How is this different from your /magento-store-health-checklist?
Different scope, different depth, complementary.
/magento-store-health-checklist:
- Broader, covers SEO, performance, UX, content, conversion, accessibility, plus security.
- Lighter on security, ~10 security questions out of ~60 total.
- Static checklist with self-rating; no weighted scoring.
- Best for: a quarterly "is everything still okay" review.
/magento-security-score-checker (this tool):
- Narrower, security-only across 5 categories.
- Deeper, 25 questions weighted by severity, server-scored, with a prioritized fix list.
- Real numeric output, 0-100 score + A/B/C/D/F + 5 sub-scores.
- Best for: pre-PCI-audit prep, post-incident review, or a focused security improvement sprint.
Recommended cadence:
- Monthly: Run /magento-store-health-checklist as a 15-min overall posture review.
- Quarterly: Run this security score checker as a 5-min focused security drill.
- Annually: Commission a real external pentest + (if applicable) PCI assessment.
The two tools share their philosophy: free, anonymous, honest, severity-weighted, no upsell required. If the score checker surfaces a critical gap, the health checklist will usually agree, just less specifically.