WHAT IT IS
A governed way to review a website
WebTrustEngine accepts a local folder, a ZIP package or an authorised URL. It records the input identity, evaluates applicable signals and produces findings, evidence, remediation guidance and decision-ready reports. A score is a summary of measured readiness; it is never a guarantee of ranking, citation, compliance or security.
The operating stages are Review, SafeFix, Build and Deploy-Verify. Monitor is the agreed cadence for repeating verification, not a fifth stage.
EVIDENCE MODEL
Every material number has a source
Input identity
File lists and SHA-256 values preserve what was reviewed.
Metric lineage
Scores and counts retain their source, unit and derivation.
Release integrity
Validation reports, manifests and rollback records travel with the delivery.
Number discipline
2,033 is the reference catalog. The source inventory contains 319 implemented detectable units (80 core + 239 granular), but the executed subset depends on mode and applicability; the primary scan path runs 80 core checks. The 26 SafeFix generators are counted separately.
BOUNDARY
Static review is not a penetration test
The standard engine can inspect source, configuration, client-side signals, dependency indicators and deployment readiness without attempting exploitation. Port scans, active payloads, authentication bypass attempts and form submissions are outside the standard product boundary and require a separately authorised scope.
Offline review proves file truth. Live HTTP, TLS, DNS, cache and third-party behaviour must be verified after deployment; the report marks that distinction instead of inventing certainty.
PUBLIC IDENTITY
One product name, one evidence chain
Public reports, downloadable assets and this site use WebTrustEngine as the product and publisher identity. The same release identifier, number contract and verification language are carried across human-readable and machine-readable surfaces.