Skip to content

Security Score

Use issue severity, CVSS data where available, and risk tags to prioritize findings. The Security Score of a scan or profile summarizes the number and severity of counted issues.

Issue Severity and CVSS

Escape issues have one of five severity levels: Critical, High, Medium, Low, or Info. An issue can also include a CVSS score and vector. You can override an issue's severity during triage.

Risk Tags

Risk tags describe finding context, such as unauthenticated access, sensitive data, critical findings, or external exposure. Use them alongside severity when reviewing issues. See Risk-Based Prioritization.

Security Score

The platform shows the Security Score as a percentage from 0 to 100. A higher score is better. A score of 100% means there are no counted Critical, High, Medium or Low issues with Open or Manual review status in scope. The API, the CLI and webhooks return the same value as a number between 0 and 1.

The Security Score drops as the number and severity of counted issues increase. Critical and High issues lower it much more than Medium or Low issues. Info findings don't affect the score. Resolving counted issues improves it, with higher-severity fixes having a greater effect.

The scan Security Score counts Open and Manual review issues associated with the scan on monitored assets. The profile Security Score counts Open and Manual review issues associated with the profile. Compare Security Scores over time alongside the underlying findings to understand changes in your security posture. See Understanding Results.

When the Profile Security Score Appears

A profile that never completed a scan has no counted issues, so its score would read 100% even though nothing was tested. Escape shows the profile Security Score only when the profile has a recorded last successful scan. Completing a continuous scan or retest does not set this marker by itself. Until the profile has a recorded last successful scan, the score is empty and the tooltip on the gauge explains why.

After Escape records a last successful scan, the score stays visible even when a later scan doesn't complete. The score keeps counting the issues that are still open on the profile, so hiding it would hide real risk. The tooltip tells you when the latest scan is running, failed, or was canceled.

Successful scan so far Latest scan Score shown Tooltip
None Starting or running Empty The first scan is in progress and the score appears when it finishes.
None Failed Empty The last scan failed, so there is no score yet. Check the scan logs.
None Canceled Empty The last scan was canceled before it completed. Run a new scan to get a score.
At least one Finished Yes The default explanation of the score.
At least one Starting or running Yes, from the last successful scan A new scan is running and the score updates when it finishes.
At least one Failed Yes, from the last successful scan The score is based on the date of the last successful scan, and the latest scan failed.
At least one Canceled Yes, from the last successful scan The score is based on the date of the last successful scan, and the latest scan was canceled.

The same rules apply to the profile list, the profile header, and the Security Score card on the profile summary. The card also hides the score history chart and the change since the previous scan while the score is empty.

See Results, Issues & Triage for the triage workflow.