Barrion Docs
Getting Started

Understanding Your Security Score

How Barrion calculates and presents your security score.

Every Barrion scan produces a security score that summarizes the overall security posture of your web application. This page explains how the score is calculated, what the grades mean, and how to improve your results.

Score Range

Your security score is a number from 0 to 100, where 100 represents a perfect score with all checks passing. The score is calculated as the ratio of earned points to the maximum possible points across all evaluated security checks.

Letter Grades

Each numeric score maps to a letter grade:

GradeScore RangeInterpretation
A90 -- 100Excellent security posture. Most or all checks are passing.
B80 -- 89Good security posture with minor issues to address.
C70 -- 79Moderate security posture. Several checks need attention.
D50 -- 69Poor security posture. Significant vulnerabilities detected.
F0 -- 49Critical security posture. Immediate action required.

How Scoring Works

Each security check has a maximum score and an earned score. When a check passes, it earns its full points. When it fails, it earns zero. The overall score is calculated as:

Security Score = (Total Earned Points / Total Maximum Points) x 100

Check weights are tied to the CVSS (Common Vulnerability Scoring System) severity of each finding. Higher-severity checks carry more weight, meaning a failing Critical check has a larger impact on your score than a failing Low check.

Check Categories

Barrion organizes the 35+ checks of its passive scan into 10 categories:

CategoryWhat It Covers
Transport Layer Security (TLS)HTTPS enforcement, TLS version, certificate validity and expiry, cipher suites, HSTS, OCSP stapling
Content Security Policy (CSP)CSP header presence, bypass detection, and console error analysis
Cross-Origin Resource Sharing (CORS)Allow-Origin, Allow-Credentials, preflight configuration, Vary header
Cookie SecuritySecure, HttpOnly, SameSite attributes on Set-Cookie headers
Cross-Site Scripting (XSS) ProtectionX-XSS-Protection header, Trusted Types policy
Clickjacking ProtectionX-Frame-Options, frame-ancestors CSP directive
Email SecuritySPF, DKIM, and DMARC record validation
Network SecurityOpen ports, DNS security, subdomain takeover detection
Miscellaneous HeadersReferrer-Policy, Permissions-Policy, X-Content-Type-Options, server information disclosure
MiscellaneousMixed content, vulnerable JavaScript libraries, anti-CSRF tokens

Free accounts have access to 18 security checks. The full suite of 35+ checks is available on Essential and Business plans. Checks that require an upgrade are marked with a RequiresUpgrade status in your results.

Severity Levels

Each failing check is assigned a severity level based on its potential impact:

  • Critical -- Exploitable vulnerabilities that could lead to data breach, account takeover, or complete system compromise. Address these immediately.
  • High -- Serious security weaknesses that significantly increase your attack surface. Prioritize these in your next development cycle.
  • Medium -- Security misconfigurations that reduce defense-in-depth. Plan to address these alongside regular development work.
  • Low -- Minor issues or best-practice recommendations. Fix these to achieve a hardened security posture.

Check Statuses

Each security check in your scan results has one of three statuses:

  • Passed -- The check was evaluated and your site meets the security requirement.
  • Failed -- The check was evaluated and a vulnerability or misconfiguration was detected.
  • RequiresUpgrade -- The check is available on a higher plan tier. Upgrade to see the result.

When you scan the same domain over time, Barrion tracks your score history and calculates a trend:

  • Improving -- Your score has increased by 2 or more points compared to the previous scan.
  • Stable -- Your score has changed by less than 2 points in either direction.
  • Declining -- Your score has decreased by 2 or more points compared to the previous scan.

Score history is displayed as a chart in the executive summary of each scan, letting you visualize your security posture over weeks or months.

Tips for Improving Your Score

  1. Start with Critical and High severity findings. These carry the most scoring weight and represent the greatest risk to your application.
  2. Address TLS issues first. Ensuring HTTPS, valid certificates, and modern TLS versions resolves multiple checks at once.
  3. Add security headers. Many Medium-severity checks can be resolved by configuring headers like Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, and Referrer-Policy.
  4. Secure your cookies. Set the Secure, HttpOnly, and SameSite attributes on all cookies.
  5. Configure email authentication. Set up SPF, DKIM, and DMARC records for your domain to pass email security checks.
  6. Set up continuous monitoring. Schedule regular scans to catch regressions before they become long-term vulnerabilities.
  7. Use AI remediation. Open a finding to get a fix recommendation written for your stack, with code snippets you can apply.

You can ignore specific checks that are not relevant to your application. Ignored checks are excluded from score calculations while remaining visible in your results for audit purposes.