What this is, and what it is not. A single number from 0 to 100, the sum of seven weighted axes, computed by a script from measurements only: the public findings registry (every finding is a command with an exit code), the measured-facts engine, the live chain feed and the CI status. Every axis lists the measurements behind its points. Anything that could not be measured scores zero and says so. It is not an audit and it does not claim safety; it is meant to move when the underlying facts change, and to be embarrassing until they do.
Raw feed: /security-score.json. Generator: scripts/scor-securitate.cjs in the operator repository; the formula of each axis is printed under it. Related: audits, security, live benchmark.