Methodology

How the WebTrustScore works

WebTrustScore rates a website from 0 to 1000 by combining seven weighted categories of evidence — read from the live site, its public records, and authoritative threat feeds at the moment of the scan. The same rules run on every site, in the same order, and every category shows the evidence behind it.

A score, not a seal of approval

Nobody can pay to raise a score, and no site is reviewed by hand. Each category is computed from what a scan can actually observe, so the same site, read the same way, returns the same score every time.

That cuts both ways: a high score is evidence that the signals we can check look sound, not a promise that a business is honest, and the absence of an adverse finding is reported as exactly that — nothing found — never as an endorsement.

What's in the score, and what's reported alongside

Only the seven weighted categories move the number. Everything else a scan learns is reported next to the score, never folded into it — so the number stays reproducible.

Signal group Role
Seven weighted categories Determine the score
Live-site state — an active site, a parking placeholder, a for-sale listing, a redirect to another domain, or nothing reachable at all Reported alongside — and when there is no site to trust, no score is published at all
Provenance context — site age, link authority, and certificate history Reported alongside — never in the score
Confidence — how much of the expected evidence was actually reachable Reported separately — can only lower the ceiling, never raise the score

Every category also ships its evidence, and severe risks cap the total score outright.

The seven categories

Category Weight What it measures
Security posture 24% Whether the site is safe to visit and use
Content trustworthiness 20% What the site asks you to believe or hand over
Ownership identity 16% Who is behind the site, and whether the records agree
Reputation history 12% The site's own age and track record
External reputation 10% How the site is regarded off its own pages
Consumer transparency 10% What a visitor is told before they commit
Operational resilience 8% Whether the site is run competently

Security posture (24%). Whether the site is technically safe to visit and interact with: HTTPS served by default with a certificate that validates, protective response headers, safe redirect behavior, and malware and phishing checks against authoritative feeds. A confirmed malware or phishing finding caps the whole score.

Content trustworthiness (20%). What the site asks a visitor to believe or hand over: deceptive claims, brand impersonation, credential and payment harvesting, fabricated authority, coercive urgency, hidden costs, and obstructed choice. Page structure — where a form sends what you type, which fields it asks for — is checked deterministically, and a semantic pass records a finding only when it can quote the exact visible text on the page.

Ownership identity (16%). Who is behind the site: public registration records (RDAP), the registrar and any named registrant organization, a legal entity stated on the page, and a working contact path — and whether those records agree with one another. A privacy service withholding the registrant is reported as withheld, not counted as a lie.

Reputation history (12%). The site's own track record: how long the domain has existed, and what our previous scans of it found. This is history we can attribute to the site itself — not crowd opinion, and not a rating anyone can vote on.

External reputation (10%). How the site is regarded from outside its own pages: authoritative threat and blocklist intelligence (Google Web Risk, abuse.ch URLhaus). Negative-only by design — an adverse listing floors the category and caps the overall score, while a clean result earns no positive credit and is left out of the weighted score entirely. Standing here cannot be bought, and a score cannot be review-bombed down.

Consumer transparency (10%). What a visitor is told before they commit: a privacy policy, terms, a cookie disclosure, a reachable contact channel, and — for a site that actually sells online — a return, refund, or dispute path. A site that sells nothing is not marked down for having no refund policy; that reads as “not applicable,” not “missing.”

Operational resilience (8%). Whether the site is run competently: availability, DNS hygiene (DNSSEC, CAA, MX), and email authentication (SPF, DMARC, and DKIM where a published key can be found).

Critical-risk caps

Some findings are severe enough to cap the final score no matter how clean everything else looks. Each applied cap is recorded with the score and explained on the report. The lowest applicable cap wins.

Finding Score capped at
Confirmed active malware 299
Confirmed phishing, or credential/payment harvesting backed by the page itself 299
High-confidence fraudulent or miracle claims 399
Clear impersonation or deceptive use of another brand 499
Multiple severe dark-pattern categories 499
Domain fails to resolve and no recent valid evidence exists 499
Invalid TLS while the site still serves over plain HTTP 699
Drip pricing — the price is revealed only after a quiz or sign-up step, on a confirmed subscription funnel 599, 499, or 399 — graded by refund recourse
Low overall confidence Band ceiling, scaled to the confidence

No score for a site that isn't there

A scan reads what a visitor actually lands on. When there is no operating site to trust — the domain redirects to a different registrable domain, shows a parking placeholder, is listed for sale, or has nothing reachable at all — no score is published. The report and the badge state the situation, and name the destination for a redirect, instead of a number that would misrepresent a vacant name. A redirect that stays on the same registrable domain (www to the apex, a subdomain, or http to https) is not a redirect for this purpose and scores normally.

Trust bands

The weighted category values are combined and scaled to 0–1000, then labeled:

Band Score
Exceptional900–1000
Strong800–899
Established700–799
Mixed600–699
Concerning500–599
Dangerous300–499
Critical Threat0–299

See real websites scoring in these bands

Confidence is reported separately

Every scan reports a confidence value next to the score: the share of the evidence we expect to collect that was actually reachable. A site that blocks automated visitors, or a registry that publishes nothing, lowers confidence. Confidence never inflates a score — it can only cap the band, so a thinly evidenced scan cannot read as an emphatic endorsement.

When evidence is unavailable

If a category cannot be evaluated at all — every lookup behind it is unreachable, or a bot challenge hides the page — it is excluded and the remaining categories are re-weighted, then marked as excluded on the report. Absence of evidence is not treated as evidence of a problem. If less than half of the model's evidence weight remains collectable, no score is published at all and the report explains what could and could not be checked. Each lookup also has its own time limit, set well beyond what a healthy service needs; a lookup that exceeds it counts as unreachable rather than holding up the rest of the scan.

Versioning

Every completed scan records two versions: the scoring model that produced the number and the evidence-collection version that gathered the inputs, shown on the report as “Model X · collection Y”. When the math, the bands, the caps, or the way evidence is collected changes, the version changes with it. Historical scores keep the version they were computed under and are never silently re-scored — model history records what each version changed.

Not a guarantee

The score measures observable trust signals at the moment of the scan. It is not a certification, a security audit, or a guarantee that a site is safe or a business is honest — and a site can change the day after it is scored. Use the score, and the evidence under it, as one input into your own judgment.