Website health, measured across real sites
These figures come from the 228 sites checked on CheckWeb so far, not from a random sample of the web. Anyone can scan any public site, so the set skews toward sites someone had a reason to check. Every number below reflects the latest scan of each domain and is recomputed as new scans land. Last updated 2026-09-15.
What the scans find
- 50% of sites fail at least one security check.
- At least 5% load a component with a known CVE. Counted per version, this is a floor, so the real share is higher.
- 45% of sites fail at least one SEO check.
The most common failures, by share of sites scanned:
- Core security headers47% of sites
- TLS certificate validity4% of sites
- Vulnerable front-end libraries4% of sites
- HTTPS & HTTP→HTTPS redirect2% of sites
- CMS known vulnerabilities1% of sites
Average score by axis
The five axes and their weights are explained in How we score.
- Security75 / 100
- Performance73 / 100
- SEO71 / 100
- Infrastructure90 / 100
- Reputation97 / 100
How the scores spread
| Score range | Sites | Share |
|---|---|---|
| 80-100 | 114 | 50% |
| 60-79 | 96 | 42% |
| 40-59 | 18 | 8% |
| 20-39 | 0 | 0% |
| 0-19 | 0 | 0% |
How these numbers are produced
Every scan is passive: it reads only what a site shows any visitor. Known vulnerabilities are counted per version against the OSV and NVD advisory ranges, and only ranges with a recorded fix are counted, so the CVE figures are a conservative floor rather than a full total. Each domain is counted once, using its most recent scan.
See where a specific site stands
Run a free scan of any public site for the same passive checks behind these numbers: security headers, TLS, known-CVE components, email spoofing gaps.
For what each check means and how to fix it, see the security check guides.
Check my website