Skip to main content
UNPWNED
Back to Home

REAL DATA · UPDATED CONTINUOUSLY

What 48 Production Sites Revealed

The research population contains 48 distinct authorized production websites across 60 eligible scans, with 264 findings from a catalog whose currently enabled Deep Scan runs up to 702 configured checks after current ownership proof. Public aggregates use completed, authorization-gated and coverage-eligible observations from the currently activated scoring methodology. Rows without an exact matching methodology are excluded. No site is identified by name.

THE EXPOSURE GAP

What Hackers Can See

64%

NO CSP HEADER

Content-Security-Policy was absent in a completed CSP scan

n=47

83%

NO DNSSEC

DNSSEC was absent in a completed DNS scan

n=41

39%

NO DMARC

No DMARC record was observed in a completed DNS scan

n=41

ADOPTION OF BASIC SECURITY

What is Actually Working

36%

HAS CSP HEADER

n=47

METHODOLOGY

How These Numbers Were Computed

Scan corpus: 48 distinct authorized production websites across 60 eligible scans. One row per deployment domain is selected by highest authorization trust tier, then freshness, so rescans do not inflate percentages.

Measurement method: Exposure percentages use conclusive scanner observations and show a per-metric denominator. Unknown, blocked, timed-out, cached, demo, opted-out, insufficient-coverage, and methodology-mismatched observations are excluded. Each published percentage requires at least 30 observed sites.

Threat telemetry: Live numbers come from UNPWNED's own honeypot system, exposed at /api/public/threat-stats. Sessions require linked non-health event evidence in the 30-day rolling window. Health-only and unverifiable sessions are excluded. The metric describes suspicious probing, not confirmed compromise or exploitation. Source IPs are not published.

License: All aggregated statistics on this page are released under CC BY 4.0. Free to cite with attribution to UNPWNED.

See where your site sits

Run the same 149 checks on your own domain. Free, no signup required.