Home / Knowledge Base / Rank Tracker, Audit and Shield / How to Read the Shield Report

How to Read the Shield Report

Rank Tracker, Audit and Shield 2 min read Updated 13.09.2026
Seventy-nine checks in twelve categories with CVSS scores linked to CWE and OWASP. What the danger levels mean, how scanning modes differ, and how to read the final score.

Shield checks the site not as a search bot, but as a security scanner: it looks for access leaks, traces of hacking, vulnerable components, and configuration errors. In the catalog, 79 checks are available in twelve categories, each finding has a danger level, a CVSS score, and a link to the CWE and OWASP classifiers.

Five Levels

LevelWhat It Means in Practice
CriticalThe site is compromised or access is exposed — respond today
HighThere is a working path to capture or infection
MediumFacilitates an attack or exposes unnecessary information
LowMinor configuration issues
InformationalNot a problem, but an observation: something is missing, but it is not essential

What Is Checked

CategoryExamples of Findings
Malicious CodeInjected script, payment data skimmer, miner, hidden links, cloaking
BackdoorsWeb shell, unauthorized administrator, modified core files, suspicious uploads
LeaksOpen .env and .git, backups, files with access, phpinfo, directory listings
CMSOpen installer, vulnerable and abandoned components, exposed version
DNS and MailSPF, DMARC, DNSSEC, possibility of subdomain interception
ConnectionCertificate, protocols, mixed content
Headers and CookiesHSTS, CSP, clickjacking protection, cookie flags
Injections and AccessSigns of SQL injections, overly open CORS, accessible admin panel

Three Scanning Modes

Free — passive: looks at what the site provides itself, without probing addresses. Deep — additionally checks about one and a half hundred characteristic paths. Full — about six hundred. The wider the probing, the higher the chance of finding a forgotten backup or open installer. Current prices are on the “Rates and Prices” page.

Refund if the check did not occur
Shield is one of two places on the platform where money is automatically refunded: if the scan could not be performed, funds are returned to the balance without contacting support. The second such place is paid page indexing.

How to Read the Score

The overall score Grade A–F is based on the issues found, taking their weight into account. A score below average almost always means one of two things: either unnecessary files are open, or headers are not configured. Both can be fixed without redesigning the site — see leak analysis.

FAQ

How many checks does Shield perform?
Seventy-nine, in twelve categories: from malicious code and backdoors to DNS settings, headers, and cookies.
How do the scanning modes differ?
The free mode only looks at what the site provides itself; the deep mode checks about one and a half hundred characteristic paths, and the full mode checks about six hundred.
What if the scan did not complete?
Funds are automatically returned to the balance — Shield is one of two places on the platform with auto-refund.
Was this article helpful?
Try it on your project Everything described in the article is available in the dashboard — the registration bonus is already in your balance.
Open dashboard