Wolfix scores every finding on a single dimension: business impact — what happens to your business if you do nothing. That score maps to one of four severity levels, which is what you see on each card and in the stat tiles at the top of the report.
Severity scale
The score is about impact, not effort
The most common misread of a Wolfix report is assuming that severity reflects how hard a fix is. It does not. Severity answers a different question: how much does it hurt to leave this alone?
A missing privacy policy scores high because operating without one creates real legal exposure — even though generating one with Wolfix takes a minute. A polished OG image scores low because its absence costs you nothing legally or operationally, even if designing one by hand takes an afternoon. Effort and impact are independent, and Wolfix scores only impact.
Why impact and not effort
Scoring by effort would bury dangerous-but-easy fixes beneath cosmetic-but-fiddly ones. Scoring by impact keeps the things that can hurt your business at the top, where you will see them first.
The four levels
Each finding lands in exactly one band based on its impact score.
Blocker — impact 9–10
Must fix before charging customers. Blocks payment or creates legal exposure. A missing privacy policy or an unconfigured payment processor.
Risk — impact 5–8
Fix at or shortly after launch. Poses operational, security, or compliance risk that compounds over time. DKIM gaps, exposed credentials.
Guide — impact 2–4
Recommended improvement. No immediate risk, but raises quality or trust. A missing OG image, a vague tagline.
Note — impact 1
Informational awareness item. No action required unless you choose to act. Surfaced because some operators want to know.
What feeds the score
Wolfix does not assign severity from the type of finding alone. It weighs what it actually detected during the scan against the context of your specific project:
- Legal exposure — does the gap create liability under a regulation that applies to you, given your detected jurisdiction and data types?
- Payment impact — does the gap stop you from collecting money, or put a payment processor relationship at risk?
- Data sensitivity — does the finding touch user data, secrets, or authentication?
- Audience and reach — a public, EU-facing app raises the stakes on consent and disclosure findings that a private prototype would not face.
Because context drives the score, the same kind of finding can sit at different levels in different reports. Cookie consent is a guide for a static brochure site and a blocker for an app loading tracking scripts for EU users.
Trust the order
The findings list is already sorted by score, highest impact first. You do not need to read severity labels to prioritise — just work top to bottom and stop when you run out of time.
How the score shapes the report
The score does three things in the report:
- Counts the stat tiles. Blockers and risks roll up into the numbers at the top, giving you an instant readiness reading.
- Orders the findings list. Highest-impact findings sit at the top of their section so the most consequential work is never buried.
- Sets the tone of each card. Blocker cards lead with what is at stake; guide cards lead with the improvement on offer.
Scores are recalculated on every scan. After you fix a blocker and re-scan, that finding either disappears or drops to a lower band, and your stat-tile counts move with it.