The scan grade (A–F)
After every scan you receive an overall grade from A to F. It shows at a glance how secure your project is. The grade is calculated from the number and severity of issues found.
| Grade | Meaning | Score |
|---|---|---|
| A | Excellent – no issues or only minor hints | 90–100 |
| B | Good – a few areas for improvement | 75–89 |
| C | Needs improvement – relevant issues exist | 55–74 |
| D | Significant risks – multiple important vulnerabilities | 35–54 |
| E | High risks – urgent action required | 15–34 |
| F | Critical – immediate action required | 0–14 |
Good to know
Even a single critical finding caps the grade at D. A high finding caps it at C – regardless of how few other issues there are.
Severity levels
Each vulnerability gets a severity level:
| Severity | What does it mean? | Score impact |
|---|---|---|
| Critical | Immediately exploitable, e.g. SQL injection or remote code execution. Must be fixed right away. | −30 |
| High | Serious security risk, e.g. cross-site scripting (XSS) or insecure authentication. | −12 |
| Medium | Potential risk, e.g. missing security headers or outdated dependencies. | −4 |
| Low | Low risk, e.g. best-practice recommendations. | −1 |
| Info | Informational only, no direct risk. | 0 |
Finding details
Click on a finding to see its details:
- Description: What exactly was found and why it's a problem.
- Location: Which file and line the issue is in.
- Confidence: How confident the scanner is (high, medium, low).
- Engine: Which scanner found the issue.
Managing findings
Not every finding is a real problem in your context. You can change the status:
- Open – the issue still needs to be fixed (default).
- Accepted – you're aware of it and consciously accept the risk.
- False positive – the scanner was wrong, it's not a real issue.
Accepted and false-positive findings are excluded from the grade calculation and improve your score.
Comparing results
When you scan the same project multiple times you can see the trend under "Targets & history". This helps you track whether your project is getting more secure or if new issues have appeared.