Skip to main content
UNPWNED
Back to Home

REAL DATA · UPDATED CONTINUOUSLY

What 525 Production Sites Revealed

The research population contains 525 distinct authorized production websites across 637 eligible scans, with 4,300 findings from a catalog whose 721-check full suite requires current ownership proof plus explicit active-testing authorization. Public aggregates use completed, authorization-gated and coverage-eligible observations. Historical rows whose exact scanner build was never persisted may remain in this legacy aggregate, but are excluded from the prospective Exposure Pressure Study. No site is identified by name.

THE EXPOSURE GAP

What Hackers Can See

32%

NO API RATE LIMITING

No limiting observed on an authoritative public API probe

n=73

66%

NO CSP HEADER

Content-Security-Policy was absent in a completed CSP scan

n=525

90%

NO DNSSEC

DNSSEC was absent in a completed DNS scan

n=507

46%

NO DMARC

No DMARC record was observed in a completed DNS scan

n=507

21%

NO PRIVACY POLICY

No privacy policy was discovered by the completed policy scan

n=414

ADOPTION OF BASIC SECURITY

What is Actually Working

100%

HAS VALID SSL/TLS

n=525

79%

HAS PRIVACY POLICY

n=414

35%

HAS CSP HEADER

n=525

69%

HAS API RATE LIMITING

n=73

METHODOLOGY

How These Numbers Were Computed

Scan corpus: 525 distinct authorized production websites across 637 eligible scans. One row per deployment domain is selected by highest authorization trust tier, then freshness, so rescans do not inflate percentages.

Measurement method: Exposure percentages use conclusive scanner observations and show a per-metric denominator. Unknown, blocked, timed-out, cached, demo, opted-out, and insufficient-coverage observations are excluded. The legacy site population can include conservatively screened historical rows whose exact build metadata was not persisted; those rows are not eligible for the new prospective study. Each published percentage requires at least 30 observed sites.

Threat telemetry: Live numbers come from UNPWNED's own honeypot system, exposed at /api/public/threat-stats. Sessions require linked non-health event evidence in the 30-day rolling window. Health-only and unverifiable sessions are excluded. The metric describes suspicious probing, not confirmed compromise or exploitation. Source IPs are not published.

License: All aggregated statistics on this page are released under CC BY 4.0. Free to cite with attribution to UNPWNED.

See where your site sits

Run the same 149 checks on your own domain. Free, no signup required.