Check a store ↗
TRANSPARENT BY DESIGN

Trust Score methodology

Understand what each component measures, how the overall score is calculated and where the assessment has limitations.

How the score is calculated

The Trust Score is a weighted result from 0 to 100. Only components applicable to the assessed website are included. General websites use Security, Reputation, Transparency and Community. Online stores also include Store Protection.

Website40% Security + 30% Reputation + 20% Transparency + 10% CommunityOnline store30% Security + 25% Reputation + 20% Transparency + 15% Store + 10% Community

The five components

Security

The scanner follows up to five HTTP redirects and validates every destination before connecting. It evaluates the final HTTPS connection, certificate, downgrade behaviour, security headers and cookies. HTTPS and certificate validity carry most of this component; optional headers create only small deductions.

Reputation

Reputation combines current website availability with external phishing and malware intelligence. Domain age is not checked, displayed or used to change the score. Unavailable third-party sources do not create a penalty, and a threat-list match is treated as a serious risk signal.

Transparency

The scanner parses linked privacy, terms, contact, operator and other policy pages. Those pages may be hosted on a separate public domain, which is common for large services. Every linked destination is subject to the same public-address and redirect safety checks.

Store Protection

For detected online stores, the scanner adds returns and refund information to essential purchasing evidence such as terms, seller identity and contact details. It does not place an order or validate inventory.

Community

Uses approved, moderated customer experiences. New reports begin with a neutral community value until enough useful evidence is available.

Evidence discovery for international stores

A global domain may first display a country selector rather than the actual store. The scanner therefore evaluates language alternatives, country routes, a small set of representative internal pages, robots and sitemap declarations, linked policy pages and accessible PDF regulations. Missing evidence caused solely by an automated-access restriction is excluded instead of being scored as zero.

External intelligence

The public OpenPhish feed is cached for six hours. Server-side integrations never expose API keys in reports. Google Safe Browsing may be enabled only for permitted non-commercial use or under a separate agreement; commercial services should use Google Web Risk. URLhaus remains subject to its provider terms. If a provider is unavailable, the report says so and the missing check does not lower the score.

Trust tiers

90–100Very High Trust

Strong combined signals with limited visible concerns.

75–89High Trust

Generally strong evidence, with some items still worth reviewing.

60–74Moderate Trust

Mixed or incomplete evidence. Verify important details independently.

40–59Caution Advised

Material weaknesses or missing transparency require additional care.

20–39Low Trust

Multiple weak signals. Avoid sensitive actions without strong verification.

0–19Critical Risk

Severe or widespread risk signals are present.

What the assessment cannot prove

A report is a current informational snapshot. It cannot guarantee future behaviour, confirm every legal registration, test every page, detect all malware or determine whether every customer claim is true. Websites change, certificates expire and ownership can move. Always check the assessment date and use a protected payment method.