Cybersecurity

Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria

A survey of 4,688 small-business websites found that 49.7% of them failed to meet any of the 7 security header criteria, which are essential for protecting against common web attacks. The criteria include the presence of the Content Security Policy (CSP), Cross-Origin Resource Sharing (CORS), Cross-Site Scripting (XSS), and other headers. The survey was conducted by RackCrunch, a security and performance optimization company. The results suggest that small businesses are not prioritizing security, leaving them vulnerable to attacks. The survey also found that only 33.6% of the websites met all 7 criteria, indicating a significant lack of security awareness.

Read the full article at rackcrunch.com →