Skip to content

Latest commit

 

History

History
180 lines (83 loc) · 7.35 KB

tab_statistics.md

File metadata and controls

180 lines (83 loc) · 7.35 KB
title displaytext layout tab order tags
statistics
Statistics
true
7
headers

Statistic about HTTP security response headers usage

📅 Last update: 03/05/2025 at 00:14:53 - Domains analyzed count: 150000.

Global usage of secure headers

Provide the distribution of usage of secure headers across all domains analyzed.

be611e71c615c27471d766612bfb7e8b05d743c7

Global usage of header 'cache-control'

Provide the distribution of usage of the header 'cache-control' across all domains analyzed.

577d76c6092c4da6347e1d2c89523dd13a1925f7

Global usage of header 'clear-site-data'

Provide the distribution of usage of the header 'clear-site-data' across all domains analyzed.

49f6a7d15e9a2e3fd4cad94360d37e83ef05fa00

Global usage of header 'content-security-policy'

Provide the distribution of usage of the header 'content-security-policy' across all domains analyzed.

2da94599d03c73073ac60b0d8864152f8609cc5b

Global usage of header 'content-security-policy-report-only'

Provide the distribution of usage of the header 'content-security-policy-report-only' across all domains analyzed.

c0b5a705e7e94af3f71ef579bb01b45c2a80ca6b

Global usage of header 'cross-origin-embedder-policy'

Provide the distribution of usage of the header 'cross-origin-embedder-policy' across all domains analyzed.

0753b0c4fecc8c56d81e31f36bc8c397cea5032b

Global usage of header 'cross-origin-opener-policy'

Provide the distribution of usage of the header 'cross-origin-opener-policy' across all domains analyzed.

e7e550d9cbff786153f7f13f664361e41efee57c

Global usage of header 'cross-origin-resource-policy'

Provide the distribution of usage of the header 'cross-origin-resource-policy' across all domains analyzed.

9cf15b18b743939cbe01342ed5461bc7af6c4d36

Global usage of header 'expect-ct'

Provide the distribution of usage of the header 'expect-ct' across all domains analyzed.

78fc7e8d03077546e27c016ee80b2143dc4ebb08

Global usage of header 'permissions-policy'

Provide the distribution of usage of the header 'permissions-policy' across all domains analyzed.

87eabe1fe075f9034dc4db8f76be07da0d08afe3

Global usage of header 'public-key-pins'

Provide the distribution of usage of the header 'public-key-pins' across all domains analyzed.

e58d592c018472a09777c3fd5440f556bd176dd5

Global usage of header 'referrer-policy'

Provide the distribution of usage of the header 'referrer-policy' across all domains analyzed.

15d82f7cac9021b254fdf8fed98bb870acc436fb

Global usage of header 'strict-transport-security'

Provide the distribution of usage of the header 'strict-transport-security' across all domains analyzed.

c313c0ceef6eb3116547426b41bdf278df2cc0c6

Global usage of header 'x-content-type-options'

Provide the distribution of usage of the header 'x-content-type-options' across all domains analyzed.

5808d16f90388bd6309eb12d74010d1c4a8518cf

Global usage of header 'x-frame-options'

Provide the distribution of usage of the header 'x-frame-options' across all domains analyzed.

cfaf56ab8ec6588aa6ee9297b4f93638640d1048

Global usage of header 'x-permitted-cross-domain-policies'

Provide the distribution of usage of the header 'x-permitted-cross-domain-policies' across all domains analyzed.

2ec5e9a684938a169c757a7a631595c53fccc769

Global usage of header 'x-xss-protection'

Provide the distribution of usage of the header 'x-xss-protection' across all domains analyzed.

7b2906800d5eb94d25d0f5cf18322155e8f2192d

Global usage of insecure framing configuration via the header 'x-frame-options'

Provide the distribution of usage of the header 'x-frame-options' across all domains analyzed with a insecure framing configuration: value different from DENY or SAMEORIGIN including unsupported values.

ccc438a754b6d9324c9c1ea62662969c6114bfdf

Global usage of insecure referrer configuration via the header 'referrer-policy'

Provide the distribution of usage of the header 'referrer-policy' across all domains analyzed with a insecure referrer configuration: value set to unsafe-url or no-referrer-when-downgrade.

no-referrer-when-downgrade was included because it send origin, path, and querystring when the protocol security level stays the same (HTTPS is very often in place).

e90a8350bb77972b086599b65efc8fcd02036a11

Global usage of the Strict Transport Security 'preload' feature

Provide the distribution of usage of the 'preload' feature for the header 'strict-transport-security' across all domains analyzed.

8dd898e970a4cc540e0394ace9c9cedd425bc1c5

Global common 'max-age' values of the Strict Transport Security header

  • Most common value used is 31536000 seconds (525600 minutes) across all domains analyzed.
  • Maximum value used is 1234513412313 seconds (20575223539 minutes) across all domains analyzed.
  • Minimum value used is -291868904 seconds (-4864482 minutes) across all domains analyzed.

Global usage of content security policy with directives allowing unsafe expressions

Provide the distribution of content security policy allowing unsafe expressions across all domains analyzed.

Determine if a CSP policy contains (default-src|script-src|script-src-elem|script-src-attr|style-src) directives using (unsafe-inline|unsafe-hashes|unsafe-eval) expressions.

Based on Report-URI CSP generator allowed instructions for CSP directives.

c7ef83055cf836a48ed9dd26b3a8d55103645022