Skip to main content

We found that only 8 of 4,688 small business sites we scanned pass a real script-CSP check

0
Medium
Published: 09/27/2026 (09/27/2026, 23:06:18 UTC)
Source: Reddit Cybersecurity

Description

A 2026 study scanned 4,688 US small business websites and found that only 8 (0.17%) implemented a Content-Security-Policy (CSP) that effectively restricts scripts. Nearly half of the sites met none of seven basic security header criteria checked, including headers like HSTS, X-Content-Type-Options, and clickjacking protection. While many sites send some headers, the adoption of strong security headers is low, especially for script-restricting CSPs. The study highlights a widespread lack of basic HTTP security header adoption among small business websites, which represent a low-cost security layer. However, the absence of these headers does not necessarily prove sites are vulnerable or hackable, but indicates a missed opportunity for improving security posture.

Reddit Discussion

r/cybersecurity·posted by u/Plastic-Falcon9147
00

I'm part of the Rackcrunch team. We ran a header-only scan of 4,688 US small business websites, sampled from a public business directory. We only read HTTPS response headers. No page content, no probing, nothing invasive.

Short version: 49.7% met none of the seven basic header criteria we checked. 21.2% send an enforced Content-Security-Policy, but most of those are framing or upgrade rules only. Only 8 out of 4,688 (0.17%) passed our check for a CSP that actually restricts scripts.

None of this proves a site is hackable or vulnerabl. Headers are one layer. But they're the cheapest layer, a few lines of config, and half sites we looked at don't bother.

Full method, rubric and de-identified data here if you want to check our work: https://rackcrunch.com/security-headers-2026

Question/feedback requested: which headers are realistic to ask of a small business site? CSP is the obvious sticking point. Nobody wants to maintain one on a site they touch twice a year.

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/27/2026, 23:17:45 UTC

Technical Analysis

The Rackcrunch team conducted a header-only scan of 4,688 US small business websites, analyzing HTTPS response headers without invasive probing. They assessed seven explicit security header criteria, including HSTS, CSP, X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy, and Cross-Origin-Opener-Policy. Results showed 49.7% of sites met none of these criteria. Only 21.2% sent an enforced CSP, but most were framing or upgrade rules, with only 0.17% passing a strict script-restricting CSP check. Other headers like strong HSTS (12.3%) and X-Content-Type-Options nosniff (39.7%) had low adoption rates. The study emphasizes that while these headers are a simple configuration step, they are underutilized in this segment of websites.

Potential Impact

The low adoption of security headers among small business websites means these sites may lack basic protections against certain classes of web-based attacks that headers like CSP, HSTS, and clickjacking protection help mitigate. However, the study does not confirm actual vulnerabilities or exploits, only the absence of these security layers. The impact is primarily an increased risk surface due to missing or weak HTTP security headers, which are a low-cost defense mechanism.

Defensive Guidance

No official patch or fix is applicable as this is a security posture assessment rather than a software vulnerability. Small business website operators are encouraged to implement appropriate HTTP security headers, especially a restrictive Content-Security-Policy to control script execution, HSTS with includeSubDomains for HTTPS enforcement, and X-Content-Type-Options: nosniff to reduce MIME-type confusion risks. Since these headers are configuration changes, they represent a low-effort improvement. The study notes that maintaining CSP can be challenging for infrequently updated sites, so realistic policies should be considered.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6ab9a414f7a7c5410699b010

Added to database: 09/27/2026, 23:17:40 UTC

Last enriched: 09/27/2026, 23:17:45 UTC

Last updated: 09/28/2026, 04:47:39 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses