How real websites are actually configured
Most security statistics are vendor estimates or survey answers. These are measurements: we run the same passive checks as the free tools on this site across hundreds of live sites and publish what came back, with the sample size next to every number.
Free to cite, with attribution. If you need a cut of the data we haven't published, ask — we'll tell you whether the underlying data supports it.
The current headline numbers
From the most recent edition — 1,106 online stores on their own domains, bucketed by the platform they run on, measured in September 2026. Denominators differ because not every check returns a usable result for every host.
- 98.5%
- send HSTS — the platform sets it at its edge, for everyone
- 336 of 341 Shopify stores
- 25.8%
- enforce DMARC, so three quarters can be impersonated by email
- 88 of the same 341
- 68.5%
- of stores that look well-configured to a browser still can't stop a spoofed email
- 311 of 454
- 31.3%
- of all stores enforce DMARC; 46.2% publish p=none, which blocks nothing
- 346 of 1,106
- 7.3%
- expose a sensitive file or panel — a .git, an .env, a backup
- 68 of 926
Editions
The platform fixes what the browser sees, not what your customer gets emailed
1,106 online stores · bucketed by platform
Shopify's 341 stores send HSTS and CSP 98.5% of the time and only 25.8% of them enforce DMARC — the same merchants, scoring 98% on the half a browser sees and 26% on the half that reaches an inbox.
Read the study →The state of web security at the companies that build websites
376 web agencies · Bulgaria and Italy
The firms that build other people's websites, measured on their own. 81% run no CSP, 63% no HSTS, and only 27% enforce DMARC — with WordPress agencies materially worse than the rest. Carries a published correction: 18 of the 376 domains turned out not to be agencies, moving the figures by under a point.
Read the study →Method
Passive only. One HTTP GET of the homepage plus public DNS lookups, per domain. No authentication, no crawling beyond that page, no port scanning, no payloads, no active testing. Everything measured is what the site sends to any browser that visits it — see how we scan.
The same engine as the free tools. No separate research pipeline that could drift from the product: a study run is the website security score check set, run in batch. If a number here looks wrong, you can reproduce it on any one of the domains yourself.
Nothing is published about an individual site. Only aggregates, with denominators. The point is the population, not naming a company — and a list of individually weak sites would be a target list, not research.
The sample is not random, and that matters. Domains come from public search results for the sector and country, deduplicated per registrable domain. Search visibility correlates with company size and technical investment, so the sample skews toward better-resourced firms. The honest reading is that the wider population is probably no better than these figures, and may be worse.
Denominators vary by check, on purpose. A host that didn't answer in time for the TLS probe is excluded from TLS figures rather than counted as a pass. That's why the numbers above say “of 353” and “of 374” rather than all citing the full 376.
Want the same measurements for your own site?
Every check in these studies is free to run on your own domain, with no signup and no email required. You'll get the same grade and the same findings the dataset is built from.