture. Significant vulnerabilities detected. |
| F | 0 -- 49 | Critical security posture. Immediate action required. |
How Scoring Works
Each security check has a maximum score and an earned score. When a check passes, it earns its full points. When it fails, it earns zero. The overall score is calculated as:
Security Score = (Total Earned Points / Total Maximum Points) x 100Check weights are tied to the CVSS (Common Vulnerability Scoring System) severity of each finding. Higher-severity checks carry more weight, meaning a failing Critical check has a larger impact on your score than a failing Low check.
Check Categories
Barrion organizes the 35+ checks of its passive scan into 10 categories:
| Category | What It Covers |
|---|---|
| Transport Layer Security (TLS) | HTTPS enforcement, TLS version, certificate validity and expiry, cipher suites, HSTS, OCSP stapling |
| Content Security Policy (CSP) | CSP header presence, bypass detection, and console error analysis |
| Cross-Origin Resource Sharing (CORS) | Allow-Origin, Allow-Credentials, preflight configuration, Vary header |
| Cookie Security | Secure, HttpOnly, SameSite attributes on Set-Cookie headers |
| Cross-Site Scripting (XSS) Protection | X-XSS-Protection header, Trusted Types policy |
| Clickjacking Protection | X-Frame-Options, frame-ancestors CSP directive |
| Email Security | SPF, DKIM, and DMARC record validation |
| Network Security | Open ports, DNS security, subdomain takeover detection |
| Miscellaneous Headers | Referrer-Policy, Permissions-Policy, X-Content-Type-Options, server information disclosure |
| Miscellaneous | Mixed content, vulnerable JavaScript libraries, anti-CSRF tokens |
Free accounts have access to 18 security checks. The full suite of 35+ checks is available on Essential and Business plans. Checks that require an upgrade are marked with a RequiresUpgrade status in your results.
Severity Levels
Each failing check is assigned a severity level based on its potential impact:
- Critical -- Exploitable vulnerabilities that could lead to data breach, account takeover, or complete system compromise. Address these immediately.
- High -- Serious security weaknesses that significantly increase your attack surface. Prioritize these in your next development cycle.
- Medium -- Security misconfigurations that reduce defense-in-depth. Plan to address these alongside regular development work.
- Low -- Minor issues or best-practice recommendations. Fix these to achieve a hardened security posture.
Check Statuses
Each security check in your scan results has one of three statuses:
- Passed -- The check was evaluated and your site meets the security requirement.
- Failed -- The check was evaluated and a vulnerability or misconfiguration was detected.
- RequiresUpgrade -- The check is available on a higher plan tier. Upgrade to see the result.
Score Trends
When you scan the same domain over time, Barrion tracks your score history and calculates a trend:
- Improving -- Your score has increased by 2 or more points compared to the previous scan.
- Stable -- Your score has changed by less than 2 points in either direction.
- Declining -- Your score has decreased by 2 or more points compared to the previous scan.
Score history is displayed as a chart in the executive summary of each scan, letting you visualize your security posture over weeks or months.
Tips for Improving Your Score
- Start with Critical and High severity findings. These carry the most scoring weight and represent the greatest risk to your application.
- Address TLS issues first. Ensuring HTTPS, valid certificates, and modern TLS versions resolves multiple checks at once.
- Add security headers. Many Medium-severity checks can be resolved by configuring headers like
Content-Security-Policy,Strict-Transport-Security,X-Content-Type-Options, andReferrer-Policy. - Secure your cookies. Set the
Secure,HttpOnly, andSameSiteattributes on all cookies. - Configure email authentication. Set up SPF, DKIM, and DMARC records for your domain to pass email security checks.
- Set up continuous monitoring. Schedule regular scans to catch regressions before they become long-term vulnerabilities.
- Use AI remediation. Open a finding to get a fix recommendation written for your stack, with code snippets you can apply.
You can ignore specific checks that are not relevant to your application. Ignored checks are excluded from score calculations while remaining visible in your results for audit purposes.