By the numbers
Aggregated across every scan we’ve run — fully anonymized. We never store which site had which issue; these are just counts.
46
Scans run
0%
Had a HIGH+ issue
2026-07-22
Library freshness
Most common findings
Missing header: Content-Security-Policy
74% of scans
Missing header: Strict-Transport-Security (HSTS)
74% of scans
Missing header: X-Content-Type-Options
67% of scans
Missing header: X-Frame-Options / frame-ancestors
61% of scans
Server advertises its framework/version
24% of scans
Plain HTTP is served without redirecting to HTTPS
15% of scans
Self Signed SSL Certificate
13% of scans
Session/auth cookie missing hardening flags
9% of scans
Version banner leaked: server
7% of scans
Severity mix
medium · 72low · 86
Want your site checked against all of this? Run a scan for $1 →