How we work out the numbers

Every figure in a Checkover report is an estimate built from published research and typical numbers for your kind of business. None of it is a measurement of your accounts. This page publishes every input, so you can check the working or decide we are wrong.

The shape of a calculation

Each finding declares how it costs money, not how much. Seven mechanisms are possible: visitors lost, trust eroded, traffic that never arrives, legal exposure, fraud exposure, incident exposure, and downtime. The engine turns the mechanism plus your business profile into a range.

Where a finding describes a one-off event, such as a fine or a fraud, we multiply the typical cost by the chance of it happening in a year and divide by twelve. That is why a rare, expensive risk shows a small monthly number. It is not a prediction that it happens every month.

Starting figures by kind of business

These are the defaults before you correct them. They are deliberately modest. A scanner that assumes every business gets fifty thousand visits a month produces impressive nonsense.

Kind of businessVisits a monthBecome customersAverage value
Restaurant or cafe1,8003.5%£48
Clinic or dental practice1,2002.8%£190
Legal or accounting firm9002.2%£850
Trades or home services1,1004.0%£320
Online shop4,5001.9%£62
Agency or consultancy8001.8%£2400
Hotel or accommodation2,6002.4%£210
Something else1,2002.5%£150

How people behave

Where a published range exists, we take the conservative end. We would rather be dull than wrong.

abandon on security warning28.0%
GlobalSign consumer trust research, 2024; conservative end of the reported rangeReported effects run higher. We use the low end deliberately.
form abandon on insecure field42.0%
Baymard Institute checkout usability research, security signalling
mobile traffic share63.0%
StatCounter global mobile share of page views, rolling 12 month average
mobile unusable penalty55.0%
Google mobile usability guidance; effect on task completion
loss per second delay7.0%
Deloitte Milliseconds Make Millions, 2020; 0.1s improvement moved conversion 8%
ctr loss no description6.0%
Aggregate SERP click-through studies; conservative midpoint
local pack loss no schema12.0%
Local search visibility studies on rich result eligibility
trust signal loss9.0%
Edelman and BrightLocal consumer trust surveys on business legitimacy signals

Costs of things going wrong

accessibility claim

Typical cost: £25,000 (UsableNet year-end digital accessibility lawsuit reports; typical settlement plus remediation)

Chance in a year: 0.8% (Filings against small businesses as a share of US small business websites)

data protection action

Typical cost: £9,000 (ICO small-business enforcement outcomes plus typical response cost)

Chance in a year: 1.2% (Complaint-driven enforcement rate; cookie consent is the most reported category)

email impersonation

Typical cost: £19,000 (FBI IC3 annual report, BEC median loss for small business filers)

Chance in a year: 2.1% (IC3 BEC complaint volume against registered small business count)

site compromise

Typical cost: £4,200 (Hiscox and Verizon DBIR small-business incident cost, cleanup plus downtime)

Chance in a year: 4.0% (Sucuri and Wordfence infection rates across scanned small-business sites)

card compliance failure

Typical cost: £5,500 (Acquirer non-compliance fees plus forensic review, small merchant tier)

Chance in a year: 3.0% (Merchant assessment failure rates in the SAQ-A population)

What we check

169 checks across 12 areas. A free scan runs 41 of them and shows every result in full, priced, with the arithmetic. The rest look at things your visitors never see, or need proof you own the domain before we may ask your server for them. Whatever we run, you see all of it: nobody should have to pay to find out what we already know about their own website.

transport security

  • Secure connection
  • Insecure address redirects
  • Certificate expiry
  • Certificate matches the address
  • Certificate trust
  • Old encryption versions
  • Insecure items on a secure page
  • Stay-secure instruction
  • Current encryption version
  • Certificate signature strength
  • Certificate key size
  • Certificate coverage
  • Certificate lifetime
  • Stay-secure instruction length
  • Stay-secure coverage

http headers

  • Script injection defence
  • Script policy strength
  • Clickjacking defence
  • File type enforcement
  • Address privacy
  • Device access limits
  • Software version disclosure
  • Cross-site data access
  • Links that open in a new tab
  • Embedded outside pages
  • Content policy source list
  • Content policy framing rule
  • Application software disclosure
  • Which sites may read your data
  • Which commands your server accepts

cookies privacy

  • Cookie protection
  • Fonts loaded from Google
  • Screen recording
  • Advertising pixels
  • Embedded content privacy
  • Cookie lifetimes
  • Cookie cross-site rules
  • Cross-site cookie safety
  • Login cookie protection

dns email

  • Email impersonation protection
  • Email protection strength
  • Approved email senders
  • Email sender rules
  • Email record limits
  • Email signing
  • Certificate issuance control
  • Domain record signing
  • Email delivery
  • Email sender record validity
  • Domain name server redundancy
  • Mail server redundancy
  • Email protection reporting
  • Email protection coverage
  • Certificate issuance alerts
  • Verified logo in inboxes
  • Lookalike domains that can send email
  • Domains resembling yours
  • Enforced mail encryption
  • Mail encryption reporting
  • Approved sender method
  • Email protection for subdomains

exposure leaks

  • Keys in public code
  • Original source code
  • Security contact
  • Email address exposure
  • Source code repository
  • Configuration file with passwords
  • Website backup left in the open
  • Database export left in the open
  • Server configuration page
  • Software parts list
  • API documentation
  • Application management endpoints
  • Administration login page
  • WordPress account listing
  • Hidden folder index
  • Web server configuration file
  • Developer notes in the page
  • Public cloud storage
  • Cloud provider credentials
  • Private key file
  • Package registry token
  • Editor and deploy settings
  • Configuration file backups
  • Application log file
  • Subversion metadata
  • Folder browsing
  • Code that builds and runs new code
  • Code that inserts unchecked HTML
  • Messages from other windows
  • Credentials kept in the browser
  • Unencrypted addresses in code
  • How random values are generated
  • Developer notes in the bundle
  • API schema disclosure
  • WordPress remote interface

dependencies cve

  • Known-vulnerable components
  • Outside script verification
  • Outside code from dead domains
  • Website software version
  • Add-on list and versions
  • Published weaknesses on your server
  • Outside code providers
  • Debug code in the live site
  • Retired browser features
  • Whether your code could be read
  • Published weaknesses in the code you load
  • Code we could not identify

infrastructure

  • Abandoned service pointers
  • Domain renewal
  • Domain transfer lock
  • The www version of your address
  • Forgotten sites on your domain
  • Databases reachable from the internet
  • Remote control services
  • Outdated network services

compliance

  • Privacy policy
  • Consent before tracking
  • Cookie policy link
  • Privacy policy accuracy
  • Where form submissions go
  • Accessibility statement
  • Terms and conditions
  • Refund and returns policy
  • Cookie detail behind the banner

content trust

  • Form submission safety
  • Form spam protection
  • Site freshness signals
  • Contact information
  • Unfinished template text
  • Holding page
  • Tap to call
  • Browser tab icon
  • Text encoding declaration
  • Physical address
  • Opening hours
  • Links to insecure pages
  • Reviews and ratings
  • Where form submissions go
  • Forwarding to any address
  • Blocklists and browser warnings

performance

  • Mobile display
  • Server response speed
  • Page weight
  • Image sizes
  • Response compression
  • Connection protocol
  • Browser caching
  • Production build quality

accessibility

  • Image descriptions
  • Form labels
  • Page language
  • Pinch to zoom
  • Heading order
  • Link descriptions
  • Skip to content
  • Form autofill hints

seo discoverability

  • Search engine access
  • Page title
  • Search result description
  • Business information for search engines
  • Site map
  • Crawler instructions
  • AI assistant visibility
  • Duplicate address handling
  • How your links look when shared
  • Main page heading
  • Competing page headings
  • Page auto-forwarding

What these numbers are not