The scan report contains a lot of data. Here's how to read it and what to do with each section.

A site scoring 53 looks fine in your browser — but a WebPulse scan flagged it suspicious before you lost a dollar.

Every section of a WebPulse scan report encodes a specific action signal, and first-time users who learn to read them together make faster, more confident vetting decisions than those who rely on gut feel alone.

Why the WebPulse Score Number Routinely Misleads First-Time Users

A single number feels authoritative. When a WebPulse scan returns a score, most first-time users treat it as a verdict—a grade that either clears a domain or flags it for rejection. That instinct is understandable, but it leads to costly misreads that more experienced analysts have learned to avoid.

The score is a summary compression. It collapses multiple dimensions of scan data into one output so that dashboards remain scannable at a glance. The problem is that compression always discards information, and in threat intelligence, discarded information is where the real story lives. A domain with a reassuring score can still carry behavioral signals, scan-volume anomalies, and count distributions that together tell a very different story than the headline number suggests.

Consider what a WebPulse report actually contains beneath that score. The full structure includes risk-tier percentages that show how threat classifications are distributed across all scans, absolute count figures for each risk tier, and a recent scan intelligence field that captures emerging signals outside the historical aggregate. Each of those fields answers a question the score cannot: not just what the overall pattern looks like, but how stable that pattern is, how frequently threatening behavior appears in real numbers, and whether anything has changed recently that the aggregate hasn't caught up to yet.

With only 13 total scans on record for a given domain, for example, a score built on that sample carries far less statistical weight than the same score built on thousands of scans. The number looks identical either way. Nothing about a standalone score communicates that fragility.

This is the core orientation every new user needs before diving into a report: the score is an entry point, not a conclusion. It tells you where to look next, not what decision to make. The sections that follow in this walkthrough each address a specific field in the report and explain what that field adds that the score alone cannot provide. Reading them in sequence is how single-number confusion becomes confident, evidence-backed vetting.

How Risk Percentages and Scan Volume Put the Score in Context

The three percentage fields — low_pct, med_pct, and high_pct — are where a WebPulse report begins to reveal its real story. Each one expresses what share of all completed scans fell into that risk tier, and reading them as a trio rather than individually is what separates a useful interpretation from a misleading one.

Consider a report showing low_pct: 38, med_pct: 31, and high_pct: 31. At a glance, the low-risk category holds the plurality, which might feel reassuring. But notice that medium and high risk together account for 62 percent of scan results — nearly two-thirds of all activity. A score that lands in "acceptable" territory can coexist with that distribution, which is precisely why the aggregate number covered in the previous section earns so little trust on its own. The percentages reframe the score by showing the underlying split.

The high_pct figure deserves particular attention whenever it approaches or matches another tier. When high_pct sits at 31 and med_pct also sits at 31, that symmetry is a signal worth pausing on. It means the domain's scan history is essentially split three ways, with no dominant pattern of clean behavior. A domain trending toward safety would show a dramatically larger low_pct and a shrinking high_pct — not a three-way near-tie.

Scan volume is the second lens here. Percentages are only as meaningful as the sample producing them. A high_pct of 31 drawn from dozens of scans carries far more weight than the same figure drawn from a handful. The total field anchors all three percentages to reality: it tells you whether you are looking at a statistically meaningful pattern or an artifact of sparse data. A small total should raise your skepticism about any percentage, even a favorable one, because thin samples shift dramatically with a single new scan.

Reading low_pct, med_pct, and high_pct together — and always against the backdrop of total — converts three isolated numbers into a coherent risk distribution. That distribution is what you actually need to make a confident vetting call.

What Raw Counts Reveal That Percentages Quietly Hide

Percentages are ratios. They describe proportion elegantly, but they erase one critical dimension: scale. A domain logging a high-risk rate of 30% sounds alarming until you learn it generated only ten scans total. The same rate across ten thousand scans is a different category of problem entirely. Raw counts exist in the report precisely to restore that missing dimension.

The three count fields — low_count, med_count, and high_count — record the absolute number of scans that resolved to each severity tier. When you read them alongside the percentages covered in the previous section, you stop interpreting ratios in a vacuum and start reading frequency as a signal in its own right.

Consider the example data: a low_count of 5, a med_count of 4, and a high_count of 4. Notice what that distribution says that percentages cannot. The high-risk and medium-risk tiers are nearly identical in absolute volume. They are not edge cases dragging up a rate — they are recurring events. Four confirmed high-severity scans is not statistical noise. It represents four separate moments at which the domain triggered the most serious classification available. That is a pattern, not an outlier.

Equally important is what the count values reveal about the low-risk tier. With only 5 low-count scans against 4 high-count scans, the supposedly "safe" outcomes barely outnumber the worst-case outcomes. A percentage view might frame this as a manageable split. The raw counts make clear that the domain has almost no deep history of clean behavior to offset its threat record.

When high_count and med_count together approach or exceed low_count, treat that as a structural flag rather than a rounding artifact. Threat frequency at that level suggests the domain's risk profile is not drifting upward — it may already be settled in elevated territory.

Raw counts also give you a quick sense of data confidence. A report built on 13 total scans (5 + 4 + 4) is informative but not yet definitive. Volume matters for certainty; counts let you measure it directly rather than infer it from a single aggregate figure.

Reading Recent Scan Intelligence as a Live Threat Layer

The fields covered in earlier sections describe a domain's historical record. The recent_scan_intelligence field does something different — it surfaces what is happening right now, or close to it, by aggregating behavioral signals from scans conducted within a recent window. Think of it less as a verdict and more as an early-warning layer that can contradict an otherwise clean-looking profile.

Every entry in this field bundles several distinct data points that must be read together: an average risk score from recent scans, a human-readable verdict, a scan count, a web-mention volume, a complaint flag, and a classification tag. No single element tells the full story. The risk score anchors the reading, but it only becomes meaningful when you stack it against the complaint flag and the classification.

Take the real entry for mailersend.com. Its average risk from recent scans is 29.0 — low enough that a quick glance might prompt a "safe" conclusion. The verdict label reinforces that instinct, returning legitimate. The classification tag, saas_prod, further positions it as an established software-as-a-service product. So far, nothing alarming.

But the entry also contains two signals that break the clean narrative. First, web mentions reach 8 — meaningful surface area for a tool that may be embedded in outbound email infrastructure. Second, and more critically, scam complaints have been found. That flag doesn't disappear because the risk score is moderate. It persists as its own data point, independent of the numeric average, and it means the domain has been associated with complaint activity in the wild.

Two total scans contributed to this entry. That's a thin evidential base. A narrow scan count means the average risk is easily skewed by a single anomalous result, so the 29.0 figure should be held loosely rather than treated as authoritative.

The correct read here: mailersend.com isn't flagged as dangerous, but it is a domain where active complaint signals exist alongside thin scan coverage. That combination warrants a follow-up check rather than unconditional clearance — which is exactly the kind of nuanced judgment this field is designed to prompt.

Affiliate Links: The Section That Rewrites a Clean-Looking Score

A site can post low risk percentages, modest raw counts, and a respectable aggregate score — and still be quietly embedded in a monetization network that tells a completely different story. The affiliate links section of a WebPulse scan report is where that hidden layer surfaces.

When WebPulse scans a domain, it doesn't stop at the page itself. It traces outbound connections: the affiliate networks the site routes traffic through, the third-party merchants it redirects to, and the tracking chains those redirects create. Each of those outbound relationships is a form of association. A site is, in part, defined by the company it keeps commercially.

This matters because affiliate architecture is one of the most reliable fingerprints of predatory or low-quality sites. Legitimate publishers do use affiliate links — that's unremarkable on its own. What's diagnostic is the pattern: which networks appear, how many distinct affiliate destinations are present, and whether those destinations cluster around categories flagged elsewhere in the report. A site monetizing through mainstream, well-documented affiliate programs reads very differently from one whose affiliate chain routes through obscure redirect hubs, offshore networks, or domains with their own elevated risk histories.

The practical move is to cross-reference the affiliate links section against the risk count data you read in earlier sections. If the site showed elevated high-risk scan hits and the affiliate section surfaces connections to networks associated with aggressive ad delivery or data harvesting, those two signals are compounding rather than independent. Neither alone closes the case; together they form a coherent pattern worth acting on.

Conversely, a modest score can look more trustworthy once you see its affiliate relationships are limited and traceable. The score didn't change — your confidence in it did, because the affiliate section gave you structural evidence the number couldn't provide by itself.

Treat the affiliate links section as a relationship audit. It answers the question no score can: not just how this site has behaved in isolation, but who it's commercially connected to and what those connections imply about intent.

MailerSend vs Example.com: When Sections Contradict Each Other

The clearest way to understand why no single section of a WebPulse report tells the whole story is to place two real domains side by side and watch the data pull in opposite directions.

Start with a domain running on MailerSend's shared sending infrastructure. A quick glance at its high_pct field returns 31 — meaning nearly a third of all scans for that domain came back flagged at the highest risk tier. Taken in isolation, that number reads like a verdict. Most users would stop there, mark the sender as dangerous, and move on.

Then look at high_count: 4.

Four. That's the absolute number of high-risk scan results sitting behind that 31 percent figure. Combined, these two data points imply a total scan volume of roughly a dozen queries — a sample so thin it could shift dramatically from a single spam complaint or one misconfigured sending burst. The percentage is mathematically correct, but it is not statistically meaningful. The report sections are contradicting each other: one says danger, the other says insufficient evidence.

Now consider Example.com. Its high_pct might appear far lower at first glance — a number that looks like a clean bill of health. But if its high_count is spread across thousands of scans rather than a handful, that lower percentage carries considerably more weight. A domain with broad scan history and a sustained pattern of high-risk flags is a qualitatively different threat than one with a single rough week on a razor-thin sample.

This is exactly where first-time readers stall. They treat whichever number they noticed first as the conclusion, when the real conclusion only emerges from the relationship between sections. A high percentage demands a count check. A low count demands skepticism about the percentage. Neither field overrules the other; they interrogate each other.

For shared infrastructure domains like MailerSend — where dozens of legitimate senders operate under the same root domain — thin scan volume is common and expected. Flagging the infrastructure as high risk based on four incidents misreads what the report is actually describing.

The Green Verdict Trap That Catches Every First-Time Reader

A green verdict feels like permission to stop reading. It shouldn't.

When a WebPulse scan returns a favorable overall rating—clean color coding, a score that sits comfortably in the safe zone—first-time users instinctively treat it as a closing argument rather than an opening one. The report has more to say, and the sections that follow the headline verdict are precisely where the most actionable intelligence lives. Stopping at the green label means ignoring all of it.

The trap works because the favorable score is genuinely accurate on its own terms. It reflects the aggregate picture, and the aggregate picture may well be positive. But "positive on balance" and "safe to proceed without further review" are not the same claim. A site can carry a green verdict while simultaneously showing raw high-severity counts that would warrant a pause, or a scan-volume figure so low that the score is statistically thin. The score doesn't lie; it just doesn't tell the whole story, and the green color obscures that incompleteness.

What makes this mistake so consistent among first-time readers is that the design of most scan interfaces rewards confirmation bias. The verdict appears prominently, often above the fold, often in a color that registers as "done." Every subsequent section requires the user to scroll, click, or expand. The interface isn't broken—it's prioritizing a summary view—but readers who haven't been taught the report's full architecture interpret the hierarchy of presentation as a hierarchy of importance. The green verdict looks final because it appears first.

The correction is mechanical, not analytical. Before acting on any favorable score, treat it as a prompt to answer three questions: Does the scan volume behind this score represent a meaningful sample? Do the raw severity counts align with what the percentages imply? Are there subsection flags or annotation fields that contradict the headline rating?

First-time users who build this three-question habit stop reading the green verdict as a destination. They start reading it as an invitation to verify—which is exactly what the full report is designed to support.

Translating Every Report Section Into a Concrete Next Step

Reading a WebPulse report is only valuable when each section drives a decision, not just an observation. The following decision rules convert everything you have learned across this walkthrough into immediate action signals.

Score alone: Treat the aggregate score as a triage filter, nothing more. If it falls in a comfortable range but you have not yet checked percentages and raw counts, withhold any judgment. The score earns your trust only after the rest of the report confirms it.

Risk percentages: When high_pct climbs above a threshold that feels disproportionate to the domain's age or reputation, flag the vendor for a secondary manual check before any purchase or data-sharing occurs. A low high_pct only clears suspicion when scan volume is meaningful — if total scans are sparse, the percentage is statistically thin and should not carry much weight.

Raw counts: If high_count is non-zero, stop and investigate the nature of those detections regardless of what percentages suggest. Even a single confirmed high-risk detection on a low-volume site can represent a genuine threat. Raw counts reveal absolute exposure; use them to set a floor, not a ceiling, on your concern.

Domain metadata: Registration age and registrar signals should influence how generously you interpret borderline scores. A recently registered domain with a mediocre score deserves more skepticism than a decade-old domain with the same number.

Category and reputation tags: Tags that contradict the stated purpose of a site are actionable on their own. A domain claiming to be a software vendor but categorized under content patterns inconsistent with that use should trigger an escalation step, not a passed review.

Taken together, these rules form a short decision chain: score sets the opening posture, percentages and volume calibrate confidence, raw counts establish a hard floor, metadata adjusts context, and category tags catch misrepresentation. Working through that chain takes under two minutes once it becomes habit, and it replaces vague instinct with a repeatable, defensible vetting process that holds up to scrutiny every time.

Ready to scan your first website? Try WebPulse free →