Data Study · Website Maintenance

    61.6% of Websites Skip HSTS, the Security Header That Forces Secure Connections

    Matt SuffolettoWritten by Matt Suffoletto
    Published Sept. 24, 2026 4 min read
    Share

    61.6% of websites do not send HSTS, the one-line setting that tells browsers to always use a secure connection. Even among the 10,000 most popular sites, 48.7% skip it.

    Analysis of 15,470,478 homepages · the public HTTP Archive crawl and Google's Chrome UX Report, September 2026

    Key Findings

    1. 1.61.6% of websites do not send HSTS, the security header that tells browsers to always load the site over a secure connection.
    2. 2.48.7% of the 10,000 most popular websites do not send HSTS, nearly half of the sites with the most visitors.
    3. 3.61.9% of websites outside the top 1 million do not send HSTS, against 57% of sites ranked from 10k to 1 million.
    4. 4.5.9% of websites fail a basic HTTPS check altogether, so they need a working secure connection before HSTS can help.
    5. 5.Missing HSTS is the most widespread of five website security gaps measured, ahead of the 54.9% of websites with no web application firewall.

    Summary

    A traveler in a hotel lobby types a bank's address into her browser without the https:// in front. For a split second, before the site redirects her, that first request goes out over an ordinary connection on shared Wi-Fi, which is the moment an attacker on the same network can use to intercept or redirect her.

    HSTS, short for HTTP Strict Transport Security, closes that gap. It is a single line a website sends that tells the browser: from now on, only connect to this site securely. It costs nothing, takes minutes to set up on most hosts, and protects every returning visitor.

    Most of the web does not send it. 61.6% of websites have no HSTS header, 9,535,779 of 15,470,478 homepages. Popularity helps less than you would expect: 48.7% of the 10,000 most popular websites skip it too.

    What we measured

    We used the September 2026 HTTP Archive crawl, a public crawl that loads 15,470,478 homepages in a real browser and records the settings each site sends back. We counted homepages that send no HSTS header and grouped them by popularity using Google's Chrome UX Report, which ranks sites by real Chrome traffic: the 10,000 most popular, sites ranked from 10k to 1 million, and sites beyond the top 1 million.

    HSTS, or HTTP Strict Transport Security, is a response header: an instruction a website sends with each page telling the browser to use only HTTPS, the secure, encrypted version of the site, for a set period. We also counted homepages that fail a basic HTTPS check, and compared missing HSTS with four other security gaps measured in the same crawl.

    HSTS is missing at every level of popularity

    48.7%
    of the 10,000 most popular websites do not send an HSTS header.

    The most popular sites do better, but not by as much as you might expect. Just over half of the 10,000 most popular websites send HSTS. For sites ranked from 10k to 1 million it drops to 43%, and beyond the top 1 million to 38%.

    The long tail dominates in raw numbers. 9,089,817 of the homepages missing HSTS rank outside the top 1 million, the small business and personal sites that rarely have anyone reviewing their server settings.

    Share missing by site popularity
    10,000 most popular
    48.7%
    10k to 1 million
    57%
    Beyond the top 1 million
    61.9%
    All websites
    61.6%

    Source: Suff Digital analysis of 15,470,478 homepages · the public HTTP Archive crawl and Google's Chrome UX Report, September 2026

    Site popularity Homepages No HSTS header Share missing
    10,000 most popular 7,500 3,654 48.7%
    10k to 1 million 775,350 442,308 57%
    Beyond the top 1 million 14,687,628 9,089,817 61.9%
    All websites 15,470,478 9,535,779 61.6%

    Why HSTS matters more than it looks

    Most sites now redirect http:// to https://. But a redirect happens after the browser has already sent the first request in the clear. HSTS removes that step for returning visitors, and sites on the browser preload list get the protection from the very first visit.

    On the other side of the numbers, 5,934,699 homepages do send HSTS, including 3,846 of the 10,000 most popular. HSTS also needs a working HTTPS setup first, and 5.9% of homepages still fail a basic HTTPS check, so those sites have to fix their secure connection before HSTS can help.

    HSTS is the most common security gap measured

    Set against four other security checks in the same September 2026 crawl, missing HSTS is the most widespread problem. It affects more homepages than having no web application firewall, a filter that blocks common attacks before they reach the site, and more than twice as many as loading a JavaScript library with a known vulnerability.

    Share of homepages by security gap
    No HSTS header
    61.6%
    No web application firewall or edge security layer
    54.9%
    Loads a JavaScript library with a known vulnerability
    28.7%
    Fails a basic HTTPS check
    5.9%
    HTTPS page loading insecure HTTP content
    4.5%

    Source: Suff Digital analysis of 15,470,478 homepages · the public HTTP Archive crawl and Google's Chrome UX Report, September 2026

    A site that has never set HSTS has often never had its response headers reviewed at all, which makes the header a useful first check of how well a site is looked after.

    What this means for website owners and developers

    Check your site with a free header scanner, or in your browser's developer tools under Network, then Response Headers. If Strict-Transport-Security is missing, add it at the server, CDN or hosting level. Start with a short max-age, confirm nothing breaks, then raise it to a year and include subdomains once all of them support HTTPS.

    While you are there, add Content-Security-Policy, X-Frame-Options and X-Content-Type-Options. Most hosts and CDNs let you set these without touching the site's code.

    Security headers are part of ongoing website management: set once, then checked whenever the host, CDN or site setup changes.

    Embed this research

    Paste this on your site to embed the charts. It links back to the source automatically.

    <iframe id="sd-hsts-security-header-missing" src="https://www.suffdigital.com/embed/data-studies/hsts-security-header-missing" width="100%" height="600" style="width:100%;border:1px solid #E5E7EB;border-radius:12px" loading="lazy" title="61.6% of Websites Skip HSTS, the Security Header That Forces Secure Connections - Suff Digital"></iframe>
    <script>window.addEventListener("message",function(e){if(e&&e.data&&e.data.sdEmbed==="hsts-security-header-missing"&&e.data.height){var f=document.getElementById("sd-hsts-security-header-missing");if(f){f.style.height=e.data.height+"px";}}});</script>
    <p style="font:14px/1.5 system-ui,sans-serif">Source: <a href="https://www.suffdigital.com/resources/data-studies/hsts-security-header-missing">61.6% of Websites Skip HSTS, the Security Header That Forces Secure Connections - Suff Digital</a></p>

    Cite this study

    APA

    Suff Digital. (2026). 61.6% of Websites Skip HSTS, the Security Header That Forces Secure Connections. https://www.suffdigital.com/resources/data-studies/hsts-security-header-missing

    Plain link

    61.6% of Websites Skip HSTS, the Security Header That Forces Secure Connections - Suff Digital - https://www.suffdigital.com/resources/data-studies/hsts-security-header-missing

    Frequently asked questions

    Related studies