61.6% of websites do not send HSTS, the one-line setting that tells browsers to always use a secure connection. Even among the 10,000 most popular sites, 48.7% skip it.
Analysis of 15,470,478 homepages · the public HTTP Archive crawl and Google's Chrome UX Report, September 2026
Key Findings
- 1.61.6% of websites do not send HSTS, the security header that tells browsers to always load the site over a secure connection.
- 2.48.7% of the 10,000 most popular websites do not send HSTS, nearly half of the sites with the most visitors.
- 3.61.9% of websites outside the top 1 million do not send HSTS, against 57% of sites ranked from 10k to 1 million.
- 4.5.9% of websites fail a basic HTTPS check altogether, so they need a working secure connection before HSTS can help.
- 5.Missing HSTS is the most widespread of five website security gaps measured, ahead of the 54.9% of websites with no web application firewall.
Summary
A traveler in a hotel lobby types a bank's address into her browser without the https:// in front. For a split second, before the site redirects her, that first request goes out over an ordinary connection on shared Wi-Fi, which is the moment an attacker on the same network can use to intercept or redirect her.
HSTS, short for HTTP Strict Transport Security, closes that gap. It is a single line a website sends that tells the browser: from now on, only connect to this site securely. It costs nothing, takes minutes to set up on most hosts, and protects every returning visitor.
Most of the web does not send it. 61.6% of websites have no HSTS header, 9,535,779 of 15,470,478 homepages. Popularity helps less than you would expect: 48.7% of the 10,000 most popular websites skip it too.
What we measured
We used the September 2026 HTTP Archive crawl, a public crawl that loads 15,470,478 homepages in a real browser and records the settings each site sends back. We counted homepages that send no HSTS header and grouped them by popularity using Google's Chrome UX Report, which ranks sites by real Chrome traffic: the 10,000 most popular, sites ranked from 10k to 1 million, and sites beyond the top 1 million.
HSTS, or HTTP Strict Transport Security, is a response header: an instruction a website sends with each page telling the browser to use only HTTPS, the secure, encrypted version of the site, for a set period. We also counted homepages that fail a basic HTTPS check, and compared missing HSTS with four other security gaps measured in the same crawl.
HSTS is missing at every level of popularity
The most popular sites do better, but not by as much as you might expect. Just over half of the 10,000 most popular websites send HSTS. For sites ranked from 10k to 1 million it drops to 43%, and beyond the top 1 million to 38%.
The long tail dominates in raw numbers. 9,089,817 of the homepages missing HSTS rank outside the top 1 million, the small business and personal sites that rarely have anyone reviewing their server settings.
Source: Suff Digital analysis of 15,470,478 homepages · the public HTTP Archive crawl and Google's Chrome UX Report, September 2026
| Site popularity | Homepages | No HSTS header | Share missing |
|---|---|---|---|
| 10,000 most popular | 7,500 | 3,654 | 48.7% |
| 10k to 1 million | 775,350 | 442,308 | 57% |
| Beyond the top 1 million | 14,687,628 | 9,089,817 | 61.9% |
| All websites | 15,470,478 | 9,535,779 | 61.6% |
Why HSTS matters more than it looks
Most sites now redirect http:// to https://. But a redirect happens after the browser has already sent the first request in the clear. HSTS removes that step for returning visitors, and sites on the browser preload list get the protection from the very first visit.
On the other side of the numbers, 5,934,699 homepages do send HSTS, including 3,846 of the 10,000 most popular. HSTS also needs a working HTTPS setup first, and 5.9% of homepages still fail a basic HTTPS check, so those sites have to fix their secure connection before HSTS can help.
HSTS is the most common security gap measured
Set against four other security checks in the same September 2026 crawl, missing HSTS is the most widespread problem. It affects more homepages than having no web application firewall, a filter that blocks common attacks before they reach the site, and more than twice as many as loading a JavaScript library with a known vulnerability.
Source: Suff Digital analysis of 15,470,478 homepages · the public HTTP Archive crawl and Google's Chrome UX Report, September 2026
A site that has never set HSTS has often never had its response headers reviewed at all, which makes the header a useful first check of how well a site is looked after.
What this means for website owners and developers
Check your site with a free header scanner, or in your browser's developer tools under Network, then Response Headers. If Strict-Transport-Security is missing, add it at the server, CDN or hosting level. Start with a short max-age, confirm nothing breaks, then raise it to a year and include subdomains once all of them support HTTPS.
While you are there, add Content-Security-Policy, X-Frame-Options and X-Content-Type-Options. Most hosts and CDNs let you set these without touching the site's code.
Security headers are part of ongoing website management: set once, then checked whenever the host, CDN or site setup changes.
Embed this research
Paste this on your site to embed the charts. It links back to the source automatically.
<iframe id="sd-hsts-security-header-missing" src="https://www.suffdigital.com/embed/data-studies/hsts-security-header-missing" width="100%" height="600" style="width:100%;border:1px solid #E5E7EB;border-radius:12px" loading="lazy" title="61.6% of Websites Skip HSTS, the Security Header That Forces Secure Connections - Suff Digital"></iframe>
<script>window.addEventListener("message",function(e){if(e&&e.data&&e.data.sdEmbed==="hsts-security-header-missing"&&e.data.height){var f=document.getElementById("sd-hsts-security-header-missing");if(f){f.style.height=e.data.height+"px";}}});</script>
<p style="font:14px/1.5 system-ui,sans-serif">Source: <a href="https://www.suffdigital.com/resources/data-studies/hsts-security-header-missing">61.6% of Websites Skip HSTS, the Security Header That Forces Secure Connections - Suff Digital</a></p>
Cite this study
Suff Digital. (2026). 61.6% of Websites Skip HSTS, the Security Header That Forces Secure Connections. https://www.suffdigital.com/resources/data-studies/hsts-security-header-missing
61.6% of Websites Skip HSTS, the Security Header That Forces Secure Connections - Suff Digital - https://www.suffdigital.com/resources/data-studies/hsts-security-header-missing
Frequently asked questions
Related studies
- Website MaintenanceNearly 3 in 10 Websites Load a JavaScript Library With a Known Security Flaw
- Website Maintenance58% of Small Websites Have No Web Application Firewall vs 34.4% of the Top 10,000
- Website Maintenance48.1% of Websites That Show Their PHP Version Run One With No Security Fixes
- Website MaintenanceSmall Business Website Upkeep: 11.5% of Domain Names Are Due to Expire Within 60 Days
