76% of 6,289 Web Apps Lack Content-Security-Policy, Security Audit Finds
A security benchmark of 6,289 publicly listed web apps, conducted on August 4, 2026, found widespread gaps in basic browser-level protections. Three-quarters of products ship without a Content-Security-Policy header, the primary browser defense against cross-site scripting attacks, while 39% lack Strict-Transport-Security headers. Additional findings show 34% have no reachable privacy policy and 33% fire tracking scripts before obtaining user consent. Only 18% of apps passed six or more of the seven checks in the deterministic audit, which tested public-facing headers and policies without requiring a login. On a positive note, 65% of the 2,405 re-tested tools showed improvement over the prior 100 days, suggesting developers act on visibility.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in