Severity is a ceiling, not a forecast
A severity rating describes the worst outcome if the weakness is exploited in the most favourable conditions for an attacker. It says nothing about whether those conditions exist where you work.
So a critical finding in a code path you will never call is less relevant to you than a medium one in the feature you bought the software for. Reading the severity alone reliably produces both of the available mistakes: refusing something safe and installing something that is not.
Reachability is the field that decides it
Reachability answers whether the weakness sits in code your usage will actually execute, with inputs you will actually supply. A finding in an optional integration you are not enabling is not reachable.
This is why we publish the affected component rather than only the rating. Read the component first, decide whether you will touch it, and only then look at how bad it would be.
Then ask who supplies the input
A weakness that requires input from an untrusted source is a real risk if your agent reads email, web pages or customer documents, and close to theoretical if it only ever processes files your own team wrote.
For agents this is the question that moves fastest. A tool added six months after purchase can turn an unreachable finding into a reachable one without anything in the software changing.
Check the date against the version
A finding is about a version. If the maker has shipped twice since, the finding may be fixed or may have been joined by others, and the only honest position is that the badge no longer describes what you would install.
An old test date beside a recent update is the single combination that should stop you, regardless of what the findings say.
A listing with findings is usually a better sign than one without
Nothing here passes sixteen checks cleanly very often, and a long clean sheet more commonly means a thin piece of software with little surface than a carefully built one.
What matters is the maker's response: whether findings are acknowledged, whether they are fixed, and how long it took. That history is on the listing, and it predicts the next twelve months better than the current rating does.
Write down what you decided and why
One line, on the day: which findings you read, why you accepted them, and what would change your mind. It takes a minute.
In six months, when somebody asks why this is installed, that line is the difference between a decision and an accident. It is also the most useful thing you can hand to whoever replaces you.