EYThe LogEmre Yakut
← all entries
Metering · Systems · deep

If it cannot be measured, it says “not verified”

I ran the same technical audit by hand for every client: two hours, missing something each time. I turned it into an engine. The hard part was not the scoring formula — it was deciding not to produce a number.

65 · kritik 1 tane38 · 3 kritik23 · 6 kritik0ceza →kategori skoruskor = 100 · 55 / (55 + ceza)ilk sorun skoru sert düşürür, yirmincisi neredeyse hiç — çünkü gerçek de öyleölçülemeyen kategori ortalamaya KATILMAZ. uydurma skor üretilmez.

For every new client I did the same work: open the site, check the certificate, check the headers, query DNS records, identify the technology, look for known vulnerabilities in its version, review the privacy texts.

Two hours. Every client. And I missed something every time.

I turned it into an engine: Globya Radar. You give it an address; the scan streams live and produces an evidenced list of findings and a transparent score.

What it measures

categoryweightexample check
SEO fundamentals18canonical, duplicate tags, 404 behaviour, www canonicalisation
Security17headers, cookie attributes, open ports, .git/.env exposure
AI visibility13live bot access testing, llms.txt, JS-dependent content
Performance13TTFB, real file weight sampling, compression, caching
Email & DNS11SPF lookup count, 26 common DKIM selectors, DMARC policy, DNSSEC
Technology1160+ fingerprints, library versions, public vulnerability lookup
Privacy & cookies10tracking cookies set before consent, adequacy of the texts
Content & accessibility7copyright freshness, leftover template text, broken links

The two in bold are the hardest to do by hand — and the most revealing.

Live bot access testing

A robots.txt saying an AI crawler is allowed does not mean it can actually get in. A server, firewall or intermediary layer may be blocking it separately.

So the engine does not stop at reading the file: it makes a real request as each crawler and looks at what comes back. The result is regularly surprising — a number of sites that say “allowed” block in practice.

Cookies set before consent

There is a cookie banner, there is an “accept” button — and tracking cookies were already set as the page loaded. The engine loads the page without clicking anything and lists the cookies set at that moment.

One check shows directly whether a compliance claim is real.

The score: a saturating curve

Every finding carries a penalty: critical 30, high 18, medium 9, low 4. My first attempt summed penalties and subtracted from 100. Bad idea — a site with four critical findings went negative, and four and twelve became indistinguishable.

category score
score = 100 × 55 / (55 + total_penalty)

Penalty 0 gives 100. Penalty 55 gives 50. It approaches zero asymptotically and never goes negative. The first problems cut hard, the twentieth almost not at all.

That behaviour reflects reality better: on a site with no security headers, the first missing header is a serious signal; the sixth only means this site never considered security headers at all — it carries no new information.

The most important rule

A category that could not be audited is excluded from the average. No invented score is produced.

If a category cannot be measured — the server timed out, DNS did not answer — no number is assigned to it. It is removed from the denominator and the report says “not verified”.

what this means in a client document

This report is a sales tool. So every number in it must be falsifiable — because the client will get a second opinion.

If a single guessed number is caught, the credibility of the whole report is gone. A line saying “not verified” is worth infinitely more than an invented number.

Technically it was the easiest part and, as a decision, the hardest. An incomplete score table looks incomplete; a guessed value looks complete and can be entirely wrong.

I had applied the same rule in the room measurement tool — there too the tool sometimes refuses to produce a number.

Every finding carries three parts

finding:  "SSL certificate does not belong to the domain"
evidence: CN=*.hosting-provider.com, domain absent from the list
impact:   visitors see a browser warning; form submission is blocked
fix:      install a certificate issued for the domain

Without evidence a finding is a claim. Without impact it is a technical detail. Without a fix it is a complaint. Together they make a decision document.

And a diff

Scanning the same address a second time makes the engine find the previous scan and show the difference: score change, findings resolved, findings introduced, findings still open.

That is the cleanest way to prove work after doing it. Instead of the sentence “we made your site faster”, a table between two dates.

An unexpected use

I wrote the engine for client reports. After adding a batch mode it became useful for something else: building a target list.

You feed it the addresses of firms in a sector, it scans them all, and out comes a table sorted by score. The lowest scores are the firms where a proposal makes most sense.

There is also a comparison mode producing a “you and your competitors” table. That table is more persuasive than any sales sentence — because it claims nothing, it only shows the measurement.

What I learned

The value of an audit tool is not in how many problems it finds. It is in whether its findings can be trusted.

And trust comes not from producing a number in every condition but from knowing where it cannot. That half-day decision — “if you could not measure it, do not write it” — became the tool’s most valuable property.

No attacks, no guesses, no invention. What can be measured is measured; where it cannot, it says “not verified”.

MeteringSystems