Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria
terrybyte
18 points
14 comments
September 24, 2026
Related Discussions
Found 5 related stories in 88.6ms across 7,602 title embeddings via pgvector HNSW
- 76% of 623 EU software vendors have no security.txt ahead of the CRA 24h rule gilsha · 15 pts · August 26, 2026 · 52% similar
- Only 2.6% of the most visited websites have fully valid HTML theo_dcrx · 40 pts · August 12, 2026 · 52% similar
- Show HN: 92% of US city websites fail ADA accessibility a11ymaster · 21 pts · July 09, 2026 · 48% similar
- Show HN: Tblue – 614 passive security scanners for any website, runs locally taylannuhoglu · 13 pts · August 24, 2026 · 44% similar
- Every fucking website: 2026 edition nerdypepper · 62 pts · August 14, 2026 · 43% similar
Discussion Highlights (5 comments)
n4pw01f
Nice work! You gave me something to fix!!
aetherspawn
It’s ridiculous that the answer to a secure web is for everyone to sprinkle the magic salt and not something on the browser side
GaProgMan
And if any of the websites use .NET, they can get almost all of the recommended security headers in one line by using a NuGet package I created: https://gaprogman.github.io/OwaspHeaders.Core/
stargrazer
So.. you've written up what you checked, and what didn't match what ever criteria you had. But.. what does it mean? Why enforce certain headers? Why enforce certain options? There is a section which kinda looks at this, but not really. You have a bunch of links at the end for resources, but why not just provide the rationale for each rule or option inclusion in the article as well? What does each prevent or allow and why?
fitsumbelay
for static sites on a VPS it's fair to expect the host to provision these, yes?