hn.today

Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria

rackcrunch.com16 points14 comments
Screenshot of Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria

A 2026 study of 7,040 directory-listed U.S. local-business websites checked HTTPS response headers (two scans per URL, following up to three redirects) and evaluated sites against seven explicit header criteria: HSTS (including a “strong” HSTS threshold: ≥1 year + includeSubDomains), X-Content-Type-Options: nosniff, Content-Security-Policy (CSP) that restricts scripts, clickjacking protection, Referrer-Policy, Permissions-Policy, and Cross-Origin-Opener-Policy. Of 7,040 sampled rows, 4,688 unique final domains returned HTTP 200 on the second scan and form the principal base for all reported rates. The headline result: 49.7% (2,331 of 4,688) met none of the seven study-defined explicit-header criteria.

The study gives detailed adoption figures: HSTS appears on 43.8% of sites but only 12.3% meet the strong-HSTS definition; X-Content-Type-Options: nosniff on 39.7%; clickjacking protection on 31.2%; explicit secure Referrer-Policy on 8.0 (missing on 86.6%, though browsers default to strict-origin-when-cross-origin); explicit non-wildcard Permissions-Policy on 8.0%; recognized non-default COOP on 1.1%; version-token disclosure in server headers on 20.5%. CSPs are present on 21.2% but most do not restrict scripts: only 4.0% have script-restricting CSPs and just eight domains (0.17%) passed the study’s header-only script-CSP rule. After fixing an earlier scoring error, only one site met all rubric criteria. The analysis read response headers only and did not inspect page markup or test nonce freshness or runtime bypasses.

Read on rackcrunch.com14 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.