Cybersecurity Rating
by ImmuniWeb® CyberScore™

Get a free cybersecurity, privacy and AI security rating of your company, partners or suppliers
Free online tool with PDF report
  • Website Security Rating
  • Website Privacy Rating
  • Encryption Security Rating
  • Email Security Rating
  • GenAI Exposure Rating
  • Dark Web Exposure
Free online tool with PDF report
58,860 organizations tested

Get Your Cybersecurity Rating

|Provided "as is" without any warranty of any kind
21
tests
running
310
tests
in 24 hours
tests in 24 hours

What Is a Cybersecurity Rating?

A cybersecurity rating is an external, evidence-based assessment of how well an organization protects its websites, data and email infrastructure. It is calculated from what is visible from the outside, exactly the way an attacker or a prospective customer would see it, without any access to internal systems.

ImmuniWeb® CyberScore™ produces six independent ratings for any domain you enter. It runs entirely from the outside, requires no agents, no credentials and no input from the tested company, making it perfect for checking your own perimeter, your suppliers or a potential acquisition target.

Every performed test is strictly non-intrusive. CyberScore does not attempt to exploit anything, does not send malicious payloads and does not disrupt the systems it analyses.

Upgrade to ImmuniWeb® AI Platform

What Does CyberScore Check?

CyberScore combines six tests into a single report. Each one is graded independently, so you see exactly where the weak spot is instead of a single opaque number.

Website Security Rating

Scans the company's websites for known web vulnerabilities, outdated or vulnerable CMS and CMS components, insecure HTTP methods, missing Web Application Firewall, weak Content Security Policy and cookie handling. Also covers HTTP security and privacy headers, DNSSEC configuration, AI bot protection, resistance to data scraping, and non-intrusive GDPR and PCI DSS compliance checks. Also available as a standalone tool: Website Security Test.

Website Privacy Rating

Tests how the company's websites handle visitor data: tracking cookies and tracking pixels, third-party content and XHR requests that send data to external services, privacy of web forms, and the presence and consistency of the privacy policy. Also available as a standalone tool: Website Privacy Test.

Encryption Security Rating

Tests the SSL/TLS stack of the company's web servers: supported protocols and ciphers, certificate validity, cryptographic flaws and misconfigurations, post-quantum cryptography readiness, and compliance with PCI DSS, GDPR, HIPAA and NIST requirements. Also available as a standalone tool: SSL Security Test.

Email Security Rating

Tests company's mail servers for open relay and SMTP enumeration, authentication enforcement, PTR records, SSL/TLS encryption of mail servers, SPF, DKIM, DMARC and MTA-STS configuration, DNSSEC signing, and presence on spam blacklists. Also available as a standalone tool: Email Security Test.

Dark Web Exposure

Detects leaks and incidents involving the tested domain on the Dark Web, including stolen user credentials and compromised databases. Also detects cybersquatting and typosquatting domains, phishing and scam websites, and fake accounts impersonating the company's brand in social networks. It is also available as a standalone tool: Dark Web and Threat Exposure Test.

GenAI Exposure Rating

Detects AI-specific risks that traditional scanners miss: AI-generated and vibe-coded patterns across company's websites, and leaks of AI tokens and other AI-related sensitive data both on the Dark Web and across the web assets. This check is available only as part of CyberScore.

How is the Rating Calculated?

Every test runs separately against each hostname discovered under the tested domain, and each hostname gets its own letter grade from A+ down to F. The rating you see for a service is the average of those individual grades.

Hostnames that could not be tested are excluded from the average instead of being counted as a failure. If a server does not respond, a tested port is closed or a domain does not resolve, it is marked as N and does not affect the rating. A parked or retired subdomain will therefore not drag down the score of a well-configured perimeter.

Dark Web Exposure works differently. Instead of a letter grade you get the number of detected incidents and domain mentions, broken down by source and risk level, because a single letter cannot meaningfully summarize a company's exposure on the Dark Web.

The full scoring methodology of each test is published here: Website Security, Website Privacy, SSL Security.

Frequently Asked Questions

Q

Is CyberScore free?

A

Yes. Running a rating and viewing the report costs nothing and requires no registration. You only need to accept the Terms of Use before starting a test.

Q

Do I need to own the domain I am testing?

A

No. All tests are non-intrusive and rely only on publicly available information, so you can rate your own company, a supplier, a partner or a vendor you are evaluating. This is what makes CyberScore perfect for third-party risk assessment.

Q

Will the test harm or disrupt the tested website?

A

No. CyberScore performs passive and non-intrusive tests only. It does not attempt to exploit vulnerabilities, does not brute-force anything and does not generate load that would affect availability.

Q

How long does a test take?

A

Most reports are ready within several minutes. Large domains with many subdomains take longer, because each subdomain is analyzed separately.

Q

How many subdomains are analyzed?

A

The number of subdomains included in the graded overview is capped at 50. Organizations that need full coverage of their external perimeter can use ImmuniWeb® Discovery, which maps all domains, subdomains, on-premise and cloud assets continuously.

Q

Is my report public?

A

Reports are accessible to anyone who has the link, so you can share them with your team, your management or a vendor you are assessing. They are excluded from search engine indexing and are not listed anywhere on the site, so a report will not surface in Google results for your company name.

Q

Can I re-run the test after fixing the issues?

A

Yes. Use the Update Rankings option on the report page to re-run the checks and get a fresh grade. You can updated rankings as soon as all tests in the current report have finished.

Q

Are there any usage limits?

A

Yes. Without an account, you can start up to 10 new tests per month.

With a Free Account, you can run up to 25 tests per month. This limit applies to both starting new tests and updating existing reports.

Q

What is the difference between CyberScore and the individual free tests?

A

The individual tests, such as the Website Security Test or the SSL Security Test, each cover one area in depth. CyberScore runs all of them at once against a single domain and adds GenAI Exposure, which has no standalone equivalent, so you get a complete external picture in one report instead of five separate ones.

Q

Why did my company get a low grade?

A

A low grade usually points at a specific, fixable configuration issue rather than a breach: an outdated CMS, a missing security header, a weak TLS configuration or an unconfigured DMARC record. Every section of the report lists the exact findings and the hostnames they were found on.

Q

Can I get a rating for something other than a website?

A

CyberScore covers web, email and Dark Web exposure. Mobile applications are covered by a separate free test. Full internal and external testing, including penetration testing, is offered by our ImmuniWeb® AI Platform.

Q

How often is the data updated?

A

A report reflects the moment the test was run, and the test date is shown at the top of every section. Companies that need their rating tracked continuously, with alerts when it changes, can use ImmuniWeb® Discovery.