REAL DATA · UPDATED CONTINUOUSLY
What 525 Production Sites Revealed
The research population contains 525 distinct authorized production websites across 637 eligible scans, with 4,300 findings from a catalog whose 721-check full suite requires current ownership proof plus explicit active-testing authorization. Public aggregates use completed, authorization-gated and coverage-eligible observations. Historical rows whose exact scanner build was never persisted may remain in this legacy aggregate, but are excluded from the prospective Exposure Pressure Study. No site is identified by name.
THE EXPOSURE GAP
What Hackers Can See
NO API RATE LIMITING
No limiting observed on an authoritative public API probe
n=73
NO CSP HEADER
Content-Security-Policy was absent in a completed CSP scan
n=525
NO DNSSEC
DNSSEC was absent in a completed DNS scan
n=507
NO DMARC
No DMARC record was observed in a completed DNS scan
n=507
NO PRIVACY POLICY
No privacy policy was discovered by the completed policy scan
n=414
ADOPTION OF BASIC SECURITY
What is Actually Working
HAS VALID SSL/TLS
n=525
HAS PRIVACY POLICY
n=414
HAS CSP HEADER
n=525
HAS API RATE LIMITING
n=73
METHODOLOGY
How These Numbers Were Computed
Scan corpus: 525 distinct authorized production websites across 637 eligible scans. One row per deployment domain is selected by highest authorization trust tier, then freshness, so rescans do not inflate percentages.
Measurement method: Exposure percentages use conclusive scanner observations and show a per-metric denominator. Unknown, blocked, timed-out, cached, demo, opted-out, and insufficient-coverage observations are excluded. The legacy site population can include conservatively screened historical rows whose exact build metadata was not persisted; those rows are not eligible for the new prospective study. Each published percentage requires at least 30 observed sites.
Threat telemetry: Live numbers come from UNPWNED's own honeypot system, exposed at /api/public/threat-stats. Sessions require linked non-health event evidence in the 30-day rolling window. Health-only and unverifiable sessions are excluded. The metric describes suspicious probing, not confirmed compromise or exploitation. Source IPs are not published.
License: All aggregated statistics on this page are released under CC BY 4.0. Free to cite with attribution to UNPWNED.
See where your site sits
Run the same 149 checks on your own domain. Free, no signup required.
