Skip to content

Scoring

KAEV scores summarize static-analysis findings; they are not SAP-certified scores or security guarantees.

Scores start at 100. Each finding applies a severity weight multiplied by confidence:

Severity Weight
Info 0
Low 1
Medium 4
High 12
Critical 30
Confidence Multiplier
Low 0.25
Medium 0.75
High 1

Modernization findings apply 25% of their normal weighted penalty, with their combined penalty capped at 10. The final result is rounded and clamped to 0–100. Duplicate and lower-priority findings at the same source location are removed before scoring.

  • Project Health uses all active evaluated findings.
  • Security Posture uses only active security findings and is null when security was not analyzed.
  • Unidentified projects receive null scores.
  • Category-only analysis, skipped/unavailable checks, and relevant discovery diagnostics mark coverage as partial.

A partial score of 100 means no weighted findings were found in the analyzed subset; it does not mean the whole application was proven healthy or secure.

--severity changes only displayed findings. It does not change scores or the process exit code.

Baselines and active suppressions remove matching findings before scoring and --fail-on evaluation. Suppressed counts remain visible in rule status. --fail-on none disables the finding threshold but does not turn analysis failures into success.