Current rubric: wsi-2026-v2

How the Web Security Index is calculated

WSI is a transparent, rubric-based indicator of security controls observable from a public website homepage. It is designed for repeatable comparisons across large cohorts—not as a substitute for a penetration test, compliance audit, or statement that a site is secure.

Score at a glance

WSI = CS + COS + NPS
CS
0–50
COS
0–50
NPS
0–50

Total range: 0–150 points per origin.

Scoring principles

Observable evidence

Points come from HTTP response headers and directly observed protocol, TLS, DNSSEC, cookie, and SRI facts. Missing or unobservable evidence receives no points.

Additive and reproducible

Each passing check contributes its published weight. There are no hidden multipliers, model-generated security scores, or manual country adjustments.

One origin, one score

The rubric evaluates the stored observation for an origin. The three components are summed to produce its WSI value on the 0–150 scale.

Context stays separate

CrUX LCP/TTFB and page category help explain the cohort but do not add to or subtract from WSI.

Current rubric

The active rubric is Web Security Index v2 (`wsi-2026-v2`). Every component has a maximum of 50 points.

Content Security

CS component

Maximum 50
Observed controlPoints
Strict-Transport-Security10
Cookies: Secure8
Cookies: HttpOnly8
Cookies: SameSite8
Subresource Integrity6
Referrer-Policy5
X-Content-Type-Options5

Cross-Origin Security

COS component

Maximum 50
Observed controlPoints
Content-Security-Policy20
Access-Control-Allow-Origin10
Access-Control-Allow-Methods5
Cross-Origin-Opener-Policy5
Cross-Origin-Embedder-Policy5
Cross-Origin-Resource-Policy5

Network & Protocol Security

NPS component

Maximum 50
Observed controlPoints
Modern HTTP (HTTP/2 or HTTP/3)20
Valid TLS certificate15
DNSSEC enabled15

Current semantic limit: response-header checks award points for observed presence. The rubric does not yet grade the full policy quality of CSP, CORS, or other header values. Boolean checks such as TLS validity, cookie flags, SRI, and DNSSEC require an affirmative observed fact.

From origins to public aggregates

  1. 1

    Origin

    The rubric produces CS, COS, NPS, and WSI for each usable homepage observation.

  2. 2

    Country and rank cohort

    Country values are arithmetic means across eligible origins in the same measurement and rank cohort.

  3. 3

    Category

    The same origin scores are grouped by the stored eight-category classification for explanatory breakdowns.

  4. 4

    Regional summaries

    When category summaries are combined, the portal uses origin-weighted means so a small category cannot count as much as a category with thousands of sites.

Versioning and publication integrity

Rubrics are versioned. A published measurement is pinned to the rubric used for its public aggregates, so later private re-scoring cannot silently rewrite historical results. A new rubric can be computed and reviewed separately before any future publication decision.

Interpretation and limitations

  • Higher means more observed controls, not absence of vulnerabilities. WSI does not test application logic, authentication, authorization, patch level, malware, or internal infrastructure.
  • A score is time- and vantage-point-specific. CDN behavior, geolocation, transient failures, redirects, and bot challenges can affect observable evidence.
  • Missing evidence is distinguishable from cohort coverage. Public pages show sample counts and measurement periods so comparisons can be interpreted within the same population.
Read how measurements are collected