Full transparency on how Sentinel calculates your security grade. 7 categories, severity-weighted deductions, hard caps for critical issues, performance bonuses, and no hidden weights.
Every scan starts at 100 points. Points are deducted based on the severity of findings discovered, then bonuses are added. The final score maps to a letter grade.
Toggle findings below to see how each severity affects your grade in real time.
Each qualifying bonus adds +1 point (max +4) to the final score. Bonuses require observed evidence.
Strict-Transport-Security header with preload directive forces all traffic to HTTPS.
Content-Security-Policy using strict-dynamic or a cryptographic nonce for scripts.
A dedicated Web Application Firewall is protecting the origin.
API endpoints and forms rate-limit requests to prevent abuse.
Note: A blocked/rate-limited scanner never earns bonuses. Coverage must be authoritative and complete.
Results are organized into seven core categories that cover the full attack surface of a modern web application.
Exposed API keys, database credentials, .env files, and source maps.
CSP, HSTS, X-Frame-Options, cookies, and CORS configuration.
Certificate validity, protocol support, and cipher strength.
Open API routes, anonymous data access, and authorization gaps.
SPF, DKIM, DMARC, DNSSEC, and domain misconfigurations.
Supabase/Firebase access, sensitive files, and cloud storage buckets.
Version-linked vulnerabilities backed by NVD and OSV data.
A grade is only issued when effective coverage meets the minimum threshold.
Introduced A+ grade with stricter bonus requirements. Added coverage classification system. Refined bonus evidence rules.
Added 7th category (Dependencies & CVEs) with NVD/OSV integration. Introduced rate limiting and WAF detection bonuses.
Rebalanced severity weights: High from −10 to −8, Medium from −5 to −3.
Initial methodology release. 6 categories, 100-base scoring, severity multipliers, and bonus system.
We believe security scoring should be transparent, not a black box. Here is what we commit to: