Methodology

Everything here is computed from public data by an open pipeline. This page gives the formulas, the thresholds and - more usefully - the things the numbers cannot tell you.

1. What counts as a city

City boundaries come from the GHS Urban Centre Database, which delineates built-up areas by population density using one method worldwide.

Administrative boundaries would make the numbers meaningless across countries. "Tokyo" can mean 23 wards, a metropolis, or a conurbation of 37 million; "London" can mean a square mile or a region. Comparing a score computed over one definition with a score computed over another says more about local government history than about hazard. A single global delineation is what makes the comparison honest.

2. The grid

Each city is covered with H3 hexagons at resolution 8 (about 0.74 km² each). Every hexagon is given a population from WorldPop, converted from the raster's own cell size to the hexagon's area.

Hazard values are population-weighted, not averaged over land. A flood plain with nobody in it is not the same risk as the same flood plain under a dense ward, and an unweighted mean would call them equal.

Raster hazards are aggregated by true zonal statistics: the hexagons are rasterised onto the source grid and every pixel inside a hexagon counts. The flood layers are 90 m, so a hexagon holds roughly a hundred pixels and exposure is reported as the fraction of a cell that floods rather than a yes-or-no verdict on the whole cell.

One indicator - air quality - is published as a single figure per urban centre and has no intra-city detail. It is shown flat on the map, and the map says so. A flat layer is a limit of the source, not a finding that the hazard is evenly spread.

3. The indicators

Flood — m/year

Expected annual inundation depth from river and coastal flooding combined, population-weighted across the city. From JRC CEMS-GloFAS river maps at 90 m (seven return periods) and WRI Aqueduct coastal maps (six). Both models are undefended: they simulate water without levees, sea walls or pumping.

Scale: logarithmic, from 0.001 (score 0) to 0.2 (score 100). Weight 1.

Earthquake — index/year

Distance-decayed, magnitude-weighted rate of observed earthquakes around the city, from the USGS ANSS catalogue.

Scale: logarithmic, from 0.01 (score 0) to 100 (score 100). Weight 1.

Cyclone — events/year

Annual rate of tropical cyclone passages near the city, weighted by the sustained wind speed at closest approach. From NOAA IBTrACS, 1980 onwards.

Scale: logarithmic, from 0.01 (score 0) to 5 (score 100). Weight 1.

Wildfire — detections/1000km²/year

Annual satellite fire-detection density in the vegetated ring around the city, from NASA FIRMS VIIRS 375 m.

Scale: logarithmic, from 0.1 (score 0) to 300 (score 100). Weight 1.

Extreme heat — °C

Maximum temperature of the warmest month (BIO5, 1981-2010), averaged across the city. An absolute measure, comparable between climate zones. It does not account for humidity, so it understates the danger of humid tropical heat.

Scale: linear, from 20 (score 0) to 45 (score 100). Weight 1.

Air quality — µg/m³

Population-weighted annual mean PM2.5 concentration. A chronic hazard rather than an episodic one - it harms through years of exposure, not in a single event - but by mortality it is the largest hazard on this site.

Scale: logarithmic, from 5 (score 0) to 100 (score 100). Weight 1.

4. Turning a measurement into a score

Most hazard rates are heavy-tailed - the gap between a quiet city and a moderate one matters as much as the gap between moderate and extreme - so those indicators are mapped through a logarithmic scale between a fixed floor and ceiling:

score = 100 × (log₁₀v − log₁₀floor) / (log₁₀ceiling − log₁₀floor)

Indicators that are already a bounded percentage use a linear scale instead:

score = 100 × (v − floor) / (ceiling − floor)

Both are clipped to 0-100, and values at or below the floor score zero. Which type each indicator uses, and why, is listed in section 3 above.

The floor and ceiling are absolute, not relative to the cities on this site. The obvious alternative - normalising across whichever cities happen to be published - would mean a city's score changed every time another city was added, silently invalidating every screenshot, citation and permalink. It is also undefined when only one city exists. The scales here were chosen against a spread of reference cities worldwide and are versioned; when one changes, that is an announced change.

5. The overall score

An equal-weighted mean of the available indicator scores. Equal weights are a deliberate choice rather than a placeholder: any other weighting encodes a judgement about whether a coastal city's danger matters more than an inland one's, and there is no defensible basis for that judgement. The individual scores are always shown, so a reader who disagrees can weigh them differently.

An indicator that could not be measured is dropped from the mean, never counted as zero. "We have no data here" and "nothing happens here" are different statements, and conflating them would push every partially-covered city towards looking safe - the one direction an error must not go.

6. What these numbers are not

They ignore defences

Both flood models are undefended: they simulate water without levees, sea walls or pumping stations, because there is no global dataset of flood defences at usable quality. A city that has spent decades on flood engineering scores the same as one that has not. This matters most for exactly the cities that have invested most.

The earthquake score looks backwards

It measures shaking that has been observed since 1970, not probabilistic seismic hazard. A fault locked and silent for three centuries contributes almost nothing to it while being among the most dangerous places on earth - Istanbul is the textbook case. The correct input would be a probabilistic seismic hazard model; the global one, the GEM Global Seismic Hazard Map, is published under a NonCommercial licence that this site cannot use while it accepts donations. That constraint is described plainly rather than hidden.

Wildfire is a satellite proxy

It counts thermal detections that NASA classifies as vegetation fires in the ring of land around the city, not modelled fire risk. Volcanoes, gas flares and industrial heat are filtered out by type, but the measure is still fire activity, which is not the same as fire danger.

Heat ignores humidity, and ignores adaptation

The heat score is BIO5, the maximum temperature of the warmest month. It is absolute and comparable between climate zones, but it cannot tell 41 °C in dry Dubai from 31 °C in humid Jakarta, and the humid one is closer to the limit of what a human body can shed. The physiologically correct measure is wet-bulb temperature, which is not published globally at this resolution under a licence this site can use.

It also under-weights temperate cities. London's warmest month peaks around 21 °C and scores near zero here, yet the 2022 heatwave killed thousands of people there, because neither the buildings nor the population were adapted to it. Absolute heat and adaptation gap are different things and this score measures only the first. The warming trend shown beside the score is the other half of the picture.

An earlier version scored that trend instead - TX90p, the share of days above each city's own 1961-1990 90th percentile. It was dropped when calibration placed Dhaka and Kolkata at the bottom of eighteen cities, below Sydney and Moscow. Decades of aerosol pollution over South Asia have held down the rise in daytime maxima there, so a baseline-relative index reads two of the hottest cities on earth as barely warming. The trend is still worth seeing, so it is shown; it is not scored.

Air quality is a different kind of hazard

PM2.5 harms through years of exposure rather than in a single event, so it sits oddly beside earthquakes and cyclones. It is included because by attributable mortality it is the largest hazard measured here, and omitting it to keep the page tidily "natural" would have meant leaving out the risk most likely to shorten a reader's life.

Resolution is about a kilometre

Population is gridded at roughly 1 km, and most hazard layers at 1 km or finer. Nothing here is reliable about an individual street or building, and none of it is advice for any personal or commercial decision.

Some data is context, not score

Sunshine, greenness, hospital density and mean temperature appear in the city profile and are excluded from the score. They are useful context, but a sunnier city is not a safer one, and folding them in would quietly change what the number claims to measure.

Some hazards are missing entirely

There is no drought, landslide, tsunami, volcano or crime indicator yet. Their absence lowers no score - the overall figure is a mean of what is measured, not a claim that nothing else threatens the city. Crime in particular has no global, city-level, commercially usable open dataset; rather than substitute a national homicide rate for a city, it is left out.

7. Reproducing this

Every city page links the JSON it was rendered from. The pipeline downloads each source from its publisher, so the results can be regenerated from scratch by anyone.