SCAN CHECKS REFERENCE

What PrivacyScan checks and how it grades

Every automated check, the result it looks for, and the exact formula behind the Score Index.

Score Index formula

  1. 01Each check has a severity weight: info=1, low=3, medium=8, high=15, critical=25.
  2. 02Pass earns the full weight. Warn earns 80%. Fail earns 0%. Not-verifiable (NV) is ignored.
  3. 03Category score = earned weight / max weight for that category.
  4. 04Overall raw base = weighted average of category scores, using the category weights shown above.
  5. 05Base is lifted by 18% toward 100 so partial coverage is not overly punished (0 and 100 stay fixed).
  6. 06A flat penalty of 2 points is applied for each category with a high or critical fail, capped at 8 points.
  7. 07Final score is rounded and clamped between 20 and 100.
A
90–100
B
80–89
C
70–79
D
55–69
F
< 55
https_usedSite served over HTTPS
PASSResponse scheme is https://.
FAILSite loads over plain http://.
cert_validTLS certificate validates
PASSHTTPS request completed without a certificate error.
N/VNot evaluated because the site is not using HTTPS.
hsts_headerStrict-Transport-Security header
PASSHSTS present with max-age >= 6 months and includeSubDomains.
WARNHSTS present but weakly configured (short max-age or missing subdomains).
FAILHSTS header missing.
mixed_contentNo mixed HTTP content
PASSNo http:// sub-resources found on any audited HTTPS page.
FAILOne or more pages load http:// resources on an HTTPS site.
form_httpsForm actions submit over HTTPS
PASSAll detected forms post to HTTPS endpoints.
FAILOne or more form actions target http://.
N/VNo forms detected on audited pages.
dns_spfSPF DNS record
PASSSPF TXT record present with strict -all or ~all.
WARNSPF present but permissive (+all / ?all).
FAILNo SPF record on a domain that sends mail.
N/VNo MX records — domain not configured for email.
dns_dmarcDMARC DNS record
PASSDMARC policy is p=quarantine or p=reject.
WARNDMARC present but policy is p=none.
FAILNo DMARC record on a domain that sends mail.
dns_dkimDKIM selector
N/VDKIM requires a provider-specific selector to verify.
dns_caaCAA DNS record
PASSCAA record restricts which certificate authorities may issue.
WARNNo CAA record — any CA may issue certificates.
hsts_preload_eligibilityHSTS preload eligibility
PASSHSTS header meets preload criteria (max-age >= 1 year, includeSubDomains, preload).
WARNHSTS header not eligible for browser preload list.
hsts_preload_statusHSTS preload list status
PASSDomain is already on the Chrome HSTS preload list.
WARNEligible but not yet submitted to hstspreload.org.
reachabilitySite reachable
PASSHomepage returned an HTTP response.
FAILTarget could not be reached from the public scanner.
robots_respectrobots.txt allows scan
PASSCrawl permitted by robots.txt.
N/Vrobots.txt disallows the homepage scan.
csp_headerContent-Security-Policy
PASSCSP present on all audited pages and does not use unsafe-inline, unsafe-eval, or wildcard sources.
FAILCSP missing on all audited pages.
WARNCSP missing on some pages, or present but using weak directives.
x_frame_optionsClickjacking protection (X-Frame-Options / frame-ancestors)
PASSX-Frame-Options or CSP frame-ancestors present on every audited page.
FAILMissing on all pages.
WARNMissing on some pages.
x_content_type_optionsX-Content-Type-Options: nosniff
PASSnosniff set on all audited pages.
WARNMissing on some or all pages.
referrer_policyReferrer-Policy
PASSStrong policy (no-referrer, strict-origin, same-origin) on all pages.
WARNMissing on some/all pages, or present but permissive.
permissions_policyPermissions-Policy
PASSPermissions-Policy (or legacy Feature-Policy) present on all pages.
WARNMissing on some or all pages.
coop_headerCross-Origin-Opener-Policy
PASSCOOP header present on all pages.
WARNMissing on some or all pages.
server_disclosureServer version disclosure
PASSNo Server version or X-Powered-By header across audited pages.
WARNServer / X-Powered-By leaks version information on at least one page.
cookie_inventoryCookie inventory on first response
PASSOnly essential cookies are set before any consent.
FAILKnown tracker/advertising cookies are set pre-consent.
WARNNon-essential/unknown cookies are set pre-consent.
cookie_flagsCookie security flags
PASSAll cookies have Secure, HttpOnly, and SameSite flags.
FAILOne or more cookies are missing Secure, HttpOnly, or SameSite.
third_party_cookiesThird-party scoped cookies
PASSNo cookies scoped to third-party domains.
WARNOne or more cookies are scoped to an external domain.
cookie_retentionCookie retention lifetime
PASSNon-essential cookies expire within 6 months.
WARNOne or more non-essential cookies live longer than 6 months.
third_party_trackersKnown tracker vendors
PASSNo known tracker vendor hosts detected on the homepage.
WARNOne or more known tracker vendors detected.
trackers_pre_consentTrackers load before consent
PASSTrackers only load after affirmative consent.
FAILTrackers detected before consent, or no CMP was found at all.
cookie_banner_presentCookie consent banner or CMP
PASSCMP marker or consent banner copy detected in the DOM/bundle.
FAILNo cookie consent banner detected on the homepage.
reject_allReject-all control
PASSReject-all / decline / only-necessary control appears as an interactive element.
WARNReject-all wording present but not as a clickable control, or missing while Accept is present.
granular_consentGranular consent categories
PASSPer-purpose toggles (analytics, marketing, functional, etc.) detected.
WARNNo granular categories detected.
withdraw_consentWithdraw consent / persistent settings
PASSPersistent cookie settings/preferences link or icon detected.
WARNNo persistent cookie-settings entry point found.
no_precheckNo pre-checked consent boxes
PASSNo pre-checked consent checkboxes found in markup.
FAILPre-checked checkbox found in consent markup.
prevents_preconsentOnly essential cookies before consent
PASSOnly essential cookies observed before consent.
FAILNon-essential cookies set before consent.
consent_string_decodedIAB TCF / GPP consent string decoded
PASSA consent string was detected and decoded.
cmp_banner_renderedCMP banner rendered
PASSCMP banner rendered in the headless DOM.
cmp_installedCMP script installed
PASSCMP script or iframe source detected.
consent_mode_diffConsent-mode diff (pre vs post consent)
PASSTrackers only load after consent, or no trackers are observed at all.
FAILTracker count does not change after consent — CMP appears non-functional.
WARNTrackers already present before consent.
privacy_policy_linkedPrivacy policy linked from homepage
PASSPrivacy policy link found on the homepage.
FAILNo privacy policy link found on the homepage.
dpo_disclosedData Protection Officer disclosed
PASSDPO / privacy officer mentioned on public pages.
FAILNo DPO mention found on public pages.
dpo_contact_detailsDPO contact details published
PASSDedicated dpo@ / privacy@ mailbox and phone number published.
FAILDPO mentioned but no contact email or phone found.
WARNPartial details published (e.g. email but no phone, or no dedicated mailbox).
spa_ssr_missingPrivacy pages server-rendered
WARNPrivacy-relevant pages are client-rendered (SPA) and may be invisible to scanners and assistive tech.
cookie_policy_presentCookie policy present
PASSDedicated cookie policy page located.
FAILNo cookie policy or privacy policy located.
WARNCookie disclosures only inside the general privacy policy.
cookie_policy_purposesCookie purposes disclosed
PASSPurposes of cookie use disclosed in prose, heading, or table layout.
FAILNo purposes of cookie use found.
cookie_policy_categoriesCookie categories disclosed
PASSEssential / analytics / marketing / functional categories listed.
FAILNo cookie categories found.
cookie_policy_retentionCookie retention disclosed
PASSCookie lifetimes/retention described.
FAILNo retention/lifetime information found.
cookie_policy_third_partiesThird-party cookie providers disclosed
PASSThird-party recipients/providers named.
FAILNo third-party providers disclosed.
cookie_policy_optoutWithdraw / manage consent explained
PASSHow to change or withdraw cookie preferences is explained.
FAILNo opt-out/withdrawal instructions found.
cookie_policy_contactCookie / privacy contact channel
PASSContact channel for cookie/privacy questions disclosed.
FAILNo contact channel found.
cookie_policy_freshnessCookie policy freshness
PASSPolicy dated within the last two years.
WARNPolicy older than two years, or no date found.
mentions_lawful_basisPrivacy policy mentions lawful basis
PASSLawful basis / legal basis / legitimate interest mentioned.
FAILNo lawful basis statement found.
mentions_ndpaPrivacy policy references NDPA / GDPR
PASSNDPA, GAID, or GDPR explicitly cited.
FAILNo regulatory framework reference found.
mentions_dpoPrivacy policy mentions DPO
PASSDPO or privacy officer mentioned.
FAILNo DPO mention in the policy.
mentions_retentionPrivacy policy states retention periods
PASSRetention periods described.
FAILNo retention periods found.
mentions_data_rightsPrivacy policy explains data subject rights
PASSRights (access, erasure, rectification, object) explained.
FAILNo data subject rights explanation found.
mentions_third_partiesPrivacy policy discloses third-party recipients
PASSThird-party recipients/processors named.
FAILNo third-party recipients disclosure found.
mentions_intl_transferPrivacy policy addresses international transfers
PASSInternational transfers / cross-border / SCCs mentioned.
FAILNo international-transfer disclosure found.
mentions_complaintPrivacy policy provides complaint mechanism
PASSComplaint / regulator / supervisory authority mentioned.
FAILNo complaint mechanism found.
mentions_contactPrivacy policy publishes organisation contact
PASSOrganisation name, address, or email in the policy.
FAILNo organisation contact details found.
rights_request_surfaceData-subject request surface
PASSDedicated DSAR / privacy-request page linked.
WARNRights described in text or mailbox present, but no dedicated form.
FAILNo data-subject rights request surface found.
right_to_erasure_surfaceRight to erasure / account deletion
PASSDelete / erasure surface detected.
FAILNo account-deletion or right-to-erasure surface found.
rights_consent_linkageRights and consent surfaces linked
PASSRights surface links to consent preferences and vice versa.
WARNBoth surfaces exist but are not cross-linked.
exposed_api_key_genericGeneric API key / secret / token
PASSNo generic API key/secret pattern found.
FAILPotential API key / secret / token exposed in public assets.
exposed_aws_keyAWS access key
PASSNo AKIA... AWS access key found.
FAILAWS access key exposed.
exposed_google_keyGoogle API key
PASSNo AIza... Google API key found.
FAILGoogle API key exposed.
exposed_slack_tokenSlack token
PASSNo Slack token found.
FAILSlack token exposed.
exposed_jwtJWT / signed token
PASSNo unsafe JWT found (Supabase anon/publishable tokens are treated as safe-by-design).
FAILService-role or otherwise unsafe JWT exposed.
exposed_private_keyPrivate key material
PASSNo PEM private key found.
FAILPrivate key material exposed in public files.
exposed_emailsExposed email addresses
PASSNo real email addresses exposed on public pages.
WARNReal email addresses found on public pages (business contacts may be intentional).
pii_cleanNo exposed PII/credentials
PASSNo publicly exposed credentials or PII patterns detected.
html_langDocument language
PASS<html lang="..."> is declared.
FAILMissing <html lang> attribute.
page_titlePage title
PASSDescriptive <title> present.
FAILMissing or empty <title>.
img_altImage alt text
PASSAll <img> tags declare alt text.
FAILMore than 30% of images are missing alt.
WARNSome images are missing alt (<= 30%).
N/VNo <img> elements found on this page.
form_labelsForm control labels
PASSAll form controls have accessible names (label, aria-label, aria-labelledby, or title).
FAILAll form controls missing accessible names.
WARNSome form controls missing accessible names.
N/VNo user-facing form controls on this page.
heading_structureHeading outline
PASSExactly one <h1> and no skipped levels.
WARNNo headings, multiple <h1>, or heading levels skipped.
main_landmarkMain landmark
PASSSingle <main> landmark present.
FAILMultiple or no <main> landmarks.
viewport_zoomViewport zoom allowed
PASSViewport allows user zoom.
FAILViewport blocks user zoom (user-scalable=no or maximum-scale=1).
skip_linkSkip-to-content link
PASSSkip-to-content link detected.
WARNNo skip-to-content link found.
accessibility_statementAccessibility statement
PASSAccessibility / WCAG / ADA compliance statement referenced.
WARNNo accessibility statement linked from the homepage.
accessibility_contactAccessibility feedback channel
PASSAccessibility feedback channel present.
WARNNo accessibility feedback channel found.
media_captionsMedia captions
PASSCaption tracks look present on videos.
FAILAll <video> elements missing caption tracks.
WARNSome videos missing caption tracks.
N/VNo embedded video/audio detected.
tabindex_positivePositive tabindex
PASSNo positive tabindex values found.
WARNPositive tabindex values detected — breaks natural focus order.
aria_hidden_focusableFocusable elements inside aria-hidden
PASSNo focusable controls found inside aria-hidden containers.
FAILFocusable elements found inside aria-hidden container.
autoplay_mediaAutoplaying media
WARNAutoplaying media detected — provide a pause control.
cmv2_applicableGoogle tag ecosystem present
PASSGoogle gtag/GTM/GA detected — Consent Mode v2 is required.
N/VNo Google tag ecosystem detected — Consent Mode v2 not applicable.
cmv2_defaultgtag('consent','default',…)
PASSDefault consent call present before any measurement tag.
FAILMissing default consent initialisation.
cmv2_updategtag('consent','update',…)
PASSUpdate call wired to CMP detected.
WARNNo consent update call detected.
cmv2_signalsad_user_data & ad_personalization signals
PASSBoth required v2 signals present.
FAILOne or both required signals missing.
cmv2_ads_data_redactionads_data_redaction enabled
PASSads_data_redaction=true configured.
WARNads_data_redaction missing or disabled.
cmv2_url_passthroughurl_passthrough configured
PASSurl_passthrough configured.
WARNurl_passthrough missing.
static_analysis_availableStatic source scan available
N/VRequires authorised source or APK upload via the Static Analysis screen.
hardcoded_secretHardcoded API key or secret
PASSNo hardcoded secret detected in uploaded source.
FAILHardcoded API key / secret / token / password found.
aws_keyAWS access key hardcoded
PASSNo AKIA... key in uploaded source.
FAILAWS access key hardcoded in source.
google_keyGoogle API key hardcoded
PASSNo AIza... key in uploaded source.
FAILGoogle API key hardcoded in source.
insecure_storageInsecure local storage of credentials
PASSNo sensitive values stored in localStorage / SharedPreferences.
FAILSensitive key/value pattern found in local storage usage.
disabled_pinningCertificate pinning disabled
PASSCertificate pinning not explicitly disabled.
FAILPinning disabled flag or debug config found.
verbose_loggingVerbose logging in production
PASSNo debug/verbose logging flags in production build.
FAILDebug / verbose logging enabled in production code.
vulnerable_dependencyVulnerable dependency version
PASSNo known-vulnerable version strings detected.
FAILDependency version matches a known vulnerable range.