This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.
Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.
As we collect more data, we will plot changes over time.
Statistic summary for Wednesday May 16th 2012. 21673 distinct hosts.| Header | # of Hosts | ||
|---|---|---|---|
| Content-Type | 21673 | ||
| Date | 21624 | ||
| Server | 21365 | ||
| Connection | 18567 | ||
| Set-Cookie | 16338 | ||
| X-Powered-By | 12684 | ||
| Cache-Control | 10951 | ||
| Content-Length | 8204 | ||
| Expires | 7890 | ||
| Last-Modified | 7381 | ||
| Vary | 6862 | ||
| Pragma | 6118 | ||
| Accept-Ranges | 4701 | ||
| ETag | 4640 | ||
| X-Pingback | 3363 | ||
| P3P | 1669 | ||
| X-AspNet-Version | 1265 | ||
| X-XSS-Protection | 859 | ||
| X-Content-Type-Options | 846 | ||
| Content-Location | 663 | ||
| Link | 617 | ||
| X-Cache | 412 | ||
| Content-Language | 376 | ||
| Via | 355 | ||
| Age | 294 | ||
| X-UA-Compatible | 242 | ||
| X-Varnish | 185 | ||
| X-Hacker | 162 | ||
| MicrosoftOfficeWebServer | 155 | ||
| Keep-Alive | 140 | ||
| Status | 135 | ||
| X-Pad | 131 | ||
| WP-Super-Cache | 125 | ||
| X-Runtime | 114 | ||
| X-Tumblr-Usec | 95 | ||
| X-Tumblr-User | 95 | ||
| X-Cache-Lookup | 73 | ||
| X-FRAME-OPTIONS | 70 | ||
| X-Nananana | 69 | ||
| X-Powered-By-Plesk | 64 | ||
| MS-Author-Via | 62 | ||
| X-AspNetMvc-Version | 62 | ||
| X-Generator | 54 | ||
| X-Powered-CMS | 52 | ||
| X-Server | 49 | ||
| X-Cnection | 45 | ||
| X-Drupal-Cache | 41 | ||
| X-Cacheable | 37 | ||
| X-Host | 37 | ||
| X-XRDS-Location | 36 | ||
| X-Mod-Pagespeed | 32 | ||
| X-Webserver | 29 | ||
| X-PhApp | 29 | ||
| X-XN-Trace-Token | 27 | ||
| X-XN-XNHTML | 27 | ||
| X-ServedBy | 26 | ||
| X-INKT-SITE | 26 | ||
| Content-Encoding | 26 | ||
| X-INKT-URI | 26 | ||
| X-Mobilized-By | 26 | ||
| Composed-By | 25 | ||
| Served-By | 25 | ||
| X-Robots-Tag | 25 | ||
| MicrosoftSharePointTeamServices | 23 | ||
| Refresh | 20 | ||
| Content-Script-Type | 17 | ||
| Access-Control-Allow-Origin | 17 | ||
| X-Rack-Cache | 16 | ||
| X-Check | 15 | ||
| X-Language | 15 | ||
| X-Template | 15 | ||
| X-Request-Id | 13 | ||
| IISExport | 13 | ||
| X-Cache-Hits | 12 | ||
| X-CF-Powered-By | 11 | ||
| X-BackEnd | 11 | ||
| X-Served-By | 11 | ||
| X-SharePointHealthScore | 11 | ||
| SPRequestGuid | 11 | ||
| X-Firenze-Processing-Times | 11 | ||
| Content-Style-Type | 10 | ||
| X-Whom | 10 | ||
| X-Drectory-Script | 10 | ||
| Imagetoolbar | 9 | ||
| X-Umbraco-Version | 9 | ||
| X-Outils-CS | 9 | ||
| X-Cache-Server | 8 | ||
| X-Alternate-Cache-Key | 8 | ||
| PICS-Label | 8 | ||
| X-Matrix-Server | 8 | ||
| Xonnection | 7 | ||
| X-Type | 7 | ||
| TCN | 7 | ||
| X-Cache-Group | 7 | ||
| Page-Completion-Status | 7 | ||
| X-Secret | 7 | ||
| Cm-Server | 6 | ||
| X-Server-Name | 6 | ||
| Liferay-Portal | 6 | ||
| X-FB-Debug | 6 | ||
| X-Matrix-Proxy | 6 | ||
| X-PHP-Engine | 5 | ||
| X-Loop | 5 | ||
| X-TN-ServedBy | 5 | ||
| Real-Hostname | 5 | ||
| X-Cache-Info | 5 | ||
| X-Enhanced-By | 5 | ||
| X-PWb-Node | 5 | ||
| X-AH-Environment | 5 | ||
| NS-RTIMER-COMPOSITE | 5 | ||
| X-PosterousHostName | 5 | ||
| X-GitSHA | 5 | ||
| X-DDC-Arch-Trace | 5 | ||
| X-RateLimit-Remaining | 5 | ||
| X-RateLimit-Limit | 5 | ||
| Generator | 5 | ||
| COMMERCE-SERVER-SOFTWARE | 5 | ||
| Powered-By-ChinaCache | 5 | ||
| X-Amz-Id-2 | 4 | ||
| Cartoon | 4 | ||
| X-Haiku | 4 | ||
| X-ELC-Checkpoint4 | 4 | ||
| Access-Control-Allow-Headers | 4 | ||
| B-Powered-By | 4 | ||
| MIME-Version | 4 | ||
| X-Px | 4 | ||
| X-CJ-Soft | 4 | ||
| X-GLaDOS | 4 | ||
| IBM-Web2-Location | 4 | ||
| X-Amz-Request-Id | 4 | ||
| Location | 4 | ||
| X-PF-Uncompressing | 4 | ||
| X-Cache-Control-Orig | 3 | ||
| X-Wily-Servlet | 3 | ||
| Access-Control-Allow-Methods | 3 | ||
| X-Bettercache-Proxy | 3 | ||
| X-Wily-Info | 3 | ||
| X-TNCMS-Memory-Usage | 3 | ||
| X-Object-Id | 3 | ||
| Wn-Vars | 3 | ||
| X-Expires-Orig | 3 | ||
| From | 3 | ||
| Content-Disposition | 3 | ||
| X-TNCMS-Render-Time | 3 | ||
| X-Generated-By | 3 | ||
| X-Object-Type | 3 | ||
| SynthaSite-ID | 3 | ||
| X-EdgeRouter | 3 | ||
| Lsrequestid | 3 | ||
| X-TNCMS-Version | 3 | ||
| Thanks | 3 | ||
| WN | 3 | ||
| CP | 3 | ||
| Railo-Version | 3 | ||
| X-Content-Encoded-By | 3 | ||
| X-Grid-Server | 3 | ||
| Loadtime-Newsletter | 3 | ||
| X-Page-Speed | 3 | ||
| X-Cdn | 3 | ||
| X-Yadis-Location | 3 | ||
| X-TNCMS-Served-By | 3 | ||
| X-Frontend | 2 | ||
| X-MJ-Serve-Req-Time | 2 | ||
| ServerName | 2 | ||
| X-Cache-Control | 2 | ||
| Page.Ly | 2 | ||
| Progma | 2 | ||
| X-SATserver | 2 | ||
| X-MJ-Upstream-Addr | 2 | ||
| ProxiaInstanceId | 2 | ||
| X-Blog | 2 | ||
| X-UPSTREAM | 2 | ||
| X-PvInfo | 2 | ||
| SN | 2 | ||
| X-Cached-By | 2 | ||
| X-GC-App | 2 | ||
| X-Server-IP | 2 | ||
| X-Varnish-IP | 2 | ||
| Node | 2 | ||
| X-Wix-Renderer-Server | 2 | ||
| Powered-By | 2 | ||
| CCEncrypt | 2 | ||
| X-Software-Info | 2 | ||
| X-GC-Read | 2 | ||
| X-Varnish-Cache | 2 | ||
| Content-Base | 2 | ||
| Content | 2 | ||
| X-Nginx-IP | 2 | ||
| X-Firenze-Processing-Time | 2 | ||
| Uniqueid | 2 | ||
| X-DeliveryServer | 2 | ||
| X-REDIRECTSERVER | 2 | ||
| Surrogate-Control | 2 | ||
| Warning | 2 | ||
| Proxy-Connection | 2 | ||
| Req-Timestamp | 2 | ||
| X-GC-Write | 2 | ||
| X-Seen-By | 2 | ||
| Access-Control-Max-Age | 2 | ||
| X-Vtex-Cache-Key | 2 | ||
| X-MSG-06 | 2 | ||
| D | 2 | ||
| X-MSG-05 | 2 | ||
| X-StoreSense | 2 | ||
| X-MSG-04 | 2 | ||
| X-Tiger-TTFB | 2 | ||
| X-ProStores-StoreApiEntryPoint | 2 | ||
| X-S | 2 | ||
| Iinfo | 2 | ||
| X-Vtex-Remote-Cache | 2 | ||
| WS | 2 | ||
| DeleGate-Ver | 2 | ||
| X-MSG-03 | 2 | ||
| X-MSG-02 | 2 | ||
| X-MSG-01 | 2 | ||
| X-MSG-00 | 2 | ||
| X-DEBUG-X-Id | 2 | ||
| No | 2 | ||
| MASTERWEBLET | 2 | ||
| X-Phpwcms-Page-Processed-In | 2 | ||
| X-Phpwcms-Release | 2 | ||
| X-Vary-Options | 2 | ||
| X-Session-Reinit | 2 | ||
| ServerID | 2 | ||
| X-App-Server | 2 | ||
| X-UD-Host | 2 | ||
| X-Beatles | 2 | ||
| X-Content-Digest | 2 | ||
| WP-Cache | 2 | ||
| X-Info | 2 | ||
| X-Server-Id | 2 | ||
| S | 2 | ||
| X-UD-Target | 2 | ||
| X-UD-Method | 2 | ||
| Cache | 2 | ||
| X-It-Host-Id | 1 | ||
| X-SID | 1 | ||
| MW-Server | 1 | ||
| Www.Oyuncuadresi.Com | 1 | ||
| X-LAvg | 1 | ||
| X-Served-By-Node | 1 | ||
| X-Varnish-Machine | 1 | ||
| X-TTL | 1 | ||
| X-Description | 1 | ||
| X-Avvio-Cms-Cacheload | 1 | ||
| X-COOKIEWAS3 | 1 | ||
| X-Accelerated-By | 1 | ||
| MWHOST | 1 | ||
| X-ApacheHost | 1 | ||
| X-Stopwatch | 1 | ||
| X-CMS-Version | 1 | ||
| X-Hostname | 1 | ||
| Cache-Expires | 1 | ||
| X-AspNetWebPages-Version | 1 | ||
| Kp-EeAlive | 1 | ||
| X-DIP | 1 | ||
| PowerCDN | 1 | ||
| X-PageId | 1 | ||
| X-PoweredBy | 1 | ||
| MyServer | 1 | ||
| X-NOCOOKIEFOUND | 1 | ||
| X-Server-By | 1 | ||
| X-Zone | 1 | ||
| X-Achmed-Status | 1 | ||
| Robots | 1 | ||
| X-Secoya-Server | 1 | ||
| Varnish-Active | 1 | ||
| X-Cache-Hit | 1 | ||
| X-IsMobileHost | 1 | ||
| X-IsFrontPageReq | 1 | ||
| X-Cocoon-Version | 1 | ||
| X-Powered-S | 1 | ||
| X-Catalyst | 1 | ||
| UniqueName | 1 | ||
| X-Which-Box | 1 | ||
| X-Country-Name | 1 | ||
| X-Country | 1 | ||
| X-Debug-Serve | 1 | ||
| Last-Updated | 1 | ||
| X-Version | 1 | ||
| X-Pb-Mii | 1 | ||
| X-DoRedirect | 1 | ||
| Response-Server | 1 | ||
| Response-File | 1 | ||
| X-Bak | 1 | ||
| X-Server-Admins | 1 | ||
| X-Cache-Action | 1 | ||
| ZoogleHost | 1 | ||
| X-Url | 1 | ||
| X-RE-Ref | 1 | ||
| X-Set-Cookie | 1 | ||
| X-VarnishNode | 1 | ||
| Nodo | 1 | ||
| X-Original-At | 1 | ||
| X-DEBUG-Obj-Ttl | 1 | ||
| Noahs-Classifieds | 1 | ||
| A-Powered-By | 1 | ||
| X-DOTLAN-License | 1 | ||
| X-DOTLAN-Version | 1 | ||
| GP-NGX | 1 | ||
| X-WLD-LB | 1 | ||
| X-Permitted-Cross-Domain-Policies | 1 | ||
| QYSID | 1 | ||
| X-WhitelistedCookie | 1 | ||
| X-From | 1 | ||
| X-Analytics-Terminal | 1 | ||
| X-Node | 1 | ||
| X-BServer | 1 | ||
| Tempo | 1 | ||
| Timing | 1 | ||
| X-Content-Parsed-By | 1 | ||
| X-PC3-Time | 1 | ||
| X-PC3-Control | 1 | ||
| X-Cache-Timing | 1 | ||
| Servlet-Engine | 1 | ||
| Il-Cl | 1 | ||
| X-Amz-Meta-S3cmd-Attrs | 1 | ||
| Server-Hostname | 1 | ||
| X-Served2-By | 1 | ||
| X-SUP-ID | 1 | ||
| X-CMS-Powered-By | 1 | ||
| X-From-Pagecache | 1 | ||
| XServer | 1 | ||
| SOSLoc | 1 | ||
| X-DotDefender-Denied | 1 | ||
| ScoreTracker | 1 | ||
| X-Highwire-SessionId | 1 | ||
| X-Libsyn-Host | 1 | ||
| X-Varnish-Age | 1 | ||
| X-Header-Set-Id | 1 | ||
| X-Caching-Rule-Id | 1 | ||
| X-ApacheServer | 1 | ||
| Gzip | 1 | ||
| Hacked | 1 | ||
| ROCKandREVIEW.Com | 1 | ||
| Lytee-CME-Version | 1 | ||
| Lytee-Server | 1 | ||
| X-Adobe-Content | 1 | ||
| X-Highwire-RequestId | 1 | ||
| With | 1 | ||
| HOST-SERVICE | 1 | ||
| X-Hrouter | 1 | ||
| THIELI-VERSION | 1 | ||
| X-Question | 1 | ||
| X-Answer | 1 | ||
| X-CAPP-PROFILING | 1 | ||
| X-Generate | 1 | ||
| X-Expires | 1 | ||
| WCSITE | 1 | ||
| Adepteo | 1 | ||
| WSID | 1 | ||
| X-I | 1 | ||
| UNIQUE-ID | 1 | ||
| X-Framework | 1 | ||
| X-CacheServer | 1 | ||
| X-Id | 1 | ||
| X-Request-Duration | 1 | ||
| X-Original-Request | 1 | ||
| Title | 1 | ||
| X-Confluence-Request-Time | 1 | ||
| X-Duration | 1 | ||
| Content-MD5 | 1 | ||
| X-Server-Oad | 1 | ||
| X-Handled-By | 1 | ||
| Webserver | 1 | ||
| X-Responding-Server | 1 | ||
| Z-Powered-By | 1 | ||
| Accept | 1 | ||
| X-Time-Microsecs | 1 | ||
| X-Empowered-By | 1 | ||
| X3CMS-Release | 1 | ||
| ZEONWEB-Cluster | 1 | ||
| Beyond-Iis | 1 | ||
| Page | 1 | ||
| X-CacheHits | 1 | ||
| X-VarnishServer | 1 | ||
| X-Database-Slave-Connection | 1 | ||
| X-AWS-Id | 1 | ||
| If-Modified-Since | 1 | ||
| CachedXSLT | 1 | ||
| PROPSON-FARM | 1 | ||
| X-FIRSTPAGE | 1 | ||
| X-Passed-To-DLL | 1 | ||
| X-End | 1 | ||
| WP-AdvCache-MemCached | 1 | ||
| Centent-Type | 1 | ||
| X-Who-O | 1 | ||
| X-Fueled-By | 1 | ||
| Backend-INFRA.WAN | 1 | ||
| X-20M-Cache | 1 | ||
| X-PCS-TTL | 1 | ||
| X-Ziosting-Rule | 1 | ||
| X-Who-L | 1 | ||
| User-Agent | 1 | ||
| X-Beta | 1 | ||
| X-Origin-Srv | 1 | ||
| X-Who | 1 | ||
| X-AP-Version | 1 | ||
| X-AWCMS-Version | 1 | ||
| X-Portal | 1 | ||
| WP-KEY | 1 | ||
| Filter-Revision | 1 | ||
| X-Euro-ID | 1 | ||
| X-Account-Management-Status | 1 | ||
| Engine-Programming | 1 | ||
| Web3 | 1 | ||
| X-Passed-To | 1 | ||
| Cluster | 1 | ||
| Pagename | 1 | ||
| Response | 1 | ||
| X-Bstat | 1 | ||
| X-Country-Code | 1 | ||
| SVR | 1 | ||
| X-PH-Magento-Cache | 1 | ||
| WhoisCache | 1 | ||
| X-SW | 1 | ||
| Last-UpdatedL | 1 | ||
| Cache-Ctrol | 1 | ||
| X-Wf-Protocol-1 | 1 | ||
| X-Varnish-Hits | 1 | ||
| X-Back | 1 | ||
| X-Aliases | 1 | ||
| Wwwcr.Mossgreen.Com.Au | 1 | ||
| X-Artvisual-Server | 1 | ||
| Hola | 1 | ||
| X-Purge-URL | 1 | ||
| X-Ws | 1 | ||
| X-Accelance-Front | 1 | ||
| X-Purge-Host | 1 | ||
| X-RCR | 1 | ||
| Login-Required | 1 | ||
| Hostedby | 1 | ||
| X-Abuse | 1 | ||
| P3P:CP | 1 | ||
| VTag | 1 | ||
| Cluster-Node | 1 | ||
| X-Wf-1-Structure-1 | 1 | ||
| X-Varnish-Backend | 1 | ||
| X-Origin | 1 | ||
| Www.Mossgreen.Com.Au | 1 | ||
| NLCacheNote | 1 | ||
| X-ODL-Server | 1 | ||
| X-QueryRuntime | 1 | ||
| X-Cached | 1 | ||
| X-Ruby-Cluster-ID | 1 | ||
| CDCHOST | 1 | ||
| X-Actual-URL | 1 | ||
| X-DmUser | 1 | ||
| X-SSS-Version | 1 | ||
| No-Cache | 1 | ||
| LibAstro | 1 | ||
| X-Cache2 | 1 | ||
| X-Papaya-Gzip | 1 | ||
| X-Invocation-Time | 1 | ||
| Loadtime-SocialMedia | 1 | ||
| X-PBY | 1 | ||
| .Woff | 1 | ||
| Loadtime-PropertyFeature | 1 | ||
| Apache | 1 | ||
| X-Debug | 1 | ||
| Application-Version | 1 | ||
| .Svg | 1 | ||
| X-QueryCount | 1 | ||
| X-Varnish-Hostname | 1 | ||
| X-Real-Server | 1 | ||
| X-Site | 1 | ||
| X-Developer | 1 | ||
| X-Realserver | 1 | ||
| SL-NOREWRITE-REDIRECTS | 1 | ||
| X-Papaya-Cache | 1 | ||
| Vala | 1 | ||
| Srv | 1 | ||
| Cluster-Id | 1 | ||
| X-CFRH | 1 | ||
| X-MTX-DBCache[C-Pri-1926] | 1 | ||
| X-UA-Comatible | 1 | ||
| X-SRV | 1 | ||
| Web-Hostname | 1 | ||
| X-Wf-1-Plugin-1 | 1 | ||
| X-Gentics | 1 | ||
| X-FreeTag-Count | 1 | ||
| ProxyTime | 1 | ||
| X-App-Hosting | 1 | ||
| Mossgreen.Com.Au | 1 | ||
| X-Wm-1 | 1 | ||
| X-LiteSpeed-Cache | 1 | ||
| Server-N | 1 | ||
| Origin | 1 | ||
| X-CFRM2 | 1 | ||
| ContentType | 1 | ||
| X-Accel-Version | 1 | ||
| Cache-Key | 1 | ||
| X-MTX-DBCache[C-1899] | 1 | ||
| X-Backend-Server | 1 | ||
| 0 | 1 | ||
| X-Wf-1-1-1-1 | 1 | ||
| X-Cache-NHIT | 1 | ||
| ProxyServer | 1 | ||
| X-N | 1 | ||
| PFHOST | 1 | ||
| X-Test | 1 | ||
| Infra | 1 | ||
| ASTrefflag | 1 | ||
| X-Head | 1 | ||
| X-ACMCache | 1 | ||
| Req-Id | 1 | ||
| X-Content-Security-Policy | 1 | ||
| Hits | 1 | ||
| Rating | 1 | ||
| Content-Description | 1 | ||
| X-Via | 1 | ||
| X-MCB-Server | 1 | ||
| Product-Version | 1 | ||
| X-SmugMug-Hiring | 1 | ||
| X-Oad-Xslt | 1 | ||
| X-SmugMug-Values | 1 | ||
| X-Source-Host | 1 | ||
| X-Hosted-By | 1 | ||
| Expire | 1 | ||
| X-Powered-By-Home.Pl | 1 | ||
| Charset | 1 | ||
| X-Track | 1 | ||
| X-Hit-Cache | 1 | ||
| Provider | 1 | ||
| X-Forwarded-For | 1 | ||
| Host | 1 | ||
| Content-Transfer-Encoding | 1 | ||
| CommunityServer | 1 | ||
| X-MS-InvokeApp | 1 | ||
| Accept-Encoding | 1 | ||
| X-Snapsis-PageBlaster | 1 | ||
| Vserver | 1 | ||
| X-Front | 1 | ||
| X-User-Agent | 1 | ||
| Accept-Charset | 1 | ||
| X-Cache-Expires | 1 | ||
| X-GAMECOUNTRY | 1 | ||
| MST-Version | 1 | ||
| X-Origin-Id | 1 | ||
| X-UD-Loopcounter | 1 | ||
| X-Eznode | 1 | ||
| Db | 1 | ||
| X-Nikon-Host | 1 | ||
| X-Re-Srv | 1 | ||
| X-Disclaimer | 1 | ||
| X-Matchfwd-Misc | 1 | ||
| X-Ants-Machine-Id | 1 | ||
| X-Confirmit-ID | 1 | ||
| X-USERCOUNTRY | 1 | ||
| Reply-To | 1 | ||
| Hishop | 1 | ||
| X-VWS-Id | 1 | ||
| X-Returned-From-DLL | 1 | ||
| X-Returned-From | 1 | ||
| X-Apache-IP | 1 | ||
| X-Gateway | 1 | ||
| WEBO | 1 | ||
| Version | 1 | ||
| X-20M-WebServer | 1 | ||
| X-Filmed-By | 1 | ||
| Proxy-Agent | 1 | ||
| X-Web-Hosting-Service-Provider | 1 | ||
| X-Matchfwd-GenTime | 1 | ||
| X-Sportal-Origin | 1 | ||
| Stylesheets | 1 | ||
| X-PAGE | 1 | ||
| Type | 1 | ||
| X-Header | 1 | ||
| X-Cache-Debug | 1 | ||
| X-CF | 1 | ||
| ERROR | 1 | ||
| X-Sitemap-URL | 1 | ||
| X-MTX-DBCache[C-1898] | 1 | ||
| X-Stackable-Node | 1 | ||
| X-Instance-Name | 1 | ||
| Is-Cached | 1 | ||
| AppTime | 1 | ||
| X-FW | 1 | ||
| X-PE-Server: | 1 | ||
| Hostname | 1 | ||
| ASTadv | 1 | ||
| X-Powered-WP | 1 | ||
| Server-Name | 1 | ||
| X-Stat-Server | 1 | ||
| X-ServerID | 1 | ||
| Nectar | 1 | ||
| Response-Type | 1 | ||
| X-UD-REMOTE-ADDR | 1 | ||
| X-Metrix-Cachesite | 1 | ||
| X-Machine-ID | 1 | ||
| X-RSS-CACHE-STATUS | 1 | ||
| X-XTM-Node | 1 | ||
| X-HN | 1 | ||
| AppServer | 1 | ||
| X-USERIP | 1 | ||
| X-Amz-Cf-Id | 1 | ||
| X-Oracle-DMS-ECID | 1 | ||
| SmartCDS | 1 | ||

