Website security, measured across real sites
These figures come from the 81 sites checked on CheckWeb so far, not from a random sample of the web. Anyone can scan any public site, so the set skews toward sites someone had a reason to check. Every number below reflects the latest scan of each domain and is recomputed as new scans land. Last updated 2026-07-28.
What the scans find
- 42% of sites fail at least one security check.
- At least 10% load a component with a known CVE. Counted per version, this is a floor, so the real share is higher.
The most common failures, by share of sites scanned:
- Core security headers38% of sites
- TLS certificate validity7% of sites
- CMS known vulnerabilities5% of sites
- Vulnerable front-end libraries5% of sites
- HTTPS & HTTP→HTTPS redirect4% of sites
Average score by axis
The five axes and their weights are explained in How we score.
- Security75 / 100
- Performance81 / 100
- SEO70 / 100
- Infrastructure91 / 100
- Reputation97 / 100
How the scores spread
| Score range | Sites | Share |
|---|---|---|
| 80-100 | 45 | 56% |
| 60-79 | 30 | 37% |
| 40-59 | 6 | 7% |
| 20-39 | 0 | 0% |
| 0-19 | 0 | 0% |
How these numbers are produced
Every scan is passive: it reads only what a site shows any visitor. Known vulnerabilities are counted per version against the OSV and NVD advisory ranges, and only ranges with a recorded fix are counted, so the CVE figures are a conservative floor rather than a full total. Each domain is counted once, using its most recent scan.
See where a specific site stands
Run a free scan of any public site for the same passive checks behind these numbers: security headers, TLS, known-CVE components, email spoofing gaps.
For what each check means and how to fix it, see the security check guides.
Check my website