Securing the Web: Analysis of HTTP Security Headers in Popular Global Websites
Urvashi Kishnani, Sanchari Das

TL;DR
This study analyzes HTTP security headers across 3,195 popular websites, revealing widespread weak security practices, especially in healthcare sites, and emphasizes the need for improved HTTPS implementation and security policies.
Contribution
The paper provides a comprehensive analysis of HTTP security header implementation on a large, diverse set of global websites, highlighting prevalent security deficiencies and offering targeted recommendations.
Findings
55.66% of websites received an 'F' security grade
Healthcare websites scored the lowest with an average of 18.14
Most websites showed weak implementation of CSP, HSTS, and SRI
Abstract
The surge in website attacks, including Denial of Service (DoS), Cross-Site Scripting (XSS), and Clickjacking, underscores the critical need for robust HTTPS implementation-a practice that, alarmingly, remains inadequately adopted. Regarding this, we analyzed HTTP security headers across N=3,195 globally popular websites. Initially, we employed automated categorization using Google NLP to organize these websites into functional categories and validated this categorization through manual verification using Symantec Sitereview. Subsequently, we assessed HTTPS implementation across these websites by analyzing security factors, including compliance with HTTP Strict Transport Security (HSTS) policies, Certificate Pinning practices, and other security postures using the Mozilla Observatory. Our analysis revealed over half of the websites examined (55.66%) received a dismal security grade of…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSocial Media and Politics · Hate Speech and Cyberbullying Detection
