61.6% of Websites Skip HSTS, the Security Header That Forces Secure Connections

    61.6% of websites do not send HSTS, the one-line setting that tells browsers to always use a secure connection. Even among the 10,000 most popular sites, 48.7% skip it.

    Share missing by site popularity
    10,000 most popular
    48.7%
    10k to 1 million
    57%
    Beyond the top 1 million
    61.9%
    All websites
    61.6%

    Source: Suff Digital analysis of 15,470,478 homepages · the public HTTP Archive crawl and Google's Chrome UX Report, September 2026

    Share of homepages by security gap
    No HSTS header
    61.6%
    No web application firewall or edge security layer
    54.9%
    Loads a JavaScript library with a known vulnerability
    28.7%
    Fails a basic HTTPS check
    5.9%
    HTTPS page loading insecure HTTP content
    4.5%

    Source: Suff Digital analysis of 15,470,478 homepages · the public HTTP Archive crawl and Google's Chrome UX Report, September 2026

    Source: 61.6% of Websites Skip HSTS, the Security Header That Forces Secure Connections - Suff Digital