Methodology
How the WebTrustScore works
WebTrustScore rates a website from 0 to 1000 by combining seven weighted categories of evidence — read from the live site, its public records, and authoritative threat feeds at the moment of the scan. The same rules run on every site, in the same order, and every category shows the evidence behind it.
A score, not a seal of approval
Nobody can pay to raise a score, and no site is reviewed by hand. Each category is computed from what a scan can actually observe, so the same site, read the same way, returns the same score every time.
That cuts both ways: a high score is evidence that the signals we can check look sound, not a promise that a business is honest, and the absence of an adverse finding is reported as exactly that — nothing found — never as an endorsement.
What's in the score, and what's reported alongside
Only the seven weighted categories move the number. Everything else a scan learns is reported next to the score, never folded into it — so the number stays reproducible.
| Signal group | Role |
|---|---|
| Seven weighted categories | Determine the score |
| Live-site state — an active site, a parking placeholder, a for-sale listing, a redirect to another domain, or nothing reachable at all | Reported alongside — and when there is no site to trust, no score is published at all |
| Provenance context — site age, link authority, and certificate history | Reported alongside — never in the score |
| Confidence — how much of the expected evidence was actually reachable | Reported separately — can only lower the ceiling, never raise the score |
Every category also ships its evidence, and severe risks cap the total score outright.
The seven categories
| Category | Weight | What it measures |
|---|---|---|
| Security posture | 24% | Whether the site is safe to visit and use |
| Content trustworthiness | 20% | What the site asks you to believe or hand over |
| Ownership identity | 16% | Who is behind the site, and whether the records agree |
| Reputation history | 12% | The site's own age and track record |
| External reputation | 10% | How the site is regarded off its own pages |
| Consumer transparency | 10% | What a visitor is told before they commit |
| Operational resilience | 8% | Whether the site is run competently |
Security posture (24%). Whether the site is technically safe to visit and interact with: HTTPS served by default with a certificate that validates, protective response headers, safe redirect behavior, and malware and phishing checks against authoritative feeds. A confirmed malware or phishing finding caps the whole score.
Content trustworthiness (20%). What the site asks a visitor to believe or hand over: deceptive claims, brand impersonation, credential and payment harvesting, fabricated authority, coercive urgency, hidden costs, and obstructed choice. Page structure — where a form sends what you type, which fields it asks for — is checked deterministically, and a semantic pass records a finding only when it can quote the exact visible text on the page.
Ownership identity (16%). Who is behind the site: public registration records (RDAP), the registrar and any named registrant organization, a legal entity stated on the page, and a working contact path — and whether those records agree with one another. A privacy service withholding the registrant is reported as withheld, not counted as a lie.
Reputation history (12%). The site's own track record: how long the domain has existed, and what our previous scans of it found. This is history we can attribute to the site itself — not crowd opinion, and not a rating anyone can vote on.
External reputation (10%). How the site is regarded from outside its own pages: authoritative threat and blocklist intelligence (Google Web Risk, abuse.ch URLhaus). Negative-only by design — an adverse listing floors the category and caps the overall score, while a clean result earns no positive credit and is left out of the weighted score entirely. Standing here cannot be bought, and a score cannot be review-bombed down.
Consumer transparency (10%). What a visitor is told before they commit: a privacy policy, terms, a cookie disclosure, a reachable contact channel, and — for a site that actually sells online — a return, refund, or dispute path. A site that sells nothing is not marked down for having no refund policy; that reads as “not applicable,” not “missing.”
Operational resilience (8%). Whether the site is run competently: availability, DNS hygiene (DNSSEC, CAA, MX), and email authentication (SPF, DMARC, and DKIM where a published key can be found).
Critical-risk caps
Some findings are severe enough to cap the final score no matter how clean everything else looks. Each applied cap is recorded with the score and explained on the report. The lowest applicable cap wins.
| Finding | Score capped at |
|---|---|
| Confirmed active malware | 299 |
| Confirmed phishing, or credential/payment harvesting backed by the page itself | 299 |
| High-confidence fraudulent or miracle claims | 399 |
| Clear impersonation or deceptive use of another brand | 499 |
| Multiple severe dark-pattern categories | 499 |
| Domain fails to resolve and no recent valid evidence exists | 499 |
| Invalid TLS while the site still serves over plain HTTP | 699 |
| Drip pricing — the price is revealed only after a quiz or sign-up step, on a confirmed subscription funnel | 599, 499, or 399 — graded by refund recourse |
| Low overall confidence | Band ceiling, scaled to the confidence |
No score for a site that isn't there
A scan reads what a visitor actually lands on. When there is no operating site to trust — the domain redirects to a different registrable domain, shows a parking placeholder, is listed for sale, or has nothing reachable at all — no score is published. The report and the badge state the situation, and name the destination for a redirect, instead of a number that would misrepresent a vacant name. A redirect that stays on the same registrable domain (www to the apex, a subdomain, or http to https) is not a redirect for this purpose and scores normally.
Trust bands
The weighted category values are combined and scaled to 0–1000, then labeled:
| Band | Score |
|---|---|
| Exceptional | 900–1000 |
| Strong | 800–899 |
| Established | 700–799 |
| Mixed | 600–699 |
| Concerning | 500–599 |
| Dangerous | 300–499 |
| Critical Threat | 0–299 |
See real websites scoring in these bands
Confidence is reported separately
Every scan reports a confidence value next to the score: the share of the evidence we expect to collect that was actually reachable. A site that blocks automated visitors, or a registry that publishes nothing, lowers confidence. Confidence never inflates a score — it can only cap the band, so a thinly evidenced scan cannot read as an emphatic endorsement.
When evidence is unavailable
If a category cannot be evaluated at all — every lookup behind it is unreachable, or a bot challenge hides the page — it is excluded and the remaining categories are re-weighted, then marked as excluded on the report. Absence of evidence is not treated as evidence of a problem. If less than half of the model's evidence weight remains collectable, no score is published at all and the report explains what could and could not be checked. Each lookup also has its own time limit, set well beyond what a healthy service needs; a lookup that exceeds it counts as unreachable rather than holding up the rest of the scan.
Versioning
Every completed scan records two versions: the scoring model that produced the number and the evidence-collection version that gathered the inputs, shown on the report as “Model X · collection Y”. When the math, the bands, the caps, or the way evidence is collected changes, the version changes with it. Historical scores keep the version they were computed under and are never silently re-scored — model history records what each version changed.
Not a guarantee
The score measures observable trust signals at the moment of the scan. It is not a certification, a security audit, or a guarantee that a site is safe or a business is honest — and a site can change the day after it is scored. Use the score, and the evidence under it, as one input into your own judgment.