Methodology
50+ Signals. 13 Dimensions. One Trust Score.
Every RoastReady audit runs your website through the same signal checks that sophisticated buyers, B2B procurement teams, and search engine quality raters use to evaluate trust.
Scoring Weights
30%
Security
25%
Legal
25%
Performance
10%
Marketing
10%
Content
13 Dimensions
SSL certificate validity & chainTLS 1.2+ enforcementHSTS header presenceCSP policy analysis (wildcard / unsafe-inline detection)X-Frame-OptionsReferrer-PolicyX-Content-Type-Options
Largest Contentful Paint (LCP)Cumulative Layout Shift (CLS)Interaction to Next Paint (INP)Server TTFBMobile viewport meta tagTap target sizing
SPF record presence & validityDKIM selector verificationDMARC record with policy level (none / quarantine / reject)CNAME-following for delegated providers
Privacy Policy page detection (20+ languages)Terms of Service / AGB detectionCookie consent banner presenceCMP platform identification (OneTrust, Cookiebot, etc.)IAB TCF v2 compliance checkImpressum detection (DE/AT/CH)
Fake countdown timersFake social proof popupsPre-ticked opt-in checkboxesDeceptive price anchoringHidden subscription trapsUrgency language patterns
Trustpilot score & review countG2 rating lookupCapterra rating lookupBimodal review distribution detectionReview volume thresholds
Flesch readability scoreBoilerplate ratio detectionThin content flagging (<300 words)H1 tag presence & qualityCTA detectionMeta description length & qualityTitle tag length & keyword presence
Internal link samplingHTTP HEAD-check verification404 / redirect chain detection
Google Safe Browsing API checkabuse.ch URLhaus malware databaseThreatFox IOC (Indicators of Compromise) feeds
Transparency page / DSA report detectionDesignated contact point checkNotice-and-action mechanism presenceMulti-language detection (EN/DE/FR)
Sentence-length standard deviationTrigram lexical uniqueness ratioCombined statistical threshold flagging
jQuery <3.5 (CVE-2020-11022)AngularJS <1.8 (prototype pollution)Bootstrap <3.4.1 (XSS)Lodash <4.17.21 (prototype pollution)Moment.js <2.29.4 (ReDoS)Vue <2.7 (XSS)React <16.14 (XSS)DOMPurify <2.3 (bypass)
Pre-consent tracker detection (GA, Meta Pixel, TikTok, Hotjar, Clarity)CMP load-order verificationHEAD section script sequencing analysis
Crypto/DeFi keyword detection (25+ terms, EN/DE/FR)Web3 SDK detection (ethers.js, web3.js, wagmi, RainbowKit)Elevated HSTS/CSP scrutiny for wallet-connecting sites