Mega Report Scoring Rubric

The Mega Report assigns your website an overall health grade from A (excellent) to F (critical) based on the combined findings across all test sections. Here is exactly how grades are calculated.

Overall Health Grade

The grade is calculated from the total count of findings across all enabled test sections. Findings are categorized by severity and the thresholds below are evaluated in order:

Grade Label Condition
A Excellent No critical, high, or medium findings; low ≤ 20
B Good Any medium findings OR more than 20 low findings
C Needs Improvement Any high findings OR more than 10 medium findings
D Poor More than 5 high severity findings
F Critical Any critical findings (1 or more)
Evaluation order: Grades are evaluated from F upward. If any critical finding exists the grade is F, regardless of other counts. Then high counts are checked for D, and so on.

Severity Levels

Every finding is assigned one of five severity levels:

Info findings and grading: Info-level findings are counted and displayed in reports but do not directly affect the A–F grade. The grade calculation only considers critical, high, medium, and low counts.

Per-Test Scoring Criteria

Each test section contributes findings to the overall grade. Here is how each test maps findings to severity levels:

Accessibility (WCAG)

WCAG compliance testing (AA or AAA level) using axe-core automated scanning.

Note: Automated accessibility tests cover less than 60% of WCAG criteria. Full WCAG conformance requires manual testing.

Security Scan

OWASP-based security validation including security headers, SSL/TLS, and vulnerability detection.

Meta Tags

Validates Open Graph, Twitter Card, and standard meta tags.

HTML Validation

HTML validation against W3C standards using the Nu Html Checker.

SEO Test

Comprehensive SEO analysis covering page structure, content quality, and technical SEO factors.

Page Size & Performance

Resource inventory and page performance analysis with specific size thresholds.

Page SizeSeverity
> 10 MBCritical
> 5 MBHigh
> 3 MBMedium
> 1.5 MBLow
ResourceSeverity
Any file > 5 MBCritical
Image > 1 MBHigh
Image > 500 KBMedium
Image > 200 KBLow
PNG > 100 KB (no WebP)Info

Secrets Detection (Gitleaks)

Detects hardcoded secrets, API keys, and credentials in git history.

Supply Chain Vulnerabilities (OSV)

Dependency vulnerability scanning using the Open Source Vulnerabilities database.

CVSS ScoreSeverity
≥ 9.0Critical
≥ 7.0High
≥ 4.0Medium
> 0Low
Important: OSV findings without CVSS scores (or invalid/zero scores) are promoted to high severity to ensure they are properly prioritized. All OSV findings are treated as real security issues and included in the overall grade.

Static Analysis (Semgrep / OpenGrep)

Code quality and security analysis using Semgrep and OpenGrep engines.

Link & Content Analysis

These tests analyze link integrity, redirect behavior, metadata consistency, structured data, image optimization, site structure, and content uniqueness across your pages.

Broken Links

Checks all internal and external links for broken URLs (404, 5xx, timeouts).

Redirect Analysis

Analyzes redirect chains for loops, excessive hops, and mixed protocols.

Canonical URL Validation

Validates canonical URL tags for correctness and consistency.

Hreflang Validation

Validates hreflang alternate language tags and cross-references between pages.

Structured Data Validation

Validates JSON-LD structured data against Schema.org types and Google rich result requirements.

Image Optimization

Checks images for alt text, dimensions, lazy loading, file size, and format optimization.

Internal Link Structure

Analyzes internal link graph for orphan pages, click depth, and discoverability.

Duplicate Content Detection

Detects duplicate titles, descriptions, thin content, and near-duplicate page content.

Console Errors (Browser-based)

Loads the page in a headless WebView and captures JavaScript console errors, uncaught exceptions, network failures, CORS errors, CSP violations, mixed content warnings, and deprecated API usage. Available on all platforms.

Improving Your Grade

  1. Fix critical issues first — any critical finding results in an F grade
  2. Address high issues — more than 5 high issues drops you to D; any high issue drops you to C
  3. Reduce medium issues — more than 10 medium issues drops you to C
  4. Manage low issues — more than 20 low issues drops you to B
  5. Address OSV findings — they are treated as real security issues; findings without CVSS scores are promoted to high
  6. Re-run the report — after fixing issues, generate a new Mega Report to see your improved grade

Related Resources