Methodology
The rules, before the numbers.
A ranking of other people’s projects is only worth reading if its criterion is technical, quantifiable and public. This document is that criterion: what is measured, how it weighs, how the total is computed, what is deliberately left unscored, and where every published figure comes from.
Applies to the current measurement of 26 September 2026. Every figure on this page is re-runnable: the engine, the probes and the inputs are stated at the end.
First: two different numbers
The exposure score and the unified score are not the same figure
Search exposure (WSEP) is what the ranking orders by: a 0–100 measurement of whether a project can be found and read — by people, by crawlers and by AI agents — built from what the project publishes about itself and from public sources.
The unified score is what the free score returns: the engine’s declared weighting, 60% exposure + 40% post-quantum readiness. Two figures from the same engine are not interchangeable and this page does not pretend they are: the ranking shows exposure, and post-quantum readiness beside it as its own column.
The five dimensions
What the 0–100 is made of
The catalogue groups every module into five dimensions. The weights are the engine’s own, and they are the reason a project cannot be strong in one thing and invisible in the rest.
| Dimension | Weight | What it covers |
|---|---|---|
| Identity & metadataWSEP-1 | 30 | Whether the site says who it is: registry record and real age of the domain, corroborated brand, semantic metadata, DNS trust records and anti-spoofing. |
| Performance & availabilityWSEP-2 | 15 | What was measured in the capture: size, compression, response times, links and images. |
| Security & verificationWSEP-3 | 20 | Secure connection and security headers, plus what the chain says about the contract the site publishes (readable source, ECDSA use). |
| Ecosystem authorityWSEP-4 | 20 | Measurable authority: on-chain footprint, own public registry, archived continuity and open-index presence. |
| Tech stack & AI agentsWSEP-5 | 15 | Detected technology, exposure to AI crawlers, and whether an AI agent can read and discover the site. |
The modules
The complete catalogue, including what does not score yet
Each module measures one thing and carries its own weight inside its dimension. A module with no measurement of its own is declared here as not scored yet — it is never filled with an invented number.
| Dim. | Module | Weight | What it measures |
|---|---|---|---|
| WSEP-1 | Semantic metadata | 2 | title, description, canonical and social cards of the captured page |
| WSEP-1 | Corroborated external identity | 1.5 | real domain record and age (RDAP), popularity (Tranco), corroborated brand (Wikidata), Farcaster and GitHub |
| WSEP-1 | Content | 1 | volume and structure of the page text |
| WSEP-1 | Heading hierarchy | 1 | order and presence of h1-h6 |
| WSEP-1 | Structured data | 1 | JSON-LD / microdata present and valid |
| WSEP-1 | DNS trust and anti-spoofing | 1 | DNSSEC, DMARC and SPF published, and DNSLink, read over public DNS-over-HTTPS |
| WSEP-1 | Topics and keywordsnot scored yet | 0.5 | own term extraction from the content (never search volume or CPC: not freely measurable) |
| WSEP-2 | Measured performance | 2 | size, compression, response times and resource weight measured in the capture |
| WSEP-2 | Internal and external links | 1 | link density and health of the document |
| WSEP-2 | Image resources | 1 | images with alt text, format and declared resolution |
| WSEP-3 | Connection and header security | 2 | HTTPS, HSTS, CSP, X-Frame-Options and X-Content-Type-Options read from the real headers |
| WSEP-3 | Verified smart contract | 1.5 | contract verification and how the site connects to the chain (public RPC, no paid provider) |
| WSEP-3 | On-chain proof of the published contract | 1.5 | code published on public networks (keyless RPC), name/symbol/decimals/totalSupply by eth_call, EIP-1967 proxy and source verification |
| WSEP-3 | Content authenticitynot scored yet | 0.5 | own heuristics over the HTML and content availability on IPFS |
| WSEP-4 | On-chain reading | 1.5 | on-chain activity of the target by public RPC |
| WSEP-4 | NFT assets | 1 | collections and NFT activity of the target |
| WSEP-4 | Ecosystem (TVL and liquidity) | 1 | TVL of the DefiLlama protocol that claims this domain, and liquidity/volume of the tokens the site itself publishes |
| WSEP-4 | Own on-chain registry | 1.5 | presence, score, confidence, age, IPFS report and quantum echo of the target in our own public Polygon registry (read by keyless RPC) |
| WSEP-4 | Continuity in the open world | 1.5 | first and recent capture in the Wayback Machine, and presence in the Common Crawl open index (the corpus LLMs feed on) |
| WSEP-4 | History and availabilitynot scored yet | 0.5 | timeline of our own stored measurements (measured uptime, not a third party’s) |
| WSEP-4 | Web3 social presencenot scored yet | 0.5 | Farcaster/GitHub/own feed (the free part; X and Lens are declared not measured) |
| WSEP-4 | Popularity and referencesnot scored yet | 0.5 | measured popularity (Tranco) and real coverage (Common Crawl). “Who links to whom” is not bought |
| WSEP-5 | Technology stack | 2 | technologies detected in the HTML and the real headers (own detector) |
| WSEP-5 | Search and AI-crawler exposure | 1.5 | robots.txt and its policy for AI crawlers, llms.txt, sitemap, feed and meta robots / X-Robots-Tag, measured on the site itself |
| WSEP-5 | Readability by AI agents | 1.5 | content negotiation (Accept: text/markdown), agent descriptor (OpenAPI/MCP/plugin) and HTML readability without JavaScript |
| WSEP-5 | Discovery by agents (A2A, MCP, Content-Signal) | 1.5 | A2A agent card at /.well-known/agent-card.json, live MCP server at /mcp and Content-Signal declared in robots.txt |
| WSEP-5 | Spatial / metaversenot scored yet | 1 | own detectors for 3D/spatial assets (today a standalone frontend tool: it does not score) |
The arithmetic, in the open
The total renormalises over what was actually measured
- Not measuring does not penalise. A module that could not run is not a zero: the total is re-normalised over the weight of the dimensions that were really measured. A project is never punished for our blind spots.
- A low-confidence reading does not count as a reading. Below a confidence of 40 the module is declared and excluded from the total, instead of contributing a number nobody should trust.
- Measured weight is published. Each row carries the sum of the weights of the dimensions that were measurable (30 + 15 + 20 + 20 + 15). That is why two rows can show the same coverage level with a different measured weight, and why the weight is printed beside the score instead of hidden.
- Coverage is how deep the measurement went — nothing else. A = identity was measurable · AA = identity and security · AAA = identity, security and ecosystem authority. It is not a conformity certificate and must never be read as one.
- If the site did not deliver its HTML, the number is flagged as not comparable. A site that refuses the read (anti-bot gate, rate limit, timeout) would otherwise be scored from external sources alone and look worse than a site that did let itself be read. It is declared, not scored.
The post-quantum column
Four verdicts, never merged — and a fifth case declared
The probe reads the key exchange the site actually negotiates in the TLS handshake and scans the JavaScript the site serves for post-quantum primitives (ML-KEM, ML-DSA, SLH-DSA and the libraries that carry them). The network behind the host is attributed by ASN, so a CDN’s work is never credited to the project — and it is never held against a project either.
- PQ in its own codepost-quantum cryptography found in the JavaScript the project itself serves — the signature layer, the part a quantum computer actually breaks
- PQ on its own edgethe hybrid key exchange is served by the project’s own network, not by a CDN it rents
- PQ borrowed from its CDNthe hybrid key exchange comes from the CDN in front of them (Cloudflare, Fastly, Akamai, CloudFront, Bunny, Imperva). Real protection, but not their work
- no PQ measuredno post-quantum signal measured anywhere: classical key exchange
- not measurablethe probe could not reach a conclusion on that row. It is declared instead of scored, and it is never counted as “nothing”
The rule that matters: borrowed is not prepared. A project behind a CDN inherits hybrid key exchange without doing anything; one running its own edge may look worse and be further along. The column says whose cryptography it is — never how serious the project is.
The ranking
Four families, each with its selection rule declared
- Nothing is hidden inside the sample. Each family says how its rows were chosen: web3 domains — the first 10 of the measured sample (top 40 by DefiLlama TVL), in measurement order; powerful contracts — oracles and contracts holding money, with the address DefiLlama declares; memes — the largest by market capitalisation with a project site of their own (CoinGecko, by id); NFTs — an editorial selection of well-known collections (no free source for volume).
- The order is post-quantum first, then exposure. The priority of the table is measured readiness for the quantum era; the exposure score decides inside each verdict group.
- One entity, one row. A project is published in a single family; two different numbers for the same site in one page would be a defect, not a feature.
- Rows that could not be measured are printed with the evidence. An anti-bot gate, a rate limit or a timeout is stated on the row, with what the site answered — checkable by opening the same site yourself.
- The order is not for sale. No project can buy a position, a score or a module result.
Declared, not scored
What this measurement cannot see
- A door that will not open. If a site answers an anti-bot gate to our reader, its HTML is not measured: the row is declared, with the answer it gave.
- A project with no declared site. If the project publishes no working domain, the row says so with the domain its own source declares — never a look-alike domain.
- Floor price and secondary volume for NFTs. There is no free source; the column is declared empty instead of filled with a number nobody can check.
- A partial capture. Where the page is bigger than the read limit, the row declares that only the first stretch was read. That score is a floor, not a ceiling.
- Traffic, search volume and conversion. None of it is used — it is not freely measurable, and pretending to measure it would be the easiest lie in this market.
Data attribution
Where every published figure comes from, and when it was consulted
Part of these figures come from third-party public APIs, and publishing them with attribution is the condition of their use — not a courtesy. Each source below states what it feeds, the date it was consulted, and how the data is reused.
- StygiaScore WSEP engine (our own measurement)search exposure · consulted 26 Sept 2026
our own engine, querying public sources only: RDAP registry records, DNS-over-HTTPS (Google and Cloudflare resolvers), Tranco, Common Crawl, the Wayback Machine, Sourcify and public RPC nodes. No paid provider and no API key involved.
- Post-quantum probe (our own tool)post-quantum verdict · consulted 26 Sept 2026
our own probe: it reads the key exchange the site actually negotiates in the TLS handshake and scans the JavaScript the site serves for post-quantum libraries. The network behind the host is attributed by ASN (RIPE Stat, BGPView), so a CDN’s work is never credited to the project.
- DefiLlamaTVL · consulted 24 Sept 2026
public API. Figures are published with attribution to DefiLlama; no raw dataset is redistributed, resold or republished.
- CoinGeckomarket capitalisation · consulted 24 Sept 2026
public API (free tier, rate-limited), read by coin id and never by ticker — two projects can share a symbol. Attribution shown as required; no raw dataset is redistributed.
- Public chain sourcesreadable source, ECDSA use, native balance · consulted 24 Sept 2026
read-only calls to public RPC endpoints (Polygon, Ethereum, BNB, Avalanche) and to Etherscan/Sourcify-compatible source verification. No private key, no account data and no paid indexer is involved.
- Site-answer probe (our own tool)the evidence printed on rows that could not be measured · consulted 26 Sept 2026
our own probe records what each excluded site answered, at the moment of the run, so the reason on the row can be checked by opening the same site yourself.
No provider’s raw dataset is redistributed, resold or republished: what is published is a derived measurement with its date. Where a provider requires attribution, it is printed here and on the ranking.
What this is not
No advice, no audit, no endorsement
Automated measurement of public data on a stated date · not financial advice · not a security audit · not an endorsement · nobody can buy a position
This is not financial, investment or trading advice, and it is not a price or value opinion about any asset. It is not a security audit either: it reads a subset of public signals on a stated date and cannot find every flaw in a project. Scores change as projects — and public sources — change.
StygiaScore is not affiliated with, sponsored by or endorsed by any project listed, and no project has reviewed, approved or paid for its row. Names and domains are used nominatively, to identify what is being measured, and are the property of their owners.
- A dated snapshot, not a verdict. Scores change when projects change and when public sources change. Each row carries the date it was last scanned, and the breakdown by source, so the freshness of every figure is visible instead of implied.
- Not a security audit. It reads a subset of public signals; a clean row does not mean a project is free of flaws, and a low score does not mean it is unsafe.
- No relationship with the projects. They are named to identify what is being measured (nominative use) and keep the ownership of their names and domains.
Corrections and right of reply
If a figure is wrong, it gets corrected in public
A project — or anyone — can dispute a row. What is needed: the row, the figure being disputed, and the evidence that contradicts it (a URL, a response from the source, a measurement of your own). Send it through the contact page.
- Corrections are dated, never silent. The measurement is re-run and the new snapshot replaces the old one with its own date. A change is datable, not invisible: every table carries the day it was read, so a before and an after can always be pointed at — and a public log of every change to a published figure is the next step on this page, together with anchoring each measurement on-chain.
- A row removed by our own decision is declared. If we withdraw something, its score and the reason stay published. An omission you can see costs the table nothing; a silent one would cost it everything.
- Nobody can pay for a different result. Not for a position, not for a module result, not for a row. The only thing that can be bought is a diagnosis of which module costs points and what would move it.
Reproduce it
The measurement is a runnable pipeline, not a private dashboard
The exposure column comes from the WSEP engine over the public sources listed above; the post-quantum column from our own probe reading the TLS handshake and the served JavaScript; the power column from DefiLlama, CoinGecko or the chain itself. Every table is generated from those runs — no figure on the ranking is typed by hand, including the scan dates.