Security Score & Grading
How your security score is calculated.
Barrion assigns every scan a security score between 0 and 100, along with a letter grade. This page explains the scoring methodology so you can understand what drives your grade and how to improve it.
Score Calculation
Each security check contributes to your overall score based on two factors:
- Max score -- The maximum number of points a check can contribute if it passes. This is determined by the check's CVSS severity.
- Actual score -- The points awarded based on the check result. A passing check earns its full max score; a failing check earns zero.
Your final score is the sum of all actual scores divided by the sum of all max scores, expressed as a percentage.
Score = (sum of actual scores / sum of max scores) x 100CVSS-Weighted Severity
Checks are weighted by their CVSS v3.1 (Common Vulnerability Scoring System) base score. Higher-severity checks carry more weight, meaning a single failing critical check impacts your score more than several failing low-severity checks.
Severity is set per finding by CVSS v3.1, so the groups below are a guide. A finding's severity in your report can differ from the group its check is listed under.
Critical Checks (CVSS 9.0+)
These checks have the highest weight and represent fundamental security requirements:
- HTTPS enforcement
- TLS protocol version (1.2+ required)
- Certificate expiry validation
- CSP bypass vulnerabilities
Failing any critical check will significantly reduce your score.
High Checks (CVSS 7.0 -- 8.9)
These cover important security headers and configurations:
- HTTP Strict Transport Security (HSTS)
- Content Security Policy (CSP) presence
- X-Content-Type-Options
- X-Frame-Options
- Most security header configurations
Medium Checks (CVSS 4.0 -- 6.9)
These address important but less immediately exploitable issues:
- Cookie security attributes (Secure, HttpOnly, SameSite)
- CORS misconfiguration
- Email security (SPF, DKIM, DMARC)
- Referrer-Policy
Low Checks (CVSS 0.0 -- 3.9)
These are informational or best-practice recommendations:
- Server information disclosure
- Technology fingerprinting
- Non-critical header recommendations
Low-severity checks still contribute to your score, but their weight is minimal. Focus on critical and high findings first for the greatest score improvement.
Letter Grades
Your numeric score maps to a letter grade:
| Grade | Score Range | Interpretation |
|---|---|---|
| A | 90 -- 100 | Excellent security posture. All critical checks pass. |
| B | 80 -- 89 | Good security posture with minor improvements needed. |
| C | 70 -- 79 | Fair. Several important checks are failing. |
| D | 50 -- 69 | Poor. Significant security gaps exist. |
| F | Below 50 | Critical security issues require immediate attention. |
Grade boundaries are approximate and may be adjusted as Barrion's check library evolves. Focus on remediating individual findings rather than targeting a specific numeric threshold.
Trend Tracking
When you scan the same domain multiple times, Barrion compares your current score to previous results and reports a trend:
- Improving -- Your score has increased since the last scan. Security fixes are working.
- Stable -- Your score has not changed meaningfully. No new issues or fixes detected.
- Declining -- Your score has dropped. New vulnerabilities may have been introduced, or previously passing checks are now failing.
Trend data is especially useful when combined with continuous monitoring -- scheduled scans automatically track your score over time so you can catch regressions early.
Improving Your Score
To improve your security score efficiently:
- Start with critical findings. These carry the most weight and represent the most urgent risks.
- Address high-severity findings next. These provide the second-largest score improvement.
- Re-scan after each batch of fixes to validate that changes took effect.
- Review the Security Check Reference for detailed remediation guidance on each check.