PLATFORM FEATURESForgeScore

ForgeScore

19 min read

8-dimension codebase health scoring, NIST CSF security grade (A–F), branded PDF report, composite score, and the full score dashboard.

ForgeScore

ForgeScore is Forge’s 8-dimension engineering health scorecard. It reads your codebase like a lead architect would and returns:

  • A composite score (0–100) with a maturity label
  • Eight weighted dimensions, each with its own score, summary, and findings
  • A NIST CSF 2.0 security grade (A–F) with coverage across six cybersecurity functions
  • A branded multi-page PDF report for stakeholders (cover, executive summary, NIST posture, scorecard, tech stack, findings)
  • Prioritized findings (severity, velocity impact, compliance references — OWASP, CWE, NIST CSF, GDPR, and related mappings)
  • Optional synthesis — Gold Standard exemplar, Quick Wins, evolution projection, Surprising Fact

Use ForgeScore to baseline risk before modernization, track improvement between runs, and ground Assessment recommendations in evidence.


Where ForgeScore appears

ForgeScore surfaces in two places on a journey project:

1. Journey (in-context)

SurfaceLocationWhat you see
Assessment stripTop of Modernization → AssessmentLive states: waiting for indexing, calculating, results summary (including NIST CSF grade when present), PDF download, or skipped (no repo context)
ForgeScore sidebar tabJourney sidebar button ForgeScoreCompact report: composite, dimension pills, top findings, Full Dashboard → link
ForgeScore panelSame tab content areaFull in-journey view; empty state links to the score dashboard

On modernization projects, Forge runs scoring server-side during Assessment after repository context is indexed — you do not need to open the dashboard first. The strip shows Calculating ForgeScore while the job runs, then collapses into a score summary with Full Dashboard.

2. Score dashboard (full experience)

Open Full Dashboard or Go to Score Dashboard from the journey.

The dashboard supports versioned re-runs, tabbed drill-down, synthesis, NIST CSF security rating, and side-by-side comparison — the journey views are summaries of the latest result.


Running 8-dimension analysis

When no score exists (or you click Run New Version), the Run 8-Dimension Analysis source picker opens.

Source modes

ModeHow it works
FolderPick a local project folder in the browser. Files are aggregated client-side; sensitive paths and build dirs are skipped. Nothing uploads until you click Run Analysis.
ZIP ArchiveUpload a .zip of the repo — max 10 MB.
Git URLOne or more public GitHub, GitLab, or Bitbucket URLs. + Add another URL scores multiple repos in one run. Optional branch applies to all URLs. Private repos work when a matching connector is configured on the project.

Expand Scale Context (optional) to add monthly active users (MAU) and cloud provider hints — surfaced on the composite card for capacity-aware framing.

While a job runs

The Analyzing screen shows the repo name (or multi-repo count), explains that each run creates a new comparable version, and streams live progress via the progress ticker until completion or error.

Re-running without re-picking sources

ActionWhen to use
Quick Re-scoreRe-analyze the same source — matched Git connector + repo, stored Git URL, or previously ingested folder context. Skips the picker when Forge already knows the input.
Run New VersionStart fresh — opens the source picker so you can change folder, ZIP, URLs, or branch.

Each successful run appends a version to score history.


Dashboard layout

  • ← Back — Return to the project journey
  • ForgeScore Dashboard — Repo name, or N repositories for multi-URL runs
  • ?How ForgeScore Works modal (overview, steps, composite formula, dimension weights, NIST CSF grade table, maturity scale — loaded from scoring metadata when available)
  • Scored at timestamp; vN of N versions when history exists
  • ▲/▼ vs previous — Point delta vs the prior run
  • Run New Version · Quick Re-score · Compare Versions (header button appears when ≥ 2 versions exist)

Trend banner

When a previous version exists, a banner shows points gained or lost and the maturity transition (e.g. Developing (58) → Maturing (64)).

Summary strip

  • Score ring — Composite score + maturity
  • MAU context — Shown when provided at run time (e.g. 50k MAU on AWS)
  • Findings count — Total findings; critical badge; high velocity badge when applicable
  • Gold Standard shortcut — Clickable card jumps to the Roadmap tab when synthesis exists; otherwise a Strengths count
  • Analysis coverageBased on analysis of X of Y files (Z% sample) when the run returns coverage stats

Score bands (UI coloring)

RangeTypical UI treatment
≥ 70Strong — green / success styling; radar 70 target line
40–69Moderate — amber / warning styling
< 40Weak — muted or red styling

Dimension pills and radar charts use the same bands. The ? help modal documents the official maturity scale for your deployment.


Tabs

Overview (default)

  • NIST CSF Security Rating — Letter grade (A–F) with NIST maturity tier, short posture summary, and six-function coverage indicators (see )
  • Your Strongest Areas — Top three dimensions by score (icon + label + number)
  • What You're Doing Well — Strength cards when the model returned positives
  • Per-Repository Scores — When multiple repos were analyzed: composite, maturity, and progress per repo
  • Score Radar — All eight dimensions; blue dashed 70 = target threshold
  • Improvement Opportunities — Up to six top finding cards (severity, description, linked context, exposure risk and compliance tags when present)

Dimensions

  • Dimension pills — All eight dimensions as selectable chips (icon, label, score)
  • Security & Compliance toggle — Filters to critical/high findings and items with compliance references (OWASP, CWE, NIST CSF, GDPR, SOC2-style mappings) across every dimension
  • Selected dimension — Summary, score, maturity, progress bar, per-repo breakdown (multi-repo), strengths, and all findings for that dimension

Roadmap (synthesis tab — conditional)

The tab label is Roadmap but this is score-improvement output, not the sidebar planning page. The tab appears only when the run produced Gold Standard, Quick Wins, or Surprising Fact content:

BlockContent
Gold StandardExemplar file — title, path, description
Quick WinsRanked fixes with estimated score lift, effort label, and target dimension chips
Evolution ComparisonCurrent vs projected composite after strikes; per-dimension current / projected / gain table
Surprising FactOptional insight with related dimension tags

If synthesis did not run, the tab is hidden (or shows an unavailable message on older runs).

Not the product Roadmap — Delivery planning lives at sidebar Roadmap. Full guide: . Enable via .

Compare Versions

The Compare Versions (N) tab appears once any version exists; meaningful side-by-side comparison needs ≥ 2 runs.

  • Pick left and right versions (date, repo, maturity, composite in labels)
  • Composite & findings deltas
  • Dimension comparison table — score, maturity, and delta per dimension
  • Severity breakdown — critical / high / medium / low counts for each side

NIST CSF security grade

ForgeScore maps the codebase’s security posture to the NIST Cybersecurity Framework (CSF) 2.0. The letter grade is produced during score synthesis and is complementary to the 0–100 composite — use it as a security maturity snapshot, not a replacement for the eight dimension scores.

Where it appears

SurfaceWhat you see
Assessment ForgeScore stripNIST grade badge on the security snapshot
Dashboard → OverviewNIST CSF Security Rating card with tier label, summary, and function coverage
? help modalFull grade table under Security & Compliance
PDF exportFull branded multi-page report — see

Grades (A–F)

Grades may include a + (for example B+). Tiers follow NIST CSF maturity language:

GradeNIST CSF tierMeaning
AAdaptiveSecurity is integrated into risk management and continuously adapts to evolving threats
BRepeatableRisk-informed policies are formalized and regularly practiced
CRisk-InformedSecurity practices exist but are not consistently applied; some CSF categories are only partially covered
DPartialMinimal security measures; most CSF functions have significant gaps
FNoneNo meaningful security practices detected in the codebase

Six CSF 2.0 functions

Coverage indicators on Overview track how findings map to:

CodeFunction
GVGovern
IDIdentify
PRProtect
DEDetect
RSRespond
RCRecover

Findings can carry NIST-CSF-* compliance references (for example NIST-CSF-PR.AA, NIST-CSF-PR.DS, NIST-CSF-DE.CM). The UI derives per-function coverage from those tags. On older scores that lack NIST tags on findings, Forge may fall back to patterns in the security posture summary so functions are not all shown as “Not assessed.”

How to use the grade

  1. After Assessment or a dashboard run, open Overview and note the NIST CSF grade next to the composite score.
  2. Use Dimensions → Security & Compliance to focus on critical/high findings and NIST/OWASP/CWE-tagged items.
  3. Prioritize remediations that close weak functions (for example Protect or Detect gaps).
  4. Quick Re-score or Run New Version after fixes; compare versions to show composite and security posture movement.
  5. Export the when you need a branded stakeholder or audit-ready package (includes NIST posture, scorecard, tech stack, and findings).

The NIST grade is an input to human decisions — not a certification or substitute for formal NIST assessments, penetration tests, or compliance sign-off.


ForgeScore PDF report

ForgeScore can export a properly branded multi-page PDF with full Forge / SoftwareForge brand identity — suitable for executives, security reviews, and modernization kickoffs.

How to download

  1. Complete a ForgeScore run (Assessment auto-score or dashboard analysis).
  2. On the modernization Assessment ForgeScore strip, select PDF (download icon).
  3. The browser saves a multi-page report named from the project / repo.

PDF download requires a signed-in session when authentication is enabled for your deployment.

What the report includes

SectionContents
Cover pageDark-branded cover with project name and score callout
Executive summaryOpening statement, strength-led summary paragraph, and bottom line using the actual composite score
NIST CSF security postureLetter grade, tier label, and OWASP categories covered
Security scorecardSecrets detected, CVEs, EOL packages, circular dependencies
Tech stack inventoryEach detected technology with version signal and status (modern, acceptable, or outdated)
Findings pagesSeverity-coded findings; critical items include IF EXPOSED consequence text
Every pagePage numbers and a Confidential label in the footer

The PDF also carries the NIST CSF narrative and related security posture detail aligned with the dashboard Overview experience.

Branding and reliability

  • Reports use Forge design-system styling (dark brand cover, consistent typography, score boxes, and structured cards) rather than a plain dump of dashboard HTML.
  • Document metadata (title, author, creator, subject) is set on export so antivirus products are less likely to treat the file as suspicious.

Antivirus false-positive fix

Earlier releases could produce PDFs that Norton (and similar AV heuristics) flagged as malware (for example PDF:MalwareX-gen) because empty PDF metadata is a common phishing signal. Generated ForgeScore PDFs now set proper SoftwareForge document properties, which resolves that false-positive class in this release.


The eight dimensions

DimensionFocus
Trust BoundariesSecurity boundaries between components and data flows
Logic NarrativeHow clearly control flow and responsibilities read
Code ExcellenceQuality pockets vs. risk pockets in the code
Data WeightHow data is modeled, moved, and owned
Cognitive LoadHow hard the system is to reason about
System GravityCoupling, dependencies, and architectural pull
Semantic ClarityNaming, structure, and intent in code
Future-ProofingExtensibility and tech-debt trajectory

Each dimension is weighted into the composite. Open ? → Dimensions & Weights on the dashboard for exact percentages in your deployment.

Findings

Findings carry:

  • Severity — critical, high, medium, low (color-coded cards)
  • Velocity impacthigh velocity findings are flagged in the summary strip when present
  • Exposure risk — Optional narrative of what an attacker or failure could exploit
  • Compliance references — Surfaces under the Security & Compliance filter when mapped (e.g. OWASP, CWE, NIST-CSF-*, GDPR)

How ForgeScore feeds the pipeline

StageIntegration
Assessment (modernization)ForgeScore runs before assessment generation when repo context exists. Low dimensions, NIST posture, and quick wins inform modernization line items and recommendations.
Pre-flight clarificationsAgent may reference ForgeScore dimension scores and findings when asking intent questions.
Re-runsUse Quick Re-score or Run New Version after remediation; Compare Versions to prove improvement.

ForgeScore is an input to human decisions — not a substitute for architecture review or security sign-off.


  1. Enable ForgeScore for the tenant (usually already on) and ingest or link repository context on a modernization project.
  2. Run Assessment — ForgeScore calculates automatically when indexing completes; review the ForgeScore strip (composite + NIST CSF grade when present).
  3. Open Full Dashboard → Overview for radar, NIST CSF Security Rating, dimension drill-down, synthesis, and finding detail.
  4. Act on Quick Wins and critical / NIST-tagged findings; re-score to measure delta.
  5. Compare Versions after major remediations to communicate score and security-posture progress to stakeholders.
  6. Download the PDF from the Assessment ForgeScore strip when you need a branded multi-page handoff (cover, executive summary, NIST, scorecard, stack, findings).

For ad-hoc analysis (no journey ingest), open the ForgeScore Dashboard directly and use Folder, ZIP, or Git URL from the source picker.