{"service":"ZeroWorker Security API","methodologyId":"zeroworker-security-score-v1","deterministic":true,"purpose":"Prioritize caller-supplied CVE IDs using public exploitation signals. This score is triage assistance, not a prediction of exploitability for a specific asset.","scoreComposition":{"rawFormula":"55 * epssProbability + 20 * epssPercentile + 20 * inKev + 5 * ransomwareKnown","booleanEncoding":"inKev and ransomwareKnown contribute 1 when true and 0 when false.","terms":[{"key":"epssProbability","source":"FIRST EPSS","inputRange":"0..1","maxPoints":55,"description":"Current EPSS exploitation probability contributes up to 55 points."},{"key":"epssPercentile","source":"FIRST EPSS","inputRange":"0..1","maxPoints":20,"description":"Current EPSS percentile contributes up to 20 points."},{"key":"inKev","source":"CISA Known Exploited Vulnerabilities (KEV)","inputRange":"boolean","maxPoints":20,"description":"CISA KEV membership contributes 20 points and also forces the urgent tier."},{"key":"ransomwareKnown","source":"CISA KEV known-ransomware context","inputRange":"boolean","maxPoints":5,"description":"Known ransomware campaign use contributes 5 points when present in the KEV record."}],"maximumWeightedPoints":100,"returnedScore":"The live risk implementation returns the public integer score. The formula above documents the weighted inputs; consumers should use the returned score rather than reproduce undocumented implementation details such as conversion/rounding behavior."},"tierBehavior":{"kevOverride":{"condition":"inKev == true","tier":"urgent","description":"CISA KEV membership always yields the urgent tier in the current methodology."},"otherTiers":"For non-KEV results, use the tier and reasons returned by the current versioned implementation. This public methodology does not invent or restate tier-threshold constants that are not already part of the published API contract."},"dataAvailability":{"usableSignalDefinition":"A CVE is dataAvailable when the current pipeline has usable FIRST EPSS or CISA KEV signal data for it.","noSignalBehavior":"If every requested CVE lacks usable signal data, the public paid resource returns HTTP 422 and does not successfully settle.","mixedBatchBehavior":"If at least one CVE has usable signal data, the successful batch may include other results with dataAvailable=false."},"ordering":"Results with dataAvailable=true are returned before unavailable results; available results are ordered by descending score, then CVE identifier.","sources":{"firstEpss":"https://api.first.org/data/v1/epss","cisaKevMirror":"https://github.com/cisagov/kev-data"},"evidence":{"freeLiveSample":"https://zeroworker-security-api.zeroworker-lab.workers.dev/v1/sample","openapi":"https://zeroworker-security-api.zeroworker-lab.workers.dev/openapi.json","paymentPolicy":"https://zeroworker-security-api.zeroworker-lab.workers.dev/payment-policy"},"boundaries":["EPSS, KEV membership, and ransomware-use context can change over time.","The score does not include asset criticality, exposure, compensating controls, business impact, or environment-specific exploitability.","A high score is a prioritization signal, not proof that exploitation will occur on a specific asset.","A low score or missing signal is not proof of safety or absence of vulnerability.","Consumers should combine this output with asset context and their vulnerability-management policy."]}