ForgeScore
19 min read8-dimension codebase health scoring, NIST CSF security grade (A–F), branded PDF report, composite score, and the full score dashboard.
ForgeScore
ForgeScore is Forge’s 8-dimension engineering health scorecard. It reads your codebase like a lead architect would and returns:
- A composite score (0–100) with a maturity label
- Eight weighted dimensions, each with its own score, summary, and findings
- A NIST CSF 2.0 security grade (A–F) with coverage across six cybersecurity functions
- A branded multi-page PDF report for stakeholders (cover, executive summary, NIST posture, scorecard, tech stack, findings)
- Prioritized findings (severity, velocity impact, compliance references — OWASP, CWE, NIST CSF, GDPR, and related mappings)
- Optional synthesis — Gold Standard exemplar, Quick Wins, evolution projection, Surprising Fact
Use ForgeScore to baseline risk before modernization, track improvement between runs, and ground Assessment recommendations in evidence.
Where ForgeScore appears
ForgeScore surfaces in two places on a journey project:
1. Journey (in-context)
| Surface | Location | What you see |
|---|---|---|
| Assessment strip | Top of Modernization → Assessment | Live states: waiting for indexing, calculating, results summary (including NIST CSF grade when present), PDF download, or skipped (no repo context) |
| ForgeScore sidebar tab | Journey sidebar button ForgeScore | Compact report: composite, dimension pills, top findings, Full Dashboard → link |
| ForgeScore panel | Same tab content area | Full in-journey view; empty state links to the score dashboard |
On modernization projects, Forge runs scoring server-side during Assessment after repository context is indexed — you do not need to open the dashboard first. The strip shows Calculating ForgeScore while the job runs, then collapses into a score summary with Full Dashboard.
2. Score dashboard (full experience)
Open Full Dashboard or Go to Score Dashboard from the journey.
The dashboard supports versioned re-runs, tabbed drill-down, synthesis, NIST CSF security rating, and side-by-side comparison — the journey views are summaries of the latest result.
Running 8-dimension analysis
When no score exists (or you click Run New Version), the Run 8-Dimension Analysis source picker opens.
Source modes
| Mode | How it works |
|---|---|
| Folder | Pick a local project folder in the browser. Files are aggregated client-side; sensitive paths and build dirs are skipped. Nothing uploads until you click Run Analysis. |
| ZIP Archive | Upload a .zip of the repo — max 10 MB. |
| Git URL | One or more public GitHub, GitLab, or Bitbucket URLs. + Add another URL scores multiple repos in one run. Optional branch applies to all URLs. Private repos work when a matching connector is configured on the project. |
Expand Scale Context (optional) to add monthly active users (MAU) and cloud provider hints — surfaced on the composite card for capacity-aware framing.
While a job runs
The Analyzing screen shows the repo name (or multi-repo count), explains that each run creates a new comparable version, and streams live progress via the progress ticker until completion or error.
Re-running without re-picking sources
| Action | When to use |
|---|---|
| Quick Re-score | Re-analyze the same source — matched Git connector + repo, stored Git URL, or previously ingested folder context. Skips the picker when Forge already knows the input. |
| Run New Version | Start fresh — opens the source picker so you can change folder, ZIP, URLs, or branch. |
Each successful run appends a version to score history.
Dashboard layout
Header
- ← Back — Return to the project journey
- ForgeScore Dashboard — Repo name, or N repositories for multi-URL runs
- ? — How ForgeScore Works modal (overview, steps, composite formula, dimension weights, NIST CSF grade table, maturity scale — loaded from scoring metadata when available)
- Scored at timestamp; vN of N versions when history exists
- ▲/▼ vs previous — Point delta vs the prior run
- Run New Version · Quick Re-score · Compare Versions (header button appears when ≥ 2 versions exist)
Trend banner
When a previous version exists, a banner shows points gained or lost and the maturity transition (e.g. Developing (58) → Maturing (64)).
Summary strip
- Score ring — Composite score + maturity
- MAU context — Shown when provided at run time (e.g. 50k MAU on AWS)
- Findings count — Total findings; critical badge; high velocity badge when applicable
- Gold Standard shortcut — Clickable card jumps to the Roadmap tab when synthesis exists; otherwise a Strengths count
- Analysis coverage — Based on analysis of X of Y files (Z% sample) when the run returns coverage stats
Score bands (UI coloring)
| Range | Typical UI treatment |
|---|---|
| ≥ 70 | Strong — green / success styling; radar 70 target line |
| 40–69 | Moderate — amber / warning styling |
| < 40 | Weak — muted or red styling |
Dimension pills and radar charts use the same bands. The ? help modal documents the official maturity scale for your deployment.
Tabs
Overview (default)
- NIST CSF Security Rating — Letter grade (A–F) with NIST maturity tier, short posture summary, and six-function coverage indicators (see )
- Your Strongest Areas — Top three dimensions by score (icon + label + number)
- What You're Doing Well — Strength cards when the model returned positives
- Per-Repository Scores — When multiple repos were analyzed: composite, maturity, and progress per repo
- Score Radar — All eight dimensions; blue dashed 70 = target threshold
- Improvement Opportunities — Up to six top finding cards (severity, description, linked context, exposure risk and compliance tags when present)
Dimensions
- Dimension pills — All eight dimensions as selectable chips (icon, label, score)
- Security & Compliance toggle — Filters to critical/high findings and items with compliance references (OWASP, CWE, NIST CSF, GDPR, SOC2-style mappings) across every dimension
- Selected dimension — Summary, score, maturity, progress bar, per-repo breakdown (multi-repo), strengths, and all findings for that dimension
Roadmap (synthesis tab — conditional)
The tab label is Roadmap but this is score-improvement output, not the sidebar planning page. The tab appears only when the run produced Gold Standard, Quick Wins, or Surprising Fact content:
| Block | Content |
|---|---|
| Gold Standard | Exemplar file — title, path, description |
| Quick Wins | Ranked fixes with estimated score lift, effort label, and target dimension chips |
| Evolution Comparison | Current vs projected composite after strikes; per-dimension current / projected / gain table |
| Surprising Fact | Optional insight with related dimension tags |
If synthesis did not run, the tab is hidden (or shows an unavailable message on older runs).
Not the product Roadmap — Delivery planning lives at sidebar Roadmap. Full guide: . Enable via .
Compare Versions
The Compare Versions (N) tab appears once any version exists; meaningful side-by-side comparison needs ≥ 2 runs.
- Pick left and right versions (date, repo, maturity, composite in labels)
- Composite & findings deltas
- Dimension comparison table — score, maturity, and delta per dimension
- Severity breakdown — critical / high / medium / low counts for each side
NIST CSF security grade
ForgeScore maps the codebase’s security posture to the NIST Cybersecurity Framework (CSF) 2.0. The letter grade is produced during score synthesis and is complementary to the 0–100 composite — use it as a security maturity snapshot, not a replacement for the eight dimension scores.
Where it appears
| Surface | What you see |
|---|---|
| Assessment ForgeScore strip | NIST grade badge on the security snapshot |
| Dashboard → Overview | NIST CSF Security Rating card with tier label, summary, and function coverage |
| ? help modal | Full grade table under Security & Compliance |
| PDF export | Full branded multi-page report — see |
Grades (A–F)
Grades may include a + (for example B+). Tiers follow NIST CSF maturity language:
| Grade | NIST CSF tier | Meaning |
|---|---|---|
| A | Adaptive | Security is integrated into risk management and continuously adapts to evolving threats |
| B | Repeatable | Risk-informed policies are formalized and regularly practiced |
| C | Risk-Informed | Security practices exist but are not consistently applied; some CSF categories are only partially covered |
| D | Partial | Minimal security measures; most CSF functions have significant gaps |
| F | None | No meaningful security practices detected in the codebase |
Six CSF 2.0 functions
Coverage indicators on Overview track how findings map to:
| Code | Function |
|---|---|
| GV | Govern |
| ID | Identify |
| PR | Protect |
| DE | Detect |
| RS | Respond |
| RC | Recover |
Findings can carry NIST-CSF-* compliance references (for example NIST-CSF-PR.AA, NIST-CSF-PR.DS, NIST-CSF-DE.CM). The UI derives per-function coverage from those tags. On older scores that lack NIST tags on findings, Forge may fall back to patterns in the security posture summary so functions are not all shown as “Not assessed.”
How to use the grade
- After Assessment or a dashboard run, open Overview and note the NIST CSF grade next to the composite score.
- Use Dimensions → Security & Compliance to focus on critical/high findings and NIST/OWASP/CWE-tagged items.
- Prioritize remediations that close weak functions (for example Protect or Detect gaps).
- Quick Re-score or Run New Version after fixes; compare versions to show composite and security posture movement.
- Export the when you need a branded stakeholder or audit-ready package (includes NIST posture, scorecard, tech stack, and findings).
The NIST grade is an input to human decisions — not a certification or substitute for formal NIST assessments, penetration tests, or compliance sign-off.
ForgeScore PDF report
ForgeScore can export a properly branded multi-page PDF with full Forge / SoftwareForge brand identity — suitable for executives, security reviews, and modernization kickoffs.
How to download
- Complete a ForgeScore run (Assessment auto-score or dashboard analysis).
- On the modernization Assessment ForgeScore strip, select PDF (download icon).
- The browser saves a multi-page report named from the project / repo.
PDF download requires a signed-in session when authentication is enabled for your deployment.
What the report includes
| Section | Contents |
|---|---|
| Cover page | Dark-branded cover with project name and score callout |
| Executive summary | Opening statement, strength-led summary paragraph, and bottom line using the actual composite score |
| NIST CSF security posture | Letter grade, tier label, and OWASP categories covered |
| Security scorecard | Secrets detected, CVEs, EOL packages, circular dependencies |
| Tech stack inventory | Each detected technology with version signal and status (modern, acceptable, or outdated) |
| Findings pages | Severity-coded findings; critical items include IF EXPOSED consequence text |
| Every page | Page numbers and a Confidential label in the footer |
The PDF also carries the NIST CSF narrative and related security posture detail aligned with the dashboard Overview experience.
Branding and reliability
- Reports use Forge design-system styling (dark brand cover, consistent typography, score boxes, and structured cards) rather than a plain dump of dashboard HTML.
- Document metadata (title, author, creator, subject) is set on export so antivirus products are less likely to treat the file as suspicious.
Antivirus false-positive fix
Earlier releases could produce PDFs that Norton (and similar AV heuristics) flagged as malware (for example PDF:MalwareX-gen) because empty PDF metadata is a common phishing signal. Generated ForgeScore PDFs now set proper SoftwareForge document properties, which resolves that false-positive class in this release.
The eight dimensions
| Dimension | Focus |
|---|---|
| Trust Boundaries | Security boundaries between components and data flows |
| Logic Narrative | How clearly control flow and responsibilities read |
| Code Excellence | Quality pockets vs. risk pockets in the code |
| Data Weight | How data is modeled, moved, and owned |
| Cognitive Load | How hard the system is to reason about |
| System Gravity | Coupling, dependencies, and architectural pull |
| Semantic Clarity | Naming, structure, and intent in code |
| Future-Proofing | Extensibility and tech-debt trajectory |
Each dimension is weighted into the composite. Open ? → Dimensions & Weights on the dashboard for exact percentages in your deployment.
Findings
Findings carry:
- Severity — critical, high, medium, low (color-coded cards)
- Velocity impact — high velocity findings are flagged in the summary strip when present
- Exposure risk — Optional narrative of what an attacker or failure could exploit
- Compliance references — Surfaces under the Security & Compliance filter when mapped (e.g. OWASP, CWE,
NIST-CSF-*, GDPR)
How ForgeScore feeds the pipeline
| Stage | Integration |
|---|---|
| Assessment (modernization) | ForgeScore runs before assessment generation when repo context exists. Low dimensions, NIST posture, and quick wins inform modernization line items and recommendations. |
| Pre-flight clarifications | Agent may reference ForgeScore dimension scores and findings when asking intent questions. |
| Re-runs | Use Quick Re-score or Run New Version after remediation; Compare Versions to prove improvement. |
ForgeScore is an input to human decisions — not a substitute for architecture review or security sign-off.
Recommended workflow
- Enable ForgeScore for the tenant (usually already on) and ingest or link repository context on a modernization project.
- Run Assessment — ForgeScore calculates automatically when indexing completes; review the ForgeScore strip (composite + NIST CSF grade when present).
- Open Full Dashboard → Overview for radar, NIST CSF Security Rating, dimension drill-down, synthesis, and finding detail.
- Act on Quick Wins and critical / NIST-tagged findings; re-score to measure delta.
- Compare Versions after major remediations to communicate score and security-posture progress to stakeholders.
- Download the PDF from the Assessment ForgeScore strip when you need a branded multi-page handoff (cover, executive summary, NIST, scorecard, stack, findings).
For ad-hoc analysis (no journey ingest), open the ForgeScore Dashboard directly and use Folder, ZIP, or Git URL from the source picker.