Diese Seite ist nur auf Englisch verfügbar.
Security score
How Vulnara's 0-100 security score is calculated for a scan, a repository, a git workspace and your whole workspace, what lowers it and how the trend is drawn.
The security score is one number from 0 to 100 that says how exposed your code is. Higher is better. Vulnara scores every successful scan, every repository, every git workspace and your workspace as a whole, and shows how the score has moved over time.
What it is for
- Comparing repositories at a glance and seeing which one to fix first.
- Tracking whether your posture is getting better or worse over weeks and months.
- Giving people outside the security team a number they can read without knowing what each finding means.
How it works
What lowers the score
Every repository starts from 100. Each open finding takes risk away from that, and the score is what is left. How much a finding costs depends on:
- Severity: the biggest factor, and deliberately steep. One critical finding costs far more than several low ones, so a pile of low-severity noise does not score the same as a handful of criticals.
- Confidence: how sure the scanner is that the finding is real.
- Exploitability and exposure: whether the issue is known to be exploitable and how reachable it is. Where a scanner gives no information, Vulnara assumes middle values rather than treating the finding as harmless.
Findings are counted as real problems, not scanner rows. The same finding reported by three scanners counts once, at its worst. Repeats of the same root cause in one repository add only a small extra amount each, up to a limit. See One finding, many scanners.
The score stops at 0. It never goes negative.
Caps for serious findings
Some findings cap the score, however little else is open:
- A high-severity finding reported with high confidence keeps the score off the top of the scale.
- A critical finding reported with high confidence keeps the score below the Good band.
- A critical finding that is known to be exploitable keeps it in Needs attention, and one that is actively exploited caps it lower still.
Bands
The web app and PDF reports label a score with a band:
- Strong: 80 and above.
- Good: 60 to below 80.
- Fair: 40 to below 60.
- Needs attention: below 40.
A repository with no scored scan shows as not scanned (Not assessed in reports), not as 0. Unscanned is not the same as clean, and never-scanned repositories are left out of the average rather than pulling it up or down.
Repository, git workspace and workspace scores
- Scan: each successful scan is scored on its own findings. Failed and cancelled scans get no score.
- Repository: based on the latest scored scan from each scanner that has scanned it.
- Git workspace and workspace: a blend of the repository scores. It is the average, pulled down by the worst repository, so one badly exposed repository shows in the headline number even when every other repository is healthy. The dashboard headline, the score trend and each git workspace use the same blend.
Decisions
Triage decisions affect the score. False positive, Not affected and Already dealt with take a finding out of the score. Will not fix and Defer hide it from the working list but keep it in the score, because the risk has not gone away. See Triage findings.
Trend
The trend replays the score day by day. On a day a repository was not scanned, its last known score carries forward, and scans from before the period seed the starting point so the line does not start from nothing. Long periods are thinned to fewer points but always keep the first and last day. The last point always equals the current headline score, so the chart and the headline never disagree.
What you can set
The calculation is not configurable. What moves the score is what you do about findings:
- Fix and rescan: a fixed finding drops out when the next scan no longer reports it.
- Triage: record a decision that clears the finding when it is a false positive, not affected or already dealt with.
- Ignore paths: exclude test fixtures, vendored code and other files you do not want scanned. See Ignore paths.
Do it
- Open Dashboard in the web app at vulnara.rso.dev to see the workspace score, its band and its trend.
- Open Repositories to compare repository scores, or a git workspace under Workspaces to see its score.
- Open a scan result to see the score that scan was given.
Through the API:
- GraphQL: dashboardAnalytics returns
averageSecurityScore,previousAverageSecurityScore,scoreTrendandtopRiskRepositories. repository and repositories returnsecurityScoreandscoreHistory, and scanResult returns the scan'ssecurityScore. - MCP (read only): dashboard_analytics, repositories and scan_result.
Good to know
- Scores are versioned. When the calculation changes, scans scored earlier keep the score they were given, so history is not rewritten.
- A scanner that finds only vulnerable dependencies still lowers the score: dependency findings count as well as code findings.
- A scan that failed or was cancelled has no score, so it cannot drag the average down or make a repository look clean.