STOREPROOF METHODOLOGY · v2C.7 · SCANNER 2.7.0

How StoreProof measures storefront health.

StoreProof reports health, audit coverage, and result confidence separately. A scanner limitation is not proof that a storefront is broken. Only supported, scoreable findings reduce health, and high-impact score caps require strong storefront evidence.

01

Health score

Summarizes confirmed, scoreable findings, weighted by severity and evidence confidence. Commerce and mobile carry the most weight.

02

Audit coverage

Measures how much of StoreProof's supported public storefront journey was reached and exercised.

03

Result confidence

Measures the strength and representativeness of the browser, network, rendered-page, and cart-state evidence collected.

HEALTH SCORE

Commerce problems carry the most weight.

Category scores start at 100 and confirmed findings deduct points. The overall score is the weighted combination below.

Commerce30%
Mobile20%
Performance15%
Accessibility15%
Technical10%
Seo10%
CATEGORY SCORE MEANING

100 means no confirmed deductions—not full verification.

A category score describes confirmed health findings within the checks StoreProof could evaluate. Coverage and confidence qualify how complete that number is.

Example: Commerce can remain 100 while Add to Cart is inconclusive. In that case StoreProof shows the category as provisional and reports the commerce verification percentage separately. A 100 category score must not be interpreted as proof that every supported journey step passed.
FINDING DEDUCTIONS

Severity is adjusted by evidence confidence.

The base deduction reflects potential impact. Confidence reduces the deduction when the evidence is less direct. Inconclusive, skipped, not-tested and excluded checks receive no health-score deduction.

Base severity deductions
Critical-50
High-24
Medium-10
Low-4
Info-0
Confidence multiplier
High100%
Medium75%
Low40%
CHECK OUTCOMES

Failure to prove success is not proof of failure.

Every important browser check is classified before scoring.

Passed

The browser produced direct evidence that the check succeeded.

Failed

The browser produced supported evidence that the storefront check failed. Confirmed failures may affect the health score.

Inconclusive

StoreProof attempted the check but could not prove success or failure. Inconclusive checks do not reduce the health score; they reduce coverage and confidence instead.

Skipped

The check was deliberately not executed because it was unnecessary for this scan path. A skip is not an inconclusive attempt and never reduces health.

Not Tested

The scanner did not reach or could not safely attempt the check. This affects coverage and confidence, not health.

Excluded

The check is intentionally outside StoreProof's safety boundary and never affects the score.

SHOPIFY CONFIDENCE

One platform-confidence model is used everywhere.

Shopify signal strength controls report labels, coverage semantics, and whether Shopify-specific commerce results are issued.

70% and above

Shopify storefront detected and sufficiently verified for Shopify-focused commerce QA.

40%–69%

Shopify signals detected, but platform confidence and Shopify-focused observations remain provisional.

Below 40%

Shopify is not reliably detected, so StoreProof does not issue Shopify-specific commerce results.

OBSERVATION PROVENANCE

StoreProof never scores its own probes against a merchant.

Network and browser observations are classified as storefront, StoreProof probe, scanner environment, or unknown before technical findings are created.

Only storefront-provenance observations can create merchant Health deductions. Variant JSON requests, cart-state reads, Add to Cart action windows, targeted Verify Fix activity, scanner-environment messages, and unknown-origin observations remain separately labeled evidence or coverage context.
COVERAGE

Coverage measures what ran—not whether it passed.

Coverage is weighted by how important each supported stage is to the public Shopify buying journey. Inconclusive checks receive partial coverage rather than being counted as fully tested.

Homepage10%
Shopify10%
Collection5%
Product Discovery10%
Product Sample15%
Variant10%
Add To Cart15%
Cart State15%
Mobile Product5%
Mobile Cart5%
SCORE GUARDRAILS

Severe commerce caps require high-confidence evidence.

A score cap is only applied when a high-confidence finding confirms a serious buying-flow problem. An inconclusive Add to Cart attempt cannot trigger these caps.

Confirmed critical commercemax 49
Confirmed high commercemax 74
Confirmed critical mobilemax 64
PROVISIONAL RESULTS

Incomplete evidence stays visible.

A report is marked provisional when audit coverage is below 65%, result confidence is below 70%, or a core commerce verification remains inconclusive.

Result confidence includes unreached checks and gives commerce uncertainty more influence than low-impact discovery uncertainty. A provisional result is useful as a diagnostic snapshot, but it is not a complete statement about the storefront.
COMMERCE VERIFICATION

What counts as Add to Cart evidence?

StoreProof observes the user interaction, Shopify cart network activity and cart state. It does not submit checkout or payment.

Visible enabled purchase control→Browser click→Cart mutation response→Cart quantity / variant state
High-confidence pass

Cart state increases, or a recognized cart mutation succeeds with supporting storefront evidence.

Confirmed failure

Only status classes that strongly represent a storefront failure are scoreable. Missing cart endpoints can be high-confidence failures; server errors are scored more conservatively.

Inconclusive / automation limited

HTTP 401, 403, 429 and Shopify security rejection 430 are treated as scanner-access limitations, not customer purchase failures. Ambiguous 400, 409 and 422 cart responses also require manual verification before StoreProof blames the storefront.

AUTOMATION LIMITS

Blocking and throttling lower certainty, not store health.

StoreProof deliberately separates evidence about its automated session from evidence about normal shoppers.

HTTP 429

The automated browser was rate-limited. StoreProof stops additional commerce mutations and marks remaining journey checks not tested or inconclusive.

HTTP 401 / 403

The automated session encountered an access or challenge boundary. This lowers coverage and confidence but does not create a health-score deduction by itself.

HTTP 430

Shopify security controls rejected the automated session. StoreProof stops further storefront requests, lowers coverage and confidence, and does not create a merchant Health deduction.

Retry behavior

StoreProof avoids aggressive retry loops after an automation limit signal. This protects the storefront and reduces false failures caused by scanner-generated traffic.

RETEST INTEGRITY

Methodology changes start a new comparison baseline.

Every scan stores its scanner and methodology version.

If a previous scan used different scoring rules, StoreProof disables direct health, coverage, and finding-change comparisons. The newer scan becomes the baseline for future compatible full scans.
SAFETY BOUNDARY

Checkout, payment, and order submission are excluded.

StoreProof tests only the public storefront and may use an isolated cart. It does not require Shopify Admin access and never completes a transaction.