We found that only 8 of 4,688 small business sites we scanned pass a real script-CSP check
A 2026 study scanned 4,688 US small business websites and found that only 8 (0.17%) implemented a Content-Security-Policy (CSP) that effectively restricts scripts. Nearly half of the sites met none of seven basic security header criteria checked, including headers like HSTS, X-Content-Type-Options, and clickjacking protection. While many sites send some headers, the adoption of strong security headers is low, especially for script-restricting CSPs. The study highlights a widespread lack of basic HTTP security header adoption among small business websites, which represent a low-cost security layer. However, the absence of these headers does not necessarily prove sites are vulnerable or hackable, but indicates a missed opportunity for improving security posture.
AI Analysis
Technical Summary
The Rackcrunch team conducted a header-only scan of 4,688 US small business websites, analyzing HTTPS response headers without invasive probing. They assessed seven explicit security header criteria, including HSTS, CSP, X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy, and Cross-Origin-Opener-Policy. Results showed 49.7% of sites met none of these criteria. Only 21.2% sent an enforced CSP, but most were framing or upgrade rules, with only 0.17% passing a strict script-restricting CSP check. Other headers like strong HSTS (12.3%) and X-Content-Type-Options nosniff (39.7%) had low adoption rates. The study emphasizes that while these headers are a simple configuration step, they are underutilized in this segment of websites.
Potential Impact
The low adoption of security headers among small business websites means these sites may lack basic protections against certain classes of web-based attacks that headers like CSP, HSTS, and clickjacking protection help mitigate. However, the study does not confirm actual vulnerabilities or exploits, only the absence of these security layers. The impact is primarily an increased risk surface due to missing or weak HTTP security headers, which are a low-cost defense mechanism.
Mitigation Recommendations
No official patch or fix is applicable as this is a security posture assessment rather than a software vulnerability. Small business website operators are encouraged to implement appropriate HTTP security headers, especially a restrictive Content-Security-Policy to control script execution, HSTS with includeSubDomains for HTTPS enforcement, and X-Content-Type-Options: nosniff to reduce MIME-type confusion risks. Since these headers are configuration changes, they represent a low-effort improvement. The study notes that maintaining CSP can be challenging for infrequently updated sites, so realistic policies should be considered.
We found that only 8 of 4,688 small business sites we scanned pass a real script-CSP check
Description
A 2026 study scanned 4,688 US small business websites and found that only 8 (0.17%) implemented a Content-Security-Policy (CSP) that effectively restricts scripts. Nearly half of the sites met none of seven basic security header criteria checked, including headers like HSTS, X-Content-Type-Options, and clickjacking protection. While many sites send some headers, the adoption of strong security headers is low, especially for script-restricting CSPs. The study highlights a widespread lack of basic HTTP security header adoption among small business websites, which represent a low-cost security layer. However, the absence of these headers does not necessarily prove sites are vulnerable or hackable, but indicates a missed opportunity for improving security posture.
Reddit Discussion
I'm part of the Rackcrunch team. We ran a header-only scan of 4,688 US small business websites, sampled from a public business directory. We only read HTTPS response headers. No page content, no probing, nothing invasive.
Short version: 49.7% met none of the seven basic header criteria we checked. 21.2% send an enforced Content-Security-Policy, but most of those are framing or upgrade rules only. Only 8 out of 4,688 (0.17%) passed our check for a CSP that actually restricts scripts.
None of this proves a site is hackable or vulnerabl. Headers are one layer. But they're the cheapest layer, a few lines of config, and half sites we looked at don't bother.
Full method, rubric and de-identified data here if you want to check our work: https://rackcrunch.com/security-headers-2026
Question/feedback requested: which headers are realistic to ask of a small business site? CSP is the obvious sticking point. Nobody wants to maintain one on a site they touch twice a year.
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Rackcrunch team conducted a header-only scan of 4,688 US small business websites, analyzing HTTPS response headers without invasive probing. They assessed seven explicit security header criteria, including HSTS, CSP, X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy, and Cross-Origin-Opener-Policy. Results showed 49.7% of sites met none of these criteria. Only 21.2% sent an enforced CSP, but most were framing or upgrade rules, with only 0.17% passing a strict script-restricting CSP check. Other headers like strong HSTS (12.3%) and X-Content-Type-Options nosniff (39.7%) had low adoption rates. The study emphasizes that while these headers are a simple configuration step, they are underutilized in this segment of websites.
Potential Impact
The low adoption of security headers among small business websites means these sites may lack basic protections against certain classes of web-based attacks that headers like CSP, HSTS, and clickjacking protection help mitigate. However, the study does not confirm actual vulnerabilities or exploits, only the absence of these security layers. The impact is primarily an increased risk surface due to missing or weak HTTP security headers, which are a low-cost defense mechanism.
Defensive Guidance
No official patch or fix is applicable as this is a security posture assessment rather than a software vulnerability. Small business website operators are encouraged to implement appropriate HTTP security headers, especially a restrictive Content-Security-Policy to control script execution, HSTS with includeSubDomains for HTTPS enforcement, and X-Content-Type-Options: nosniff to reduce MIME-type confusion risks. Since these headers are configuration changes, they represent a low-effort improvement. The study notes that maintaining CSP can be challenging for infrequently updated sites, so realistic policies should be considered.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6ab9a414f7a7c5410699b010
Added to database: 09/27/2026, 23:17:40 UTC
Last enriched: 09/27/2026, 23:17:45 UTC
Last updated: 09/28/2026, 04:47:39 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.