Security Headers on Directory-Listed U.S. Local-Business Websites
Summary
A large-scale RackCrunch study analyzes security headers on 7,040 directory-listed U.S. local-business websites to evaluate adherence to seven explicit header criteria. It finds that 49.7% of HTTP-200 responses meet none of the criteria and provides detailed breakdowns by header type, hosting labels, sector, and state, with practical guidance for SMB owners to improve their security posture.