How we work out the numbers
Every figure in a Checkover report is an estimate built from published research and typical numbers for your kind of business. None of it is a measurement of your accounts. This page publishes every input, so you can check the working or decide we are wrong.
The shape of a calculation
Each finding declares how it costs money, not how much. Seven mechanisms are possible: visitors lost, trust eroded, traffic that never arrives, legal exposure, fraud exposure, incident exposure, and downtime. The engine turns the mechanism plus your business profile into a range.
Where a finding describes a one-off event, such as a fine or a fraud, we multiply the typical cost by the chance of it happening in a year and divide by twelve. That is why a rare, expensive risk shows a small monthly number. It is not a prediction that it happens every month.
Starting figures by kind of business
These are the defaults before you correct them. They are deliberately modest. A scanner that assumes every business gets fifty thousand visits a month produces impressive nonsense.
| Kind of business | Visits a month | Become customers | Average value |
|---|---|---|---|
| Restaurant or cafe | 1,800 | 3.5% | £48 |
| Clinic or dental practice | 1,200 | 2.8% | £190 |
| Legal or accounting firm | 900 | 2.2% | £850 |
| Trades or home services | 1,100 | 4.0% | £320 |
| Online shop | 4,500 | 1.9% | £62 |
| Agency or consultancy | 800 | 1.8% | £2400 |
| Hotel or accommodation | 2,600 | 2.4% | £210 |
| Something else | 1,200 | 2.5% | £150 |
How people behave
Where a published range exists, we take the conservative end. We would rather be dull than wrong.
- abandon on security warning28.0%
- GlobalSign consumer trust research, 2024; conservative end of the reported rangeReported effects run higher. We use the low end deliberately.
- form abandon on insecure field42.0%
- Baymard Institute checkout usability research, security signalling
- mobile traffic share63.0%
- StatCounter global mobile share of page views, rolling 12 month average
- mobile unusable penalty55.0%
- Google mobile usability guidance; effect on task completion
- loss per second delay7.0%
- Deloitte Milliseconds Make Millions, 2020; 0.1s improvement moved conversion 8%
- ctr loss no description6.0%
- Aggregate SERP click-through studies; conservative midpoint
- local pack loss no schema12.0%
- Local search visibility studies on rich result eligibility
- trust signal loss9.0%
- Edelman and BrightLocal consumer trust surveys on business legitimacy signals
Costs of things going wrong
- accessibility claim
Typical cost: £25,000 (UsableNet year-end digital accessibility lawsuit reports; typical settlement plus remediation)
Chance in a year: 0.8% (Filings against small businesses as a share of US small business websites)
- data protection action
Typical cost: £9,000 (ICO small-business enforcement outcomes plus typical response cost)
Chance in a year: 1.2% (Complaint-driven enforcement rate; cookie consent is the most reported category)
- email impersonation
Typical cost: £19,000 (FBI IC3 annual report, BEC median loss for small business filers)
Chance in a year: 2.1% (IC3 BEC complaint volume against registered small business count)
- site compromise
Typical cost: £4,200 (Hiscox and Verizon DBIR small-business incident cost, cleanup plus downtime)
Chance in a year: 4.0% (Sucuri and Wordfence infection rates across scanned small-business sites)
- card compliance failure
Typical cost: £5,500 (Acquirer non-compliance fees plus forensic review, small merchant tier)
Chance in a year: 3.0% (Merchant assessment failure rates in the SAQ-A population)
What we check
169 checks across 12 areas. A free scan runs 41 of them and shows every result in full, priced, with the arithmetic. The rest look at things your visitors never see, or need proof you own the domain before we may ask your server for them. Whatever we run, you see all of it: nobody should have to pay to find out what we already know about their own website.
transport security
- Secure connection
- Insecure address redirects
- Certificate expiry
- Certificate matches the address
- Certificate trust
- Old encryption versions
- Insecure items on a secure page
- Stay-secure instruction
- Current encryption version
- Certificate signature strength
- Certificate key size
- Certificate coverage
- Certificate lifetime
- Stay-secure instruction length
- Stay-secure coverage
http headers
- Script injection defence
- Script policy strength
- Clickjacking defence
- File type enforcement
- Address privacy
- Device access limits
- Software version disclosure
- Cross-site data access
- Links that open in a new tab
- Embedded outside pages
- Content policy source list
- Content policy framing rule
- Application software disclosure
- Which sites may read your data
- Which commands your server accepts
cookies privacy
- Cookie protection
- Fonts loaded from Google
- Screen recording
- Advertising pixels
- Embedded content privacy
- Cookie lifetimes
- Cookie cross-site rules
- Cross-site cookie safety
- Login cookie protection
dns email
- Email impersonation protection
- Email protection strength
- Approved email senders
- Email sender rules
- Email record limits
- Email signing
- Certificate issuance control
- Domain record signing
- Email delivery
- Email sender record validity
- Domain name server redundancy
- Mail server redundancy
- Email protection reporting
- Email protection coverage
- Certificate issuance alerts
- Verified logo in inboxes
- Lookalike domains that can send email
- Domains resembling yours
- Enforced mail encryption
- Mail encryption reporting
- Approved sender method
- Email protection for subdomains
exposure leaks
- Keys in public code
- Original source code
- Security contact
- Email address exposure
- Source code repository
- Configuration file with passwords
- Website backup left in the open
- Database export left in the open
- Server configuration page
- Software parts list
- API documentation
- Application management endpoints
- Administration login page
- WordPress account listing
- Hidden folder index
- Web server configuration file
- Developer notes in the page
- Public cloud storage
- Cloud provider credentials
- Private key file
- Package registry token
- Editor and deploy settings
- Configuration file backups
- Application log file
- Subversion metadata
- Folder browsing
- Code that builds and runs new code
- Code that inserts unchecked HTML
- Messages from other windows
- Credentials kept in the browser
- Unencrypted addresses in code
- How random values are generated
- Developer notes in the bundle
- API schema disclosure
- WordPress remote interface
dependencies cve
- Known-vulnerable components
- Outside script verification
- Outside code from dead domains
- Website software version
- Add-on list and versions
- Published weaknesses on your server
- Outside code providers
- Debug code in the live site
- Retired browser features
- Whether your code could be read
- Published weaknesses in the code you load
- Code we could not identify
infrastructure
- Abandoned service pointers
- Domain renewal
- Domain transfer lock
- The www version of your address
- Forgotten sites on your domain
- Databases reachable from the internet
- Remote control services
- Outdated network services
compliance
- Privacy policy
- Consent before tracking
- Cookie policy link
- Privacy policy accuracy
- Where form submissions go
- Accessibility statement
- Terms and conditions
- Refund and returns policy
- Cookie detail behind the banner
content trust
- Form submission safety
- Form spam protection
- Site freshness signals
- Contact information
- Unfinished template text
- Holding page
- Tap to call
- Browser tab icon
- Text encoding declaration
- Physical address
- Opening hours
- Links to insecure pages
- Reviews and ratings
- Where form submissions go
- Forwarding to any address
- Blocklists and browser warnings
performance
- Mobile display
- Server response speed
- Page weight
- Image sizes
- Response compression
- Connection protocol
- Browser caching
- Production build quality
accessibility
- Image descriptions
- Form labels
- Page language
- Pinch to zoom
- Heading order
- Link descriptions
- Skip to content
- Form autofill hints
seo discoverability
- Search engine access
- Page title
- Search result description
- Business information for search engines
- Site map
- Crawler instructions
- AI assistant visibility
- Duplicate address handling
- How your links look when shared
- Main page heading
- Competing page headings
- Page auto-forwarding
What these numbers are not
- They are not a measurement. We cannot see your traffic or your takings unless you tell us.
- They are not a legal opinion. Where we mention a rule, we name it so a solicitor can check it. We are not one.
- They are not a promise that a problem will cost you exactly this. They are an ordering device: the biggest number is the thing to look at first.
- Automated accessibility checks catch roughly a third of what a real audit finds. A clean result there means the machine found nothing, not that a person using a screen reader can use your site.