Methodology
How we score a website
A score you can't question is just a number. So here is exactly how ours works: what we check, how much each kind of problem costs, and where the method is limited. Every figure on this page is read straight from the code that calculates your score.
The short version
We read your homepage and up to seven other pages in a real browser, run a Google Lighthouse test on a simulated phone, and check your security, search and email set-up. Each problem we find gets a severity. Each area (security, SEO, speed and so on) starts at 100 and loses points for its problems. The overall score is a weighted average of the areas, with extra deductions for the few problems that stop a site working at all.
Seven areas, weighted
| Area | Weight | What it covers |
|---|---|---|
| Security HTTPS and certificate health, security headers, exposed files, email spoofing protection (SPF/DMARC), cookie consent. | 20% | HTTPS and certificate health, security headers, exposed files, email spoofing protection (SPF/DMARC), cookie consent. |
| SEO Titles, descriptions, headings, duplicates across pages, sitemaps, indexing mistakes, structured data. | 20% | Titles, descriptions, headings, duplicates across pages, sitemaps, indexing mistakes, structured data. |
| Speed A Lighthouse run on a throttled phone, server response, page weight, images, blocking scripts. | 20% | A Lighthouse run on a throttled phone, server response, page weight, images, blocking scripts. |
| Accessibility Colour contrast, labels, alt text, keyboard access, checked in a real browser with the axe engine. | 15% | Colour contrast, labels, alt text, keyboard access, checked in a real browser with the axe engine. |
| Mobile Sideways scrolling, tiny text, viewport, tap-to-call. | 10% | Sideways scrolling, tiny text, viewport, tap-to-call. |
| Content & conversion Calls to action, contact routes, trust signals, readability, stale content, local-business signals. | 10% | Calls to action, contact routes, trust signals, readability, stale content, local-business signals. |
| Technical health Broken links and pages, failed files, JavaScript errors, domain and certificate expiry. | 5% | Broken links and pages, failed files, JavaScript errors, domain and certificate expiry. |
Security, SEO and speed carry the most weight because they decide whether people can find, trust and use a site.
How serious is a problem?
The site is failing at something basic: it can't be found, can't be trusted or can't be used.
A clear problem that costs visitors, rankings or trust right now.
A real improvement that makes the site stronger, but nothing is broken.
Polish. Shown (free with your email) but never counted against your score.
Severity depends on how much of the problem there is. One link with no accessible name is a small detail. Forty of them is a real accessibility problem. The same goes for missing image text, unlabelled form fields, low-contrast text, broken links and blocking scripts. A problem found on every page you have costs more than the same problem on one page (between 60% and 100% of its points, depending on how many pages it affects).
The formula
- Each area: add up the points for its problems, then the area score is
100 × e(−points ÷ 60). It falls quickly for the first few problems and then slows, so one more problem on an already-struggling area matters less than the first did, and no area ever hits a hard zero. - Overall: the weighted average of the seven area scores, using the weights above.
- Critical problems: take an extra 10 points off the overall score each (at most 25 in total).
- Showstoppers: a few problems mean the site effectively doesn't work, so the overall score can't go above 45 while one is present.
- Small details never change the score.
Overall bands: 90–100 Excellent (grade A) · 80–89 Good (grade B) · 68–79 Fair (grade C) · 50–67 Needs work (grade D) · 0–49 At risk (grade F).
The showstoppers
- There is no real website at the address (a hosting placeholder or an empty page)
- The homepage tells Google not to index it
- robots.txt blocks every search engine
- The security certificate has expired
- The domain name has expired
- The site isn't served over HTTPS
A worked example
A site with two moderate SEO problems, one serious accessibility problem, one serious speed problem and one moderate content problem:
| Area | Points off | Area score | Weight |
|---|---|---|---|
| Security | none | 100 | 20% |
| SEO | −6 | 90 | 20% |
| Speed | −8 | 88 | 20% |
| Accessibility | −8 | 88 | 15% |
| Mobile | none | 100 | 10% |
| Content & conversion | −3 | 95 | 10% |
| Technical health | none | 100 | 5% |
Weighted overall: 93 (Excellent). Add one critical content problem and it drops to 81. Make that critical problem “the site isn't served over HTTPS”, a showstopper, and the score is held to 45.
How we calibrated it
We first scored 40 real small-business websites (clinics, dentists, law and conveyancing firms) and found our early scoring was too harsh: none reached 80, and typical healthy sites looked mediocre. We rebuilt it so that the problems that matter drive the score, the small stuff doesn't, and the ranking still matches common sense: unpublished, hidden or insecure sites land at the bottom, polished ones at the top. We re-check this whenever the scoring changes.
Measured, estimated and verified
These three words mean different things in your report, and we keep them apart.
- Measured. The score at the top comes only from a scan we ran. It never changes unless you scan again.
- Estimated. When you tick “Mark fixed”, that is your own note. We may show what your score could be if everything you ticked really is fixed, always labelled as an estimate. It is never added to your measured score.
- Verified. After you re-scan, we compare the two scans. An issue the first scan found and the new scan doesn't is shown as “no longer detected”. That verifies the result on your site. It does not tell us what you changed.
What “tested fix” means
We only show a fix once we've verified it. Right now that's 30 fixes. We have drafted more (54 others) that you will never see until they're verified; for those you can ask us to review them for you. Each verified fix carries a record of how, visible on the fix itself. There are three kinds of evidence:
- Automated test. We build a page with the problem and confirm our scanner flags it. We apply the fix's own code snippet, not a hand-written stand-in, and confirm the flag clears and no new problems appear.
- Real websites. We take the real pages of live sites, apply the fix to a copy, and re-scan it to check the issue clears there too, not just in our own test pages.
- Official documentation. Where a fix involves a platform's settings (WordPress, Wix, Squarespace, Shopify), we check the menu steps against that platform's own help pages. Steps we have checked are marked ✓ on the fix; the rest are general guidance, because menus change between versions and plans.
What this does not prove: that a fix suits every site. A fix can still depend on your theme, plugins, host or plan. That's why every fix tells you to re-scan afterwards. If the issue doesn't clear, tell us. Evidence last gathered 30 September 2026.
What the score can't tell you
- It is automated. It finds real, measurable problems but can't judge whether your design is good or your copy persuasive.
- The speed test runs from Google's servers on a throttled phone, so sites hosted far from the US can read slower than most of their local visitors experience. Treat it as a comparison, not a stopwatch.
- A finding describes what we observed. “Why it can matter” describes possible consequences, not outcomes we have measured for your business. We don't claim an issue will cost you rankings, customers or money, and nothing here is legal advice.
- We read up to eight pages. A very large site is sampled, not fully audited.
- Some sites block automated visitors. When we can't read a site we say so instead of guessing.
Think a score is wrong? That's useful to us. Email [email protected] with the address and what looks off, and we'll check it.