Website Security Score Comparator

Compare the security posture of up to five sites you are authorised to test, normalised by category so the differences are meaningful rather than cosmetic.

Runs locally

Everything happens in your browser. What you paste or drop here is never uploaded, logged or stored.

Use the tool

Two to five audit results, compared in your browser. Nothing is uploaded.

Unreachable is not the same as secure

The failure mode of every scoring comparison is the same. One site's TLS check timed out, so it produced no transport findings, so its transport column looks clean, so it wins. The way to top the table becomes being hard to measure - which is the precise opposite of what the table is meant to show.

So checks that did not run and findings that could not be established are never folded into the passes. They are counted in their own Unresolved column, every audit carries a completeness note next to its score, and a category that produced no findings at all is labelled not measured rather than shown as a blank that reads like a clean sheet.

Category scores, not just the headline

Two sites can arrive at the same overall score by entirely different routes - one with weak transport security and excellent headers, the other the reverse. The overall number hides that, so the second table breaks the comparison down by category, before weighting, with a spread column that highlights where the group genuinely diverges.

A wide spread in one category is usually the most useful thing on the page: it is a control that some of the group has and the rest does not, which is a much more actionable observation than "site B scores four points lower than site A".

Different methodology versions are not comparable

The audit's scoring model is versioned. If the audits you load were scored under different versions, the comparison says so at the top: the individual findings still line up correctly, but the headline numbers were produced by different rules, and part of the difference between them is a difference in the ruler rather than in the sites.

Only test what you are authorised to test

This tool compares audit results you already hold. It runs no scans of its own. Producing those results in the first place means auditing the sites, and you should only do that for sites you own or have written permission to assess.

Everything stays local

Five audit reports side by side amount to a map of which of those sites is weakest - which is not a document to upload anywhere. All five are read, compared and exported entirely in your browser.

Frequently asked questions

How many audits can I compare?

Two at minimum, five at most. Past five the table stops being readable, which defeats the purpose.

Why does one column say "not measured"?

That category produced no findings in that audit. It may not apply - a domain with no mail has no email authentication to score - or the check may not have run. Either way it is not evidence of a good result, so it is not displayed as one.

Can I compare audits of the same site over time?

You can, but the Regression Checker is built for that: it matches individual findings between two audits and tells you which specific controls changed.

Will it read an older export?

Yes, any schema version 1.x document plus pre-versioning exports, which are upgraded on read. Documents from a newer major version are refused rather than guessed at.

Are the reports uploaded?

No. Reading, comparison and export all happen in your browser.

References

What this tool can and cannot tell you. It reports what is present in the input you provide. It cannot see anything you did not give it, and a clean result means nothing was found in that input - not that the wider system is secure.

Security guidance here follows current published sources - OWASP, MDN, the relevant RFCs, NIST, CISA, FIRST and MITRE - which are linked beside the specific claims they support.

Rate this tool

Was this tool useful? Your feedback helps us improve it.

No ratings yet — be the first to rate this tool.
Your rating (required)
0 / 2000

Please do not include passwords, payment details or other sensitive information.

Your feedback is sent privately to the A2Z.Tools team and will not be posted publicly.