Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria
5 hours ago
- Only 0.17% of sites passed the script-CSP rule, demonstrating extremely low adoption of effective script restrictions.
- Nearly half (49.7%) of unique final domains met none of the seven studied security header criteria.
- HSTS was the most common header at 43.8%, but only 12.3% met strong HSTS criteria (at least one year with includeSubDomains).
- One in five sites leaked version tokens via server headers, aiding reconnaissance.
- Platform and hosting labels showed that many protections come from hosted platforms (e.g., Shopify, GoDaddy builder) rather than site owner configuration.
- State-level differences in header adoption were not statistically significant, with New York showing the lowest share of zero criteria at 42.9% and Florida the highest at 56.2%.
- Recommended fixes include deploying HSTS, adding clickjacking protection, nosniff, and strict CSP in stages.