Methodology
The rules, before the numbers.
A ranking of other people’s projects is only worth reading if its criterion is technical, quantifiable and public. This document is that criterion: what is measured, how it weighs, how the total is computed, what is deliberately left unscored, and where every published figure comes from.
Applies to the snapshot whose most recent source was consulted on 7 October 2026. The snapshot is not measured in one day: each row carries the dates it was last scanned by each source, and the source table at the end states the date of every one of them. Every figure on this page is re-runnable: the engine, the probes and the inputs are stated there too.
First: two different numbers
The exposure score and the unified score are not the same figure
Search exposure (WSEP) is what the ranking orders by: a 0–100 measurement of whether a project can be found and read — by people, by crawlers and by AI agents — built from what the project publishes about itself and from public sources.
The unified score is what the free score returns: the engine’s declared weighting, 60% exposure + 40% post-quantum readiness. Two figures from the same engine are not interchangeable and this page does not pretend they are: the ranking shows exposure, and post-quantum readiness beside it as its own column.
The five dimensions
What the 0–100 is made of
The catalogue groups every module into five dimensions. The weights are the engine’s own, and they are the reason a project cannot be strong in one thing and invisible in the rest.
- WSEP-1
Identity & metadata
30weightWhether the site says who it is: registry record and real age of the domain, corroborated brand, semantic metadata, DNS trust records and anti-spoofing.
- WSEP-2
Performance & availability
15weightWhat was measured in the capture: size, compression, response times, links and images.
- WSEP-3
Security & verification
20weightSecure connection and security headers, plus what the chain says about the contract the site publishes (readable source, ECDSA use).
- WSEP-4
Ecosystem authority
20weightMeasurable authority: on-chain footprint, own public registry, archived continuity and open-index presence.
- WSEP-5
Tech stack & AI agents
15weightDetected technology, exposure to AI crawlers, and whether an AI agent can read and discover the site.
The modules
The complete catalogue, including what does not score yet
Each module measures one thing and carries its own weight inside its dimension. A module with no measurement of its own is declared here as not scored yet — it is never filled with an invented number.
- WSEP-1
Semantic metadata
2weighttitle, description, canonical and social cards of the captured page
- WSEP-1
Corroborated external identity
1.5weightreal domain record and age (RDAP), popularity (Tranco), corroborated brand (Wikidata), Farcaster and GitHub
- WSEP-1
Content
1weightvolume and structure of the page text
- WSEP-1
Heading hierarchy
1weightorder and presence of h1-h6
- WSEP-1
Structured data
1weightJSON-LD / microdata present and valid
- WSEP-1
DNS trust and anti-spoofing
1weightDNSSEC, DMARC and SPF published, and DNSLink, read over public DNS-over-HTTPS
- WSEP-1
Topics and keywords
not scored yet0.5weightown term extraction from the content (never search volume or CPC: not freely measurable)
- WSEP-2
Measured performance
2weightsize, compression, response times and resource weight measured in the capture
- WSEP-2
Internal and external links
1weightlink density and health of the document
- WSEP-2
Image resources
1weightimages with alt text, format and declared resolution
- WSEP-3
Connection and header security
2weightHTTPS, HSTS, CSP, X-Frame-Options and X-Content-Type-Options read from the real headers
- WSEP-3
Verified smart contract
1.5weightcontract verification and how the site connects to the chain (public RPC, no paid provider)
- WSEP-3
On-chain proof of the published contract
1.5weightcode published on public networks (keyless RPC), name/symbol/decimals/totalSupply by eth_call, EIP-1967 proxy and source verification
- WSEP-3
Content authenticity
not scored yet0.5weightown heuristics over the HTML and content availability on IPFS
- WSEP-4
On-chain reading
1.5weighton-chain activity of the target by public RPC
- WSEP-4
NFT assets
1weightcollections and NFT activity of the target
- WSEP-4
Ecosystem (TVL and liquidity)
1weightTVL of the DefiLlama protocol that claims this domain, and liquidity/volume of the tokens the site itself publishes
- WSEP-4
Own on-chain registry
1.5weightpresence, score, confidence, age, IPFS report and quantum echo of the target in our own public Polygon registry (read by keyless RPC)
- WSEP-4
Continuity in the open world
1.5weightfirst and recent capture in the Wayback Machine, and presence in the Common Crawl open index (the corpus LLMs feed on)
- WSEP-4
History and availability
not scored yet0.5weighttimeline of our own stored measurements (measured uptime, not a third party’s)
- WSEP-4
Web3 social presence
not scored yet0.5weightFarcaster/GitHub/own feed (the free part; X and Lens are declared not measured)
- WSEP-4
Popularity and references
not scored yet0.5weightmeasured popularity (Tranco) and real coverage (Common Crawl). “Who links to whom” is not bought
- WSEP-5
Technology stack
2weighttechnologies detected in the HTML and the real headers (own detector)
- WSEP-5
Search and AI-crawler exposure
1.5weightrobots.txt and its policy for AI crawlers, llms.txt, sitemap, feed and meta robots / X-Robots-Tag, measured on the site itself
- WSEP-5
Readability by AI agents
1.5weightcontent negotiation (Accept: text/markdown), agent descriptor (OpenAPI/MCP/plugin) and HTML readability without JavaScript
- WSEP-5
Discovery by agents (A2A, MCP, Content-Signal)
1.5weightA2A agent card at /.well-known/agent-card.json, live MCP server at /mcp and Content-Signal declared in robots.txt
- WSEP-5
Spatial / metaverse
not scored yet1weightown detectors for 3D/spatial assets (today a standalone frontend tool: it does not score)
The arithmetic, in the open
The total renormalises over what was actually measured
- Not measuring does not penalise. A module that could not run is not a zero: the total is re-normalised over the weight of the dimensions that were really measured. A project is never punished for our blind spots.
- A low-confidence reading does not count as a reading. Below a confidence of 40 the module is declared and excluded from the total, instead of contributing a number nobody should trust.
- Measured weight is published. Each row carries the sum of the weights of the dimensions that were measurable (30 + 15 + 20 + 20 + 15). That is why two rows can show the same coverage level with a different measured weight, and why the weight is printed beside the score instead of hidden.
- Coverage is how deep the measurement went — nothing else. A = identity was measurable · AA = identity and security · AAA = identity, security and ecosystem authority. It is not a conformity certificate and must never be read as one.
- If the site did not deliver its HTML, the number is flagged as not comparable. A site that refuses the read (anti-bot gate, rate limit, timeout) would otherwise be scored from external sources alone and look worse than a site that did let itself be read. It is declared, not scored.
The post-quantum column
Five verdicts, never merged — and a sixth case, declared
The engine challenges the domain itself first: it asks it to sign a fresh 32-byte nonce with the post-quantum key that domain publishes, and verifies the signature — that is PQ proved with its own key, the one verdict that cannot be rented. On top of that the probe reads the key exchange the site actually negotiates in the TLS handshake and scans the JavaScript the site serves for post-quantum primitives (ML-KEM, ML-DSA, SLH-DSA and the libraries that carry them). The network behind the host is attributed by ASN, so a CDN’s work is never credited to the project — and it is never held against a project either.
- PQ proved with its own keythe domain signed a fresh challenge with the private key behind the post-quantum public key it publishes, and the engine verified the signature (ML-DSA-65, FIPS 204). A CDN standing in front of the site cannot produce that proof — it holds no private key. It is the only verdict that cannot be rented
- PQ in its own codepost-quantum code found in the JavaScript the project itself serves. A floor, not a ceiling: the probe reads the browser side, so cryptography running on a server it cannot see would be a false negative — and this verdict says nothing about the key exchange, which is the layer a harvest-now-decrypt-later attack waits on
- PQ on its own edgethe hybrid key exchange is served by the project’s own network, not by a CDN it rents
- PQ borrowed from its CDNthe hybrid key exchange comes from the CDN in front of them (Cloudflare, Fastly, Akamai, CloudFront, Bunny, Imperva). Real protection, but not their work
- no PQ measuredno post-quantum signal measured anywhere: classical key exchange
- not measurablethe probe could not reach a conclusion on that row. It is declared instead of scored, and it is never counted as “nothing”
Family: on-chain contracts · Quantum Scanner
The five contract checks the on-chain scanner runs · never merged
Powerful on-chain contracts (oracles, lending, bridges) are not measured with the web probe: they are read straight off the chain with their own Quantum Scanner — keyless RPC + the explorer’s verified source. Every row in the contracts family of the ranking runs these five checks. They are kept separate and never collapsed into one number because each one means a different thing for post-quantum exposure.
- 1 · Public key exposure (EOAs)
On a classical EVM EOA (a plain wallet) any nonce > 0, or any signed transaction in the explorer history, means the ECDSA / secp256k1 public key is already public. Harvest-now, decrypt-later attackers already have what they need; the account is not salvageable by a PQC migration of the signature — it has to rotate. This is the only check that can print critical by itself.
- 2 · Native signature model
How the account validates.
classical_ecdsa= plain wallet, still on the ECDSA model the quantum computer breaks.not_observed_yet= the wallet has never signed publicly (still classical underneath, but not yet exposed).contract_controlled_or_unknown= smart contract wallet / multisig / code-controlled account — the validation could in principle be swapped, so the check moves to step 3 and 4 below. - 3 · Validation path · ecrecover / proxy / implementation
The verified source (or, for proxies, the verified implementation source) is scanned for Solidity calls to
ecrecover(...)— the primitive that makes a contract hard-depend on classical ECDSA validation. A proxy without a readable implementation is reported as coverage-incomplete, not as a clean result. This is what theuses ecrecoverchip in the ranking means. - 4 · PQC scheme names in verified source · detection only
The same verified source is checked against NIST FIPS 203 / 204 / 205 scheme names: ML-KEM (Kyber 512/768/1024), ML-DSA / Dilithium, SLH-DSA / SPHINCS+, plus
PQCVerifier*interfaces. The green chip in the ranking says detection only on purpose: naming a scheme in source does not prove a key is actually held, that the verification path is exercised in production or that the implementation is correct. The only proof of real PQC key possession is the separate/v1/pqc/proof/:domainchallenge-response endpoint — the one a CDN cannot fake. - 5 · ZK agility signals · NOT post-quantum ⚠
The scanner also looks for Groth16, Plonk and generic
verifyProofusage in the verified source. These are pairing-based ZK SNARK verifiers over elliptic curves: they fall to Shor’s algorithm exactly the way ECDSA does, so the fuchsia chip in the ranking explicitly says NOT PQC next to it. It is a crypto-agility signal (“the contract does have a verifier and room to swap cryptography”), never a post-quantum readiness verdict — mixing them would produce a fake “PQC ready” row.
Coverage honesty rule (the same principle as the web probe): what the explorer says is about the contract; what the explorer does not answer is about the scanner. verified / unverified come from the explorer and are facts about the contract. unreadable / not_applicable mean the explorer did not answer during that scan or that the network has no explorer hooked up — they are coverage limitations of the scanner itself, never a conclusion about the contract, and the ranking paints them grey as “not measured” instead of publishing a synthetic floor.
The rule that matters: borrowed is not preparation. A project behind a CDN inherits hybrid key exchange without deciding anything; one running its own edge may look worse and be further along. The column says whose cryptography it is — never how serious the project is. The order of the table does group by that verdict, because what it ranks is the protection actually in place: own cryptography, then inherited, then none, then not measured. Read the column for the merit and the position for the protection; they are two different questions.
The ranking
Five families, each with its selection rule declared
- Nothing is hidden inside the sample. Each family says how its rows were chosen: Web2 domains of Web3 projects — the ten highest-scoring rows of the measured sample (top projects by DefiLlama TVL). The rest of the sample is not published in this family, and any row that was measured and kept out is declared with its score instead of disappearing.; powerful contracts — oracles and contracts holding money, with the address DefiLlama declares; memes — the largest by market capitalisation with a project site of their own (CoinGecko, by id); NFTs — an editorial selection of well-known collections (no free source for volume); .eth names — every .eth name that serves a page through its gateway today, out of a pool declared in full (Certificate Transparency plus the registry read on-chain) — a census, not a selection.
- The order is post-quantum first, then exposure. The priority of the table is measured readiness for the quantum era; the exposure score decides inside each verdict group.
- The top of the scale is measured, not promised. A 100 needs the five dimensions at 100 at the same time. Single dimensions have been measured at 100; the highest total the engine has returned on the most instrumented domain we could find is 86, and the highest row in the published snapshot is 75. The ranking prints that ceiling with the command that reproduces it.
- One entity, one row. A project is published in a single family; two different numbers for the same site in one page would be a defect, not a feature.
- Rows that could not be measured are declared, not turned into scores. A site that answers an anti-bot gate, a rate limit or a timeout to our reader is not measured, so it stays out of the table instead of being scored from third-party sources alone: a score computed from other people’s data is not comparable with one computed from the site, and publishing it would reward whoever blocks the measurement. A row that was measured and is kept out is a different case and is declared with its score and the reason, under its family.
- The order is not for sale. No project can buy a position, a score or a module result.
Declared, not scored
What this measurement cannot see
- A door that will not open. If a site answers an anti-bot gate to our reader, its HTML is not measured: the row is declared, with the answer it gave.
- A project with no declared site. If the project publishes no working domain, the row says so with the domain its own source declares — never a look-alike domain.
- Floor price and secondary volume for NFTs. There is no free source; the family publishes no power column at all instead of seven empty cells.
- Decentralised names (.eth, .crypto, .wallet). They are not in the ranking: the modules read the public DNS and an on-chain naming registry is a different read, so a score built here would measure nothing. Declared as a gap, not scored as a zero.
- A partial capture. Where the page is bigger than the read limit, the row declares that only the first stretch was read. That score is a floor, not a ceiling.
- Traffic, search volume and conversion. None of it is used — it is not freely measurable, and pretending to measure it would be the easiest lie in this market.
Data attribution
Where every published figure comes from, and when it was consulted
Part of these figures come from third-party public APIs, and publishing them with attribution is the condition of their use — not a courtesy. Each source below states what it feeds, the date it was consulted, and how the data is reused.
- StygiaScore WSEP engine (our own measurement)search exposure · consulted 26 Sept 2026
our own engine, querying public sources only: RDAP registry records, DNS-over-HTTPS (Google and Cloudflare resolvers), Tranco, Common Crawl, the Wayback Machine, Sourcify and public RPC nodes. No paid provider and no API key involved.
- Post-quantum probe (our own tool)post-quantum verdict · consulted 28 Sept 2026
our own probe: it reads the key exchange the site actually negotiates in the TLS handshake and scans the JavaScript the site serves for post-quantum libraries. The network behind the host is attributed by ASN (RIPE Stat, BGPView), so a CDN’s work is never credited to the project.
- DefiLlamaTVL · consulted 24 Sept 2026
public API. Figures are published with attribution to DefiLlama; no raw dataset is redistributed, resold or republished.
- CoinGeckomarket capitalisation · consulted 24 Sept 2026
public API (free tier, rate-limited), read by coin id and never by ticker — two projects can share a symbol. Attribution shown as required; no raw dataset is redistributed.
- Public chain sourcesreadable source, ECDSA use, native balance · consulted 24 Sept 2026
read-only calls to public RPC endpoints (Polygon, Ethereum, BNB, Avalanche) and to Etherscan/Sourcify-compatible source verification. No private key, no account data and no paid indexer is involved.
- On-chain contract scan (our own scanner)contract post-quantum risk · consulted 7 Oct 2026
our own scanner over public read-only RPC: it reads the contract bytecode and the source the explorer has verified, flags ECDSA ecrecover in the validation path, and looks for post-quantum scheme names (ML-DSA, SLH-DSA, ML-KEM). No private key and no paid indexer involved. A risk level is only published when the source was actually read and the coverage was complete; otherwise the cell says not measured.
No provider’s raw dataset is redistributed, resold or republished: what is published is a derived measurement with its date. Where a provider requires attribution, it is printed here and on the ranking.
What this is not
No advice, no audit, no endorsement
Automated measurement of public data on a stated date · not financial advice · not a security audit · not an endorsement · nobody can buy a position
This is not financial, investment or trading advice, and it is not a price or value opinion about any asset. It is not a security audit either: it reads a subset of public signals on a stated date and cannot find every flaw in a project. Scores change as projects — and public sources — change.
StygiaScore is not affiliated with, sponsored by or endorsed by any project listed, and no project has reviewed, approved or paid for its row. Names and domains are used nominatively, to identify what is being measured, and are the property of their owners.
- A dated snapshot, not a verdict. Scores change when projects change and when public sources change. Each row carries the date it was last scanned, and the breakdown by source, so the freshness of every figure is visible instead of implied.
- Not a security audit. It reads a subset of public signals; a clean row does not mean a project is free of flaws, and a low score does not mean it is unsafe.
- No relationship with the projects. They are named to identify what is being measured (nominative use) and keep the ownership of their names and domains.
Corrections and right of reply
If a figure is wrong, it gets corrected in public
A project — or anyone — can dispute a row. What is needed: the row, the figure being disputed, and the evidence that contradicts it (a URL, a response from the source, a measurement of your own). Send it through the contact page.
- Corrections are dated, never silent. The measurement is re-run and the new snapshot replaces the old one with its own date. A change is datable, not invisible: every table carries the day it was read, so a before and an after can always be pointed at — and a public log of every change to a published figure is the next step on this page, together with anchoring each measurement on-chain.
- A row removed by our own decision is declared. If we withdraw something, its score and the reason stay published. An omission you can see costs the table nothing; a silent one would cost it everything.
- Nobody can pay for a different result. Not for a position, not for a module result, not for a row. The only thing that can be bought is a diagnosis of which module costs points and what would move it.
Reproduce it
The measurement is a runnable pipeline, not a private dashboard
The exposure column comes from the WSEP engine over the public sources listed above; the post-quantum column from our own probe reading the TLS handshake and the served JavaScript; the power column from DefiLlama, CoinGecko or the chain itself. Every table is generated from those runs — no figure on the ranking is typed by hand, including the scan dates.