Metodika

METHODOLOGY

How we assess website security

The check runs externally and passively — nothing is installed on your website, nothing is hacked, and no data is changed. We only look at what the server itself makes public. The scoring is transparent: we start at 100 points and subtract for every issue we find (at most 10 points per issue).

We keep it simple: results are presented so a website owner can understand them — not just a CISO or developers. This is a free initial overview. For those seeking maximum security and in-depth analysis, we perform professional full-scope security audits.

🔒TLS / SSL certificate

  • No SSL, or the check failed −10
  • Certificate has expired −10
  • Expires in < 14 days / < 30 days −10 / −5
  • Untrusted certificate chain −10
  • Weak RSA key (< 2048 bits) −10
  • ECDSA P-256/384/521 — strong, no penalty 0

🛡️Security headers (HTTP headers)

  • HSTS (Strict-Transport-Security) −10
  • Content-Security-Policy (CSP) −8
  • X-Frame-Options (clickjacking) −6
  • X-Content-Type-Options −4
  • Referrer-Policy −3
  • Server reveals software versions −5

🍪Cookies

  • Cookies without Secure / HttpOnly flags −7

🌐DNS

  • DNSSEC not enabled −5

🧩Software (WordPress / PHP)

  • WordPress badly outdated (large gap) −10
  • WordPress outdated (minor version) −8
  • PHP no longer supported (end of life) −10
  • readme.html reveals the WordPress version −3
  • Components with a disclosed version → for CVE review info

✉️Email protection (extended scan)

  • No SPF record −8
  • No DMARC record −6
  • Weak DMARC (p=none) −2
  • No DKIM signature found −6

⚠️Reputation

  • Domain in a phishing database −10
  • Blocked by security filters (malware) −10
  • Blocked by content filters −2

📡IP reputation (DNSBL)

  • IP on 2+ spam/abuse lists (Spamhaus, SpamCop…) −10
  • IP on 1 list −6
  • IP clean on reputation lists 0

🔎AbuseIPDB (advanced scan only)

  • Abuse score ≥ 75/100 −10
  • Score 25–74 −6
  • Score 1–24 −2
  • Score 0 — clean 0

🏅Grades

A 90–100
B 80–89
C 70–79
D 50–69
E 30–49
F 0–29

🎚️Scan types

  • Simple — the technical surface: TLS / SSL, security headers, cookies, DNSSEC, version disclosure, software (WordPress / PHP) and CVEs, reputation (phishing / blocklists) and IP reputation (DNSBL).
  • Extended — everything in Simple plus email protection: SPF, DKIM and DMARC.
  • Advanced — everything in Extended plus AbuseIPDB IP-reputation enrichment, and lets you check a specific URL — a subdomain or a path, not just the main domain.

Each report is stamped with its type (simple / extended / advanced), date/time, GMT (UTC) and template version.

What you get in the report

An overall score (0–100), a list of the issues found with an explanation of what each one means and how to fix it — in plain language, not for an IT specialist. You also get a list of the things that are fine, plus a summary (IP, SSL issuer, server, WordPress / PHP versions). Every report shows the date/time, GMT (UTC), template version and scan type (simple / extended / advanced). The full report can be opened as a PDF and received by email.

Run a free check →

⚠️ This is only a simple online test

This free test shows only the publicly visible, most common issues and is meant for the website owner — not an IT specialist, DevOps or CISO. A full security audit is a paid service and is far more thorough: deeper (penetration) testing, internal analysis, manual checking and tailored recommendations. For an audit: pagalba@parescius.lt.

The check does not change or load your website. The same domain can be re-checked once per day. For deeper (penetration) testing or fixing issues: pagalba@parescius.lt