Research

How real websites are actually configured

Most security statistics are vendor estimates or survey answers. These are measurements: we run the same passive checks as the free tools on this site across hundreds of live sites and publish what came back, with the sample size next to every number.

Free to cite, with attribution. If you need a cut of the data we haven't published, ask — we'll tell you whether the underlying data supports it.

The current headline numbers

From the most recent edition — 1,106 online stores on their own domains, bucketed by the platform they run on, measured in September 2026. Denominators differ because not every check returns a usable result for every host.

98.5%
send HSTS — the platform sets it at its edge, for everyone
336 of 341 Shopify stores
25.8%
enforce DMARC, so three quarters can be impersonated by email
88 of the same 341
68.5%
of stores that look well-configured to a browser still can't stop a spoofed email
311 of 454
31.3%
of all stores enforce DMARC; 46.2% publish p=none, which blocks nothing
346 of 1,106
7.3%
expose a sensitive file or panel — a .git, an .env, a backup
68 of 926

Editions

September 2026

The platform fixes what the browser sees, not what your customer gets emailed

1,106 online stores · bucketed by platform

Shopify's 341 stores send HSTS and CSP 98.5% of the time and only 25.8% of them enforce DMARC — the same merchants, scoring 98% on the half a browser sees and 26% on the half that reaches an inbox.

Read the study →
September 2026

The state of web security at the companies that build websites

376 web agencies · Bulgaria and Italy

The firms that build other people's websites, measured on their own. 81% run no CSP, 63% no HSTS, and only 27% enforce DMARC — with WordPress agencies materially worse than the rest. Carries a published correction: 18 of the 376 domains turned out not to be agencies, moving the figures by under a point.

Read the study →

Method

Passive only. One HTTP GET of the homepage plus public DNS lookups, per domain. No authentication, no crawling beyond that page, no port scanning, no payloads, no active testing. Everything measured is what the site sends to any browser that visits it — see how we scan.

The same engine as the free tools. No separate research pipeline that could drift from the product: a study run is the website security score check set, run in batch. If a number here looks wrong, you can reproduce it on any one of the domains yourself.

Nothing is published about an individual site. Only aggregates, with denominators. The point is the population, not naming a company — and a list of individually weak sites would be a target list, not research.

The sample is not random, and that matters. Domains come from public search results for the sector and country, deduplicated per registrable domain. Search visibility correlates with company size and technical investment, so the sample skews toward better-resourced firms. The honest reading is that the wider population is probably no better than these figures, and may be worse.

Denominators vary by check, on purpose. A host that didn't answer in time for the TLS probe is excluded from TLS figures rather than counted as a pass. That's why the numbers above say “of 353” and “of 374” rather than all citing the full 376.

Want the same measurements for your own site?

Every check in these studies is free to run on your own domain, with no signup and no email required. You'll get the same grade and the same findings the dataset is built from.

Check a site