I was considering adding a rating per website to the scanner, in a similar fashion to SSLLabs or SecurityHeaders.io, but am not really sure how to do it. Any suggestion is welcome.
I guess it doesn't make sense to rate something based on the forum settings or the amount of extensions... The only thing that I think make sense is server and software security.
I was thinking of something like:
- A+: same as A, but implements recommended security headers
- A: correctly configured on HTTPS
- B: correctly configured on HTTPS but with deprecated extensions or suboptimal redirects
- C: Invalid configuration or HTTP only
- D: known security issues and/or outdated Flarum and/or vulnerable extensions