Skip to main content
Back to Home

REAL DATA · UPDATED CONTINUOUSLY

What 505 Production Sites Revealed

The research population contains 505 distinct authorized production websites across 613 eligible scans, with 4,191 findings across 800 security checks. Only completed, sufficiently covered methodology v1.3 scans are included. No site is identified by name.

THE EXPOSURE GAP

What Hackers Can See

32%

NO API RATE LIMITING

No limiting observed on an authoritative public API probe

n=72

65%

NO CSP HEADER

Content-Security-Policy was absent in a completed CSP scan

n=505

90%

NO DNSSEC

DNSSEC was absent in a completed DNS scan

n=494

46%

NO DMARC

No DMARC record was observed in a completed DNS scan

n=494

21%

NO PRIVACY POLICY

No privacy policy was discovered by the completed policy scan

n=412

ADOPTION OF BASIC SECURITY

What is Actually Working

100%

HAS VALID SSL/TLS

n=505

79%

HAS PRIVACY POLICY

n=412

35%

HAS CSP HEADER

n=505

68%

HAS API RATE LIMITING

n=72

METHODOLOGY

How These Numbers Were Computed

Scan corpus: 505 distinct authorized production websites across 613 eligible scans. One row per deployment domain is selected by highest authorization trust tier, then freshness, so rescans do not inflate percentages.

Measurement method: Exposure percentages use only conclusive scanner observations. Unknown, blocked, timed-out, cached, demo, opted-out, older-methodology, and insufficient-coverage rows are excluded. Each published percentage requires at least 30 observed sites and shows its own denominator.

Threat telemetry: Live numbers come from UNPWNED's own honeypot system, exposed at /api/public/threat-stats. Attack sessions are aggregated from attack_sessions with a 30-day rolling window. Source IPs are not published.

License: All aggregated statistics on this page are released under CC BY 4.0. Free to cite with attribution to UNPWNED.

See where your site sits

Run the same 223 checks on your own domain. Free, no signup required.