Study: half of 4,688 small-business sites fail all seven security-header checks
A 2026 study sampled 7,040 U.S. local-business website listings from the Curlie directory, checking each for seven security headers via a single-request scan. After deduplicating to one HTTP-200 response per unique domain (4,688 sites), 49.7% met none of the seven header criteria.
GoKawiil's interpretation of the reporting above, not reported fact.
Missing security headers like HSTS or Content-Security-Policy can leave small-business sites more exposed to attacks such as clickjacking, mixed-content injection or man-in-the-middle downgrade, since these businesses often lack dedicated security staff, the study's authors note. The findings suggest a broad gap between security best practices used by large enterprises and what typical small local businesses actually deploy, though the study does not measure whether this has led to actual breaches.
- Sample: 7,040 directory-listed U.S. small-business sites, deduplicated to 4,688 unique domains with HTTP-200 responses
- 49.7% of sites met zero of seven measured security-header criteria
- Study used Curlie, the human-edited directory succeeding DMOZ, to source small-business sites without dedicated web-security staff
YubiKey 5C NFC Security Key — If you run a small-business site, pair better security headers with real hardware-backed login protection. A YubiKey adds phishing-resistant multi-factor authentication to your admin and hosting accounts, closing gaps that header misconfigurations alone can't fix.
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: rackcrunch.com — Rackcrunch Team, 2026-09-24
Published there as: “Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.