How scoring works

Every finding gets one priority score from five weighted components. The formula is visible, the weights are yours to tune, and every score — past and present — shows the exact inputs and weights used when it was calculated. There is no machine-learning black box to trust; there is arithmetic to check.

The five components

Weights and versioning

The five weights must sum to one and are edited on the Scoring page (AppSec Lead only). Saving creates a new version rather than overwriting — the prior configuration is preserved, and each historical score keeps a copy of the weights used at the time. Tuning the formula today never falsifies what a score meant last month; every change is also recorded in the audit log.