REAL DATA · UPDATED CONTINUOUSLY
What 505 Production Sites Revealed
The research population contains 505 distinct authorized production websites across 613 eligible scans, with 4,191 findings across 800 security checks. Only completed, sufficiently covered methodology v1.3 scans are included. No site is identified by name.
THE EXPOSURE GAP
What Hackers Can See
NO API RATE LIMITING
No limiting observed on an authoritative public API probe
n=72
NO CSP HEADER
Content-Security-Policy was absent in a completed CSP scan
n=505
NO DNSSEC
DNSSEC was absent in a completed DNS scan
n=494
NO DMARC
No DMARC record was observed in a completed DNS scan
n=494
NO PRIVACY POLICY
No privacy policy was discovered by the completed policy scan
n=412
ADOPTION OF BASIC SECURITY
What is Actually Working
HAS VALID SSL/TLS
n=505
HAS PRIVACY POLICY
n=412
HAS CSP HEADER
n=505
HAS API RATE LIMITING
n=72
METHODOLOGY
How These Numbers Were Computed
Scan corpus: 505 distinct authorized production websites across 613 eligible scans. One row per deployment domain is selected by highest authorization trust tier, then freshness, so rescans do not inflate percentages.
Measurement method: Exposure percentages use only conclusive scanner observations. Unknown, blocked, timed-out, cached, demo, opted-out, older-methodology, and insufficient-coverage rows are excluded. Each published percentage requires at least 30 observed sites and shows its own denominator.
Threat telemetry: Live numbers come from UNPWNED's own honeypot system, exposed at /api/public/threat-stats. Attack sessions are aggregated from attack_sessions with a 30-day rolling window. Source IPs are not published.
License: All aggregated statistics on this page are released under CC BY 4.0. Free to cite with attribution to UNPWNED.
See where your site sits
Run the same 223 checks on your own domain. Free, no signup required.
