Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria

Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria

A recent study examined 4,688 small‑business sites, checking for seven common security header best practices. Nearly half—49.7%—had none of the headers in place, leaving them vulnerable to attacks such as click‑jacking, MIME sniffing, or XSS. The analysis highlights a widespread gap in basic web security measures among small businesses and underscores the need for automated security tools.