A cybersecurity rating is an external, evidence-based assessment of how well an organization protects its websites, data and email infrastructure. It is calculated from what is visible from the outside, exactly the way an attacker or a prospective customer would see it, without any access to internal systems.
ImmuniWeb® CyberScore™ produces six independent ratings for any domain you enter. It runs entirely from the outside, requires no agents, no credentials and no input from the tested company, making it perfect for checking your own perimeter, your suppliers or a potential acquisition target.
Every performed test is strictly non-intrusive. CyberScore does not attempt to exploit anything, does not send malicious payloads and does not disrupt the systems it analyses.
CyberScore combines six tests into a single report. Each one is graded independently, so you see exactly where the weak spot is instead of a single opaque number.
Scans the company's websites for known web vulnerabilities, outdated or vulnerable CMS and CMS components, insecure HTTP methods, missing Web Application Firewall, weak Content Security Policy and cookie handling. Also covers HTTP security and privacy headers, DNSSEC configuration, AI bot protection, resistance to data scraping, and non-intrusive GDPR and PCI DSS compliance checks. Also available as a standalone tool: Website Security Test.
Tests how the company's websites handle visitor data: tracking cookies and tracking pixels, third-party content and XHR requests that send data to external services, privacy of web forms, and the presence and consistency of the privacy policy. Also available as a standalone tool: Website Privacy Test.
Tests the SSL/TLS stack of the company's web servers: supported protocols and ciphers, certificate validity, cryptographic flaws and misconfigurations, post-quantum cryptography readiness, and compliance with PCI DSS, GDPR, HIPAA and NIST requirements. Also available as a standalone tool: SSL Security Test.
Tests company's mail servers for open relay and SMTP enumeration, authentication enforcement, PTR records, SSL/TLS encryption of mail servers, SPF, DKIM, DMARC and MTA-STS configuration, DNSSEC signing, and presence on spam blacklists. Also available as a standalone tool: Email Security Test.
Detects leaks and incidents involving the tested domain on the Dark Web, including stolen user credentials and compromised databases. Also detects cybersquatting and typosquatting domains, phishing and scam websites, and fake accounts impersonating the company's brand in social networks. It is also available as a standalone tool: Dark Web and Threat Exposure Test.
Detects AI-specific risks that traditional scanners miss: AI-generated and vibe-coded patterns across company's websites, and leaks of AI tokens and other AI-related sensitive data both on the Dark Web and across the web assets. This check is available only as part of CyberScore.
Every test runs separately against each hostname discovered under the tested domain, and each hostname gets its own letter grade from A+ down to F. The rating you see for a service is the average of those individual grades.
Hostnames that could not be tested are excluded from the average instead of being counted as a failure. If a server does not respond, a tested port is closed or a domain does not resolve, it is marked as N and does not affect the rating. A parked or retired subdomain will therefore not drag down the score of a well-configured perimeter.
Dark Web Exposure works differently. Instead of a letter grade you get the number of detected incidents and domain mentions, broken down by source and risk level, because a single letter cannot meaningfully summarize a company's exposure on the Dark Web.
The full scoring methodology of each test is published here: Website Security, Website Privacy, SSL Security.