Eight-point technical assessment

What Accredit Digital actually checks.

Every accredited website is evaluated against eight defined categories. Each category returns a standardized result — PASS, WARNING, FAIL, NOT APPLICABLE or SCAN ERROR — with evidence, a timestamp and a remediation recommendation.

Trust score

A single score, from eight weighted categories.

The overall technical trust score is calculated from the weighted result of each category. Weights are configurable by Accredit Digital administrators through the rule engine, so scoring can evolve without changing application code.

Reachability10%
SSL Certificate15%
HTTPS Enforcement15%
Sensitive Files15%
SPF / DMARC10%
Safe Browsing15%
Malware10%
Phishing10%
Category detail

The eight categories.

01

Website Reachability

Verifies that the website is operational and reachable through its expected endpoints.

10%Weight
Checks performed
  • DNS and domain resolution
  • HTTP and HTTPS response
  • Response status and timing
  • Redirect chain analysis
  • WWW / non-WWW behaviour
  • Server availability and timeouts
Pass when
  • Domain resolves consistently
  • Main page returns a success status
  • Redirects resolve cleanly
Fails when
  • DNS does not resolve
  • Server unreachable or timing out
  • Main page inaccessible

Recorded: URL, timestamp, HTTP status, response time, redirects, error information, IP information where appropriate, scan duration.

02

SSL Certificate

Evaluates the TLS/SSL configuration presented by the website.

15%Weight
Checks performed
  • Certificate exists and is valid
  • Start and expiry dates
  • Issuer and subject
  • Domain match and SAN coverage
  • Certificate chain integrity
  • TLS version in use
Warning when
  • Certificate nearing expiry
  • Invalid or incomplete chain
  • Domain mismatch
  • Weak or obsolete TLS configuration
Critical failure
  • Expired certificate
  • Invalid certificate
  • HTTPS unavailable
03

HTTPS Enforcement

Determines whether the website properly enforces encrypted connections.

15%Weight
Checks performed
  • HTTP → HTTPS redirect
  • Permanent redirect status
  • Redirect destination integrity
  • HTTPS canonicalization
  • Mixed-content indicators
  • HSTS header presence
Scores higher when
  • HTTPS is available and enforced
  • HSTS is enabled
  • No HTTP version is independently accessible
Warning when
  • Redirect is temporary, not permanent
  • Mixed content detected
  • HSTS absent
04

Exposed Sensitive Files

Identifies commonly and accidentally exposed files, directories and configuration artefacts.

15%Weight
Typical targets
  • /.env and config files
  • /.git/, /.svn/
  • Backup archives and database dumps
  • Source maps and log files
  • Directory listings and debug endpoints
  • Exposed admin directories
Methodology
  • Read-only checks only
  • No exploitation attempted
  • Rate limits respected
  • No brute force
  • No file modification
  • No authentication bypass
Findings include
  • URL and detection type
  • Severity
  • Evidence
  • Timestamp
  • Recommendation
05

Email Domain Security

Assesses SPF and DMARC configuration for the organization's domain.

10%Weight
SPF
  • Record exists
  • Valid syntax
  • No multiple SPF records
  • Include mechanisms
  • Hard fail vs soft fail
  • DNS lookup limits
DMARC
  • Record exists
  • Policy strength: p=reject > p=quarantine > p=none
  • Reporting configuration
  • Syntax and alignment settings
Important distinction
  • "DMARC exists" is scored separately from "DMARC is strongly enforced"
  • SPF/DMARC are technical domain-security indicators — they do not prove an organization is legitimate
06

Google Safe Browsing

Checks whether the website is identified as unsafe by supported Safe Browsing data.

15%Weight
Possible results
  • Safe
  • Potentially unsafe
  • Threat detected
  • Unable to verify
Recorded
  • Scan timestamp and domain
  • Result and threat category
  • Source response
  • Historical result
Consequence
  • An unsafe classification triggers an immediate accreditation review and can result in automatic suspension
07

Malware Pattern Scan

A layered, website-level malware indicator scan performed without executing untrusted content.

10%Weight
Six analysis layers
  • Layer 1 — HTML analysis
  • Layer 2 — JavaScript analysis
  • Layer 3 — Resource analysis
  • Layer 4 — URL / domain reputation
  • Layer 5 — Pattern & signature analysis
  • Layer 6 — Behavioural indicators
Indicators
  • Suspicious or obfuscated JavaScript
  • Known malicious URL patterns
  • Suspicious redirects and iframes
  • Unexpected executable resources
  • Script injection indicators
Safety rules
  • Potentially malicious content is never executed on scanning infrastructure
  • Dynamic analysis runs in isolated, sandboxed infrastructure
08

Phishing Pattern Scan

Assesses characteristics commonly associated with phishing and produces a graded risk assessment.

10%Weight
Indicators
  • Suspicious login and authentication pages
  • Credential collection patterns
  • Brand impersonation and domain mismatch
  • Hidden destination links
  • URL anomalies and suspicious redirects
Risk grades
  • LOW
  • MEDIUM
  • HIGH
  • CRITICAL
Stated limitation
  • Pattern scanning is an automated security assessment. It does not constitute a guarantee that a website is completely free of malware or phishing activity.
Decision engine

How results become a decision.

Accreditation rules are configurable. These are the default thresholds.

AUTOMATIC APPROVAL

Eligible for Trusted Site

No critical security issue · SSL valid · HTTPS operational · website reachable · Safe Browsing safe · no high-risk malware or phishing finding.

MANUAL REVIEW

Reviewed by an officer

A warning exists · a check could not be completed · a suspicious pattern was detected · domain configuration has unusual characteristics.

AUTOMATIC REJECTION

Not approved

Active malware · confirmed phishing · unsafe browsing classification · expired or invalid SSL · critical exposed sensitive information.

What happens if one scanner cannot complete?

A partial assessment does not automatically fail the website. If, for example, Safe Browsing returns "unable to verify" while every other check passes, the overall assessment is flagged as Manual Review / Partial Assessment rather than claiming a false failure.

How often is my website re-scanned?

Re-scan frequency is configurable — daily, weekly, monthly or on demand — and is controlled by Accredit Digital administrators. Critical findings trigger an immediate review regardless of schedule.

Can an administrator override an automated result?

Yes, but every override requires a written reason and is permanently recorded in the audit log. This protects the credibility of the accreditation.

Is the scanner aggressive toward my website?

No. The scanning engine applies rate limiting, request throttling, timeout controls, maximum crawl depth and page count, retry limits and concurrency limits, and identifies itself via user agent. All checks are read-only.

See your own results

Run your first assessment.

Onboard your website and receive a full eight-category report with evidence and remediation guidance.

Get started →