Every homepage in the Tranco top 1,000 was fetched once and graded on six HTTP security headers. The median score is 37 out of 100, and about 82% have no Content-Security-Policy that would actually stop an XSS.
Same six-header grading, run live against any URL. No sign-up. Powered by the Web Metadata & Contact Extractor API.
Share of the 489 sites that send each header. Only HSTS is on a majority.
Score = mean of the six header grades (missing 0, weak .25, reasonable .6, strong 1), as a percent.
Median security-header score by detected platform (groups with n ≥ 15). WordPress trails the field by ~10 points.
One dot per site. Pearson r = 0.17. The web has largely solved SEO (median 75) and skipped security headers (median 37).
All 1,000 Tranco domains, with the reason each one is in or out of the sample. Click a header to sort.
| # | Domain | Status | Sec | SEO | Platform | Server | Headers (HSTS, CSP, frame, nosniff, referrer, permissions) |
|---|
One GET https://<domain> per site in August 2026, redirects followed, from a
single European vantage point. Headers graded by the open-source Web Metadata & Contact
Extractor API: a CSP containing unsafe-inline, unsafe-eval or a
wildcard source is graded weak, not strong.
Of the 1,000 Tranco domains: 225 are infrastructure (DNS-only CDN / cloud endpoints that serve no site), 209 were unreachable (timeout, geo-block, paywall, apex quirk), 43 returned a bot-challenge or WAF page, and 34 served a placeholder. The 489 that remain are what every figure here is based on. The excluded sites lean toward the heavily bot-protected, so the real picture is if anything slightly worse than shown.
Code, raw responses and this page are MIT-licensed in the repo. The domain list is from Tranco and carries its own terms.