Half of 4,688 small-business sites fail every security header check

Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria

Half of 4,688 small-business sites fail every security header check

A 2026 scan of 4,688 small-business websites found that 49.7% met none of seven security header criteria. HSTS was most common at 43.8%, but only 12.3% had strong HSTS. Just 0.17% passed a strict script-CSP rule, and 20.5% leaked software version tokens. The study used a random sample from the Curlie directory and emphasizes adoption, not overall security.

Among unique final domains returning HTTP 200, 49.7% met none of seven study-defined explicit-header criteria.
  1. stargrazer

    So.. you've written up what you checked, and what didn't match what ever criteria you had.

    But.. what does it mean? Why enforce certain headers? Why enforce certain options? There is a section which kinda looks at this, but not really.

    You have a bunch of links at the end for resources, but why not just provide the rationale for each rule or option inclusion in the article as well? What does each prevent or allow and why?

  2. aetherspawn

    It’s ridiculous that the answer to a secure web is for everyone to sprinkle the magic salt and not something on the browser side

  3. GaProgMan

    And if any of the websites use .NET, they can get almost all of the recommended security headers in one line by using a NuGet package I created: https://gaprogman.github.io/OwaspHeaders.Core/

More from this day

2026-09-24