The WebPulse 0–100 Risk Score Explained
What the data reveals about e-commerce websites — from risk patterns to opportunity signals.
Every WebPulse scan produces a risk score from 0 to 100, combining two intelligence layers.
How the Score Is Built
The score has two components:
Rule Engine (0–60 points) — deterministic, instant checks:
- Missing HTTPS: +10 points
- Very new domain (<30 days): +15 points
- No contact information: +8 points
- No Privacy Policy: +6 points
- No About page: +5 points
- Scam-like language detected: +5 per pattern (capped)
- Aggressive sales tactics: +5 points
AI Layer (0–40 points) — deep content analysis:
- Content manipulation and urgency tactics
- Inconsistent business identity
- Hidden or suspicious link structures
- Overall site intent classification
- Content quality and authenticity assessment
Reading the Three Risk Bands
0–30 — Low Risk ✅
Site demonstrates strong trust signals. HTTPS present, legal pages exist, contact info available, content is straightforward. Suitable for most interactions.
31–60 — Medium Risk ⚠️
Some trust gaps detected. The site may be legitimate but is missing important signals. Investigate before sharing payment details or sensitive information.
61–100 — High Risk 🚨
Multiple risk signals detected. Proceed with significant caution. High-risk sites may be scams, phishing operations, or simply poorly maintained. The AI layer's explanation tells you exactly why.
What the Score Doesn't Tell You
The score is a risk indicator, not a verdict. A legitimate new startup might score 45 simply because it's new. A well-established scam operation might score 55 because it has learned to mimic trust signals. Use the score as one input alongside the full evidence trail — red flags, trust signals, and AI explanation — to form your own judgement.
Ready to scan your first website? Try WebPulse free →
Frequently Asked Questions
Why do e-commerce websites score high risk more often than other types of sites?
E-commerce sites are primarily built to convert visitors into buyers, meaning trust and compliance layers are frequently skipped or postponed. This creates a structural gap between transactional function and credibility infrastructure where risk signals accumulate rapidly. WebPulse scan data found that 36.4% of analyzed e-commerce sites scored high risk.
What is the most common risk signal detected on e-commerce websites?
Thin content is the single most common risk signal, with 20 detected instances across scanned sites. For e-commerce stores, this typically means product pages with minimal descriptions, duplicate copy across multiple SKUs, or auto-generated category pages with no original text. A store with hundreds of such pages can accumulate enough signals to tip the entire domain into high-risk territory.
What trust infrastructure elements are e-commerce sites most frequently missing?
According to the WebPulse dataset, e-commerce sites commonly lack contact information (11 instances), an About page (10 instances), Terms of Service (8 instances), and a Privacy Policy (7 instances). These omissions are especially damaging because customers actively look for these signals before handing over payment and personal information to an unfamiliar brand.
How do missing security headers increase the risk score of an e-commerce site?
Missing security headers appeared 8 times across scanned sites and carry amplified weight for e-commerce operations. Headers like Content-Security-Policy, X-Frame-Options, and Strict-Transport-Security protect users from clickjacking, cross-site scripting, and session hijacking — attacks that directly target payment flows and user account data. Their absence leaves an online store's customers exposed during active browsing sessions.
Why is an exposed server version considered a risk signal for e-commerce sites?
When a web server advertises its software version in HTTP headers, it gives attackers a precise roadmap of which known vulnerabilities to probe. Detected 5 times across scanned sites, this signal is particularly dangerous for sites processing transactions because it is invisible to the naked eye and can go undetected for months without active scanning.
Do individual risk signals compound, and how does that affect the final risk score?
Yes, according to the article, risk signals do not stack linearly — they compound. For example, missing security headers and an exposed server version each push the score upward individually, but together they can be the difference between a medium-risk result and a high-risk flag. E-commerce sites are especially vulnerable because they commonly accumulate multiple signals across content, compliance, and security simultaneously.
Discussion (0)
No comments yet. Be the first to share your thoughts.
Leave a Comment