How is a wallet's 0–100 risk score calculated, and can you rely on it?
The score compresses several signals into one number, so its reliability depends on the signals behind it. They come in two kinds: deterministic (a hit on a sanctions or scam list, an issuer freeze) — facts you can verify; and inferential (a very new address, few transactions, past contact with a suspicious address) — probability judgments that will produce both false alarms and misses. So don't read the number alone: a trustworthy screening tool tells you which signals made up the score and where each came from. Every OceanAlt verdict carries itemised evidence with sources, and a list hit names the exact list and its listing date.
The same score can mean two different things
Two addresses both score 60: one because it sits on a community scam list, the other because it was created three days ago with a single inbound transfer. The first is documented; the second is merely unclear. If the tool won't show where the score came from, you cannot tell these apart — and cannot decide between declining and sending a small test payment.
Using a score correctly
Treat a score as a prompt to look closer, not a conclusion. A sanctions-list hit means don't pay, whatever the score. A high score built only from inferential signals calls for reading the evidence before deciding. A brand-new address has no history, so no score is reliable — OceanAlt returns "insufficient data" there and points you to endpoint screening, a small test payment, or asking the counterparty to prove ownership.
In code, a three-state decision (allow / review / decline) is steadier than picking your own score threshold: the cut-off is set from the evidence on our side and returned with a reason code, so different callers don't each draw a different line.
Where to start: free address check · API docs · watch an address
Boundary of everything above: a screening "clear" only means no match in the data held, never a safety guarantee; this page is not legal or compliance advice.

