Skip to main content
RiskScore

What is a RiskScore?

Your RiskScore measures security and business exposure in a single 0–100 number — higher means more risk. It is a separate axis from your DriftScore: a stale package with no known vulnerability is drift, not risk; a current package with an actively-exploited CVE is risk, not drift.

How a RiskScore is built

Known-exploited first

A vulnerability in CISA's Known Exploited Vulnerabilities catalog is treated as actively exploited and drives the score high — the strongest signal there is.

Likely-exploited next

EPSS estimates the probability a vulnerability is exploited in the wild; CVSS supplies severity. Likelihood times severity, not severity alone.

End-of-life exposure

Unsupported runtimes and deprecated packages get no security patches — they add a floor to your exposure even without a specific CVE.

Weighted by what matters

The same CVE matters more in a business-critical payment service than an internal demo. Business criticality weights the result.

Every RiskScore breaks down into its top contributing findings. See the full, versioned method in the public scoring specification.

See risk and drift together

DriftScore and RiskScore combine into one headline: DriftRisk™.