Methodology

A result you can explain and reproduce.

Insight does not invent its own thresholds or hide assumptions. This page describes how data turns into a score, where thresholds come from, what the scan levels are and where automated analysis ends — everything you need to defend a report in front of a client.

Methodology v1.2

Updated: 22 Jul 2026 Applies to reports from: 22 Jul 2026 Changelog

Lighthouse WCAG 2.2 SWDM v4 OWASP ZAP CrUX

/ 01 · Scoring

How the score is built

Every score in a report follows the same path — from raw measurement to a 0–100 number. No manual adjustment and no after-the-fact “expert opinion”.

Score path

The same path for every module and every scan

  1. Source data

    Lab measurement, server response, rendered DOM, crawl

  2. Threshold

    Compared against a public standard or reference configuration

  3. Finding

    pass · warn · fail — or N/A when data is missing

  4. Severity & confidence

    Finding impact × automated detection confidence

  5. Priority

    A shared P1–P4 scale across all modules

  6. Score 0–100

    Weighted aggregation of a module’s checks

Fixed scoring rules

Weights and aggregation

Checks do not count equally: the weight depends on impact (high > medium > low). A passed check earns its full weight, a warning part of the points, a failure zero. A module score is earned points over maximum points, scaled to 0–100.

Missing data (N/A)

A module or check without data is reported as N/A and excluded from the denominator — it neither lowers nor inflates the score. A deeper scan level adds modules and scope, but does not change the verdicts of checks already measured.

Score aggregation rules

A module score comes from available, completed checks. N/A checks are neither a pass nor a zero and do not enter the denominator.

  • Module score Points from completed checks ÷ sum of those check weights × 100. Fail = 0 for that check, warn = partial weight, pass = full weight.
  • N/A outside the denominator A missing signal does not lower the score and is not counted as a pass. We show N/A separately so “not measured” is never confused with “zero”.
  • Overall score Combines measured module scores using the weights of the published methodology version. An N/A module does not enter that aggregation.
  • Priority ≠ score P1–P4 orders the implementation backlog. It does not map 1:1 to score points — severity, scope and confidence set priority separately.

/ 02 · Data sources

Where the data comes from

Insight does not install a script on the site. It reads what the browser shows and what the server returns — in one scan session.

Two analysis inputs

Rendered page

A real browser, JS, DOM and what the user actually sees.

  • Lighthouse
  • WCAG
  • Crawl

Server response

Statuses, headers, redirects and cookies at scan time.

  • HTTP
  • TLS
  • Cookies

No script on the client site

Source catalog

  • Lab performance metrics

    Lighthouse / PageSpeed API

    Lab measurement

    Results may vary between runs

  • HTTP checks

    Statuses, headers, redirects, cookies

    Direct measurement

    Server state at scan time

  • WCAG tests

    Automated, on the rendered DOM

    Automated detection

    Some criteria require manual review

  • CO₂e estimate

    The SWDM v4 model based on data transfer

    Model estimate

    Not an emissions measurement or a certificate

  • Crawl

    Links, sitemap.xml and a manual list — the page is rendered with JS

    First-party data

    Page limit per plan; recurring issues are grouped into one finding with its scope

/ 03 · Standards

Thresholds from public standards

Score thresholds come from standards you can cite in a report — not from our whim.

What we cite in a report

Core Web Vitals

Chrome UX / web.dev

  • LCP ≤ 2.5 s
  • INP ≤ 200 ms
  • CLS ≤ 0.1

WCAG 2.2 (AA)

W3C

  • Text contrast ≥ 4.5:1

Security headers

OWASP

  • CSP present
  • HSTS present
  • Guidance OWASP

The Insight scale

How we map onto the Insight scale

  • ≥ 90 good standing
  • 70–89 needs work
  • 50–69 significant issues
  • < 50 high priority

The Insight score is not a Lighthouse score, a compliance certificate or a legal opinion — it is our interpretation of source thresholds on a shared 0–100 scale.

/ 04 · Priorities

One scale across all modules

P1–P4 is implementation order, not a synonym for severity. Severity comes from the threshold; priority combines severity, scope and confidence. P1 is not always a critical defect — sometimes it is a wide, high-confidence issue. Implementation cost is only an auxiliary recommendation.

P1–P4 scale

  1. P1 Fix first
  2. P2 Plan it
  3. P3 Fix when convenient
  4. P4 Backlog / low

What moves priority

Severity

Comes from the threshold — the same problem gets the same severity.

Scope

Affected page count moves a finding along the P1–P4 scale.

Confidence

Automated detection confidence affects position on the scale.

Implementation cost

An auxiliary recommendation — it does not lower severity.

N/A — not enough data. Never zero or success.

From signal to score

Security

Missing HSTS

Priority P1
Signal
missing Strict-Transport-Security header
Source
HTTP response
Rule
OWASP Secure Headers
Scope
entire domain
Confidence
high
Severity
high
Module impact
fail · high weight · 0 pts from this check

Accessibility

Contrast below 4.5:1

Priority P2
Signal
text below WCAG AA 4.5:1
Source
rendered DOM
Rule
WCAG 2.2 · 1.4.3 Contrast (Minimum)
Scope
2 pages
Confidence
high
Severity
medium
Module impact
fail · medium weight · 0 pts from this check

/ 05 · Scan levels

A deeper scan means more data, not a “better score”

Each level runs a defined module set. Credit costs match the pricing page.

A deeper level adds scope — it does not change verdicts of checks already measured.

Quick

4 cr
Modules
5
Time
~1 min

What gets added

No Lighthouse

Best when

Quick screening of a single URL

Standard

12 cr
Modules
10
Time
3–5 min

What gets added

Adds performance

Best when

Regular site quality control

Complete

18 cr
Modules
22
Time
8–10 min

What gets added

Security cluster (ZAP)

Best when

Audit before a release or acceptance

Comprehensive

25 cr
Modules
30
Time
12–15 min

What gets added

Competitors + AI visibility

Best when

Extended scope for organisations

/ 06 · The role of AI

What AI does — and what it doesn’t

Insight uses generative models in the description layer, not in the measurement layer.

A generative model does not set the raw measurement result and does not replace source thresholds. It may help group findings and draft recommendation copy.

Measurement layer

No AI

Measurement, thresholds and severity always come from source data.

Description layer

With AI

Descriptions, grouping and recommendations — labelled, for review.

Rules

Measurement without a model

Scores, thresholds and severity never come from a generative model.

AI on raw scan data

It groups findings, describes impact and drafts recommendations.

Review only

AI recommendations are labelled — nothing is applied automatically.

Complete without AI too

The score and findings list do not depend on the generative layer.

/ 07 · Limits

Limits of automated analysis

An automated scan detects part of the problems. Honest limits are part of the methodology.

Honest limits

WCAG / EAA

Does not confirm compliance

Replaces neither manual review nor legal opinion.

CO₂e

Not a measurement or certificate

An SWDM model estimate — not a lab result.

ZAP

Not a pentest

An automated vulnerability scan, not a manual penetration test.

Crawl

Not a full enterprise crawl

No guarantee of finding every URL on the site.

Lab vs CrUX

Not the same source

Shown separately — without treating lab data as field data.

See the technical crawl methodology

/ 08 · Comparability

Comparable results under comparable conditions

Page content, third parties and the network change between scans. The report records conditions — comparisons use the same scale and thresholds.

What we lock for comparison

Time and version

Scan date and methodology version

Scope

Scan level, URLs and device profile

Completeness

Modules completed and marked N/A

Method changes

Communicated — never a silent backfill

Same scale

Illustrative example · same thresholds, same scale — no fabricated scores

Changelog

  1. v1.2 22 Jul 2026

    Table of contents, aggregation and N/A rules, full signal→score example, explicit AI role, versioned sources.

  2. v1.0 15 Jul 2026

    First public methodology: scoring path, sources, thresholds, priorities, scan levels and limits.

See the methodology in practice.

The sample report shows the data sources, timing and limits of the analysis. Free then lets you scan one project without a card.

No card on Free Data sources in every report Thresholds from public standards