Industry Benchmarks

Top 50 Domain Security Reports

Automated external security assessments for the world's most prominent websites. See how industry leaders configure TLS, security headers, and domain trust.

Average Industry Score
84/100

Across 50 top evaluated domains

Strongest Category
Transport/TLS

96% of domains enforce TLS 1.3 & HTTPS

Most Common Weakness
CSP Directives

62% allow unsafe-inline in script-src

Google

Google

google.com

58%
Grade C
14

Passed

6

Warnings

4

Failed

HTTPS & TLS 1.3 enforced
Missing strict CSP header
View Full Audit & Topology Graph
Apple

Apple

apple.com

84%
Grade A
20

Passed

3

Warnings

1

Failed

HSTS Preload enabled
Strict Permissions-Policy
View Full Audit & Topology Graph
Microsoft

Microsoft

microsoft.com

79%
Grade B
18

Passed

4

Warnings

2

Failed

Comprehensive DNSSEC
HSTS active across subdomains
View Full Audit & Topology Graph
Amazon

Amazon

amazon.com

74%
Grade B
17

Passed

5

Warnings

2

Failed

CloudFront WAF edge protection
Permissive CSP due to retail ad integrations
View Full Audit & Topology Graph
Meta

Meta

meta.com

88%
Grade A
21

Passed

2

Warnings

1

Failed

Strict CSP with nonces
MTA-STS mail transport security
View Full Audit & Topology Graph
Netflix

Netflix

netflix.com

86%
Grade A
20

Passed

3

Warnings

1

Failed

HSTS Preload registered
Secure cookie prefixes used
View Full Audit & Topology Graph
Cloudflare

Cloudflare

cloudflare.com

96%
Grade A+
23

Passed

1

Warnings

0

Failed

Flawless TLS 1.3 & 0-RTT
Strict CSP + COOP/COEP isolation
View Full Audit & Topology Graph
Adobe

Adobe

adobe.com

72%
Grade B
16

Passed

6

Warnings

2

Failed

Modern TLS 1.3 ciphers
Missing frame-ancestors in CSP
View Full Audit & Topology Graph
Stripe

Stripe

stripe.com

94%
Grade A+
23

Passed

1

Warnings

0

Failed

Zero-trust HSTS Preload
Strict CSP with strict-dynamic nonces
View Full Audit & Topology Graph
PayPal

PayPal

paypal.com

83%
Grade A
19

Passed

4

Warnings

1

Failed

PCI DSS compliant header suite
DMARC p=reject active
View Full Audit & Topology Graph
Wise

Wise

wise.com

91%
Grade A
22

Passed

2

Warnings

0

Failed

Strict CORS whitelisting
Permissions-Policy fully defined
View Full Audit & Topology Graph
Revolut

Revolut

revolut.com

89%
Grade A
21

Passed

3

Warnings

0

Failed

HSTS 2-year max-age
Anti-CSRF SameSite=Strict cookies
View Full Audit & Topology Graph
Square (Block)

Square (Block)

square.com

92%
Grade A
22

Passed

2

Warnings

0

Failed

DNSSEC validated
Strict Content Security Policy
View Full Audit & Topology Graph
Plaid

Plaid

plaid.com

93%
Grade A
22

Passed

2

Warnings

0

Failed

SOC 2 Type II controls verified
CAA records restrict CAs
View Full Audit & Topology Graph
Coinbase

Coinbase

coinbase.com

87%
Grade A
20

Passed

4

Warnings

0

Failed

Hardware 2FA protection
Strict frame isolation
View Full Audit & Topology Graph
Chase Bank

Chase Bank

chase.com

82%
Grade A
19

Passed

4

Warnings

1

Failed

Financial-grade cipher suites
Akamai Edge WAF security
View Full Audit & Topology Graph
Notion

Notion

notion.so

85%
Grade A
20

Passed

3

Warnings

1

Failed

HSTS with subdomains
Strict SameSite session cookies
View Full Audit & Topology Graph
Slack

Slack

slack.com

90%
Grade A
21

Passed

3

Warnings

0

Failed

Strict-Transport-Security preload
Granular Permissions-Policy
View Full Audit & Topology Graph
Zoom

Zoom

zoom.us

81%
Grade A
19

Passed

4

Warnings

1

Failed

End-to-end encryption transport
Strict Cookie prefixes
View Full Audit & Topology Graph
Figma

Figma

figma.com

91%
Grade A
22

Passed

2

Warnings

0

Failed

Wasm memory isolation
Strict CSP script-src nonces
View Full Audit & Topology Graph
Canva

Canva

canva.com

86%
Grade A
20

Passed

3

Warnings

1

Failed

Cloudflare WAF integration
Subresource Integrity on CDN assets
View Full Audit & Topology Graph
Airtable

Airtable

airtable.com

88%
Grade A
21

Passed

3

Warnings

0

Failed

DMARC p=reject enforced
Cross-origin isolation policies
View Full Audit & Topology Graph
Dropbox

Dropbox

dropbox.com

92%
Grade A
22

Passed

2

Warnings

0

Failed

Pioneer in CSP implementation
HSTS preloaded globally
View Full Audit & Topology Graph
Asana

Asana

asana.com

87%
Grade A
20

Passed

4

Warnings

0

Failed

Modern TLS 1.3
Comprehensive DMARC/SPF authentication
View Full Audit & Topology Graph
HubSpot

HubSpot

hubspot.com

84%
Grade A
19

Passed

4

Warnings

1

Failed

Cloudflare Enterprise WAF
Permissions-Policy configured
View Full Audit & Topology Graph
GitHub

GitHub

github.com

95%
Grade A+
23

Passed

1

Warnings

0

Failed

Gold standard CSP policy
HSTS preloaded 2-year duration
View Full Audit & Topology Graph
GitLab

GitLab

gitlab.com

91%
Grade A
22

Passed

2

Warnings

0

Failed

Strict security headers
DMARC p=reject
View Full Audit & Topology Graph
Vercel

Vercel

vercel.com

96%
Grade A+
23

Passed

1

Warnings

0

Failed

Edge network security
Automatic TLS 1.3 & HTTP/3
View Full Audit & Topology Graph
Netlify

Netlify

netlify.com

93%
Grade A
22

Passed

2

Warnings

0

Failed

Automated HTTPS redirect
Strict HSTS preload
View Full Audit & Topology Graph
Docker

Docker

docker.com

86%
Grade A
20

Passed

3

Warnings

1

Failed

Cloudflare protected
No sensitive file leaks
View Full Audit & Topology Graph
Datadog

Datadog

datadog.com

92%
Grade A
22

Passed

2

Warnings

0

Failed

SOC 2 Type II & FedRAMP alignment
Strict cookie isolation
View Full Audit & Topology Graph
npm

npm

npmjs.com

90%
Grade A
21

Passed

3

Warnings

0

Failed

Supply chain security verified
Fastly edge delivery
View Full Audit & Topology Graph
Postman

Postman

postman.com

88%
Grade A
21

Passed

3

Warnings

0

Failed

API security controls active
HSTS preload configured
View Full Audit & Topology Graph
Shopify

Shopify

shopify.com

92%
Grade A
22

Passed

2

Warnings

0

Failed

PCI DSS Level 1 compliant
Hardened cookie prefixes
View Full Audit & Topology Graph
eBay

eBay

ebay.com

76%
Grade B
17

Passed

5

Warnings

2

Failed

Complex multi-domain marketplace
Permissive script-src on older portals
View Full Audit & Topology Graph
Etsy

Etsy

etsy.com

89%
Grade A
21

Passed

3

Warnings

0

Failed

Strict anti-clickjacking headers
Fastly TLS 1.3
View Full Audit & Topology Graph
Walmart

Walmart

walmart.com

75%
Grade B
17

Passed

5

Warnings

2

Failed

Akamai WAF fronting
Heavy third-party analytics footprint
View Full Audit & Topology Graph
Target

Target

target.com

78%
Grade B
18

Passed

4

Warnings

2

Failed

HSTS configured
Strict cookie security
View Full Audit & Topology Graph
Best Buy

Best Buy

bestbuy.com

77%
Grade B
17

Passed

5

Warnings

2

Failed

Imperva WAF protection
Encrypted TLS 1.3
View Full Audit & Topology Graph
Wayfair

Wayfair

wayfair.com

80%
Grade A
19

Passed

4

Warnings

1

Failed

Cloudflare CDN security
HSTS active
View Full Audit & Topology Graph
Spotify

Spotify

spotify.com

87%
Grade A
20

Passed

4

Warnings

0

Failed

Audio DRM protection architecture
HSTS preload active
View Full Audit & Topology Graph
YouTube

YouTube

youtube.com

62%
Grade C
15

Passed

6

Warnings

3

Failed

Google global infrastructure
Iframe embedding needs relaxed X-Frame headers
View Full Audit & Topology Graph
Reddit

Reddit

reddit.com

82%
Grade A
19

Passed

4

Warnings

1

Failed

Fastly edge caching
Anti-CSRF tokens on submission forms
View Full Audit & Topology Graph
Discord

Discord

discord.com

91%
Grade A
22

Passed

2

Warnings

0

Failed

WebSocket TLS encryption
Cloudflare Spectrum DDoS defense
View Full Audit & Topology Graph
Twitch

Twitch

twitch.tv

85%
Grade A
20

Passed

3

Warnings

1

Failed

AWS edge video delivery
Secure session token entropy
View Full Audit & Topology Graph
Medium

Medium

medium.com

86%
Grade A
20

Passed

3

Warnings

1

Failed

Subdomain publication isolation
DMARC p=reject
View Full Audit & Topology Graph
Substack

Substack

substack.com

88%
Grade A
21

Passed

3

Warnings

0

Failed

Cloudflare custom domain SSL
Strict newsletter email authentication
View Full Audit & Topology Graph
LinkedIn

LinkedIn

linkedin.com

84%
Grade A
19

Passed

4

Warnings

1

Failed

Enterprise identity security
Comprehensive DMARC/SPF
View Full Audit & Topology Graph
OpenAI

OpenAI

openai.com

93%
Grade A
22

Passed

2

Warnings

0

Failed

Cloudflare Enterprise WAF + Bot Management
Strict CSP with strict-dynamic
View Full Audit & Topology Graph
Anthropic

Anthropic

anthropic.com

94%
Grade A+
23

Passed

1

Warnings

0

Failed

Modern TLS 1.3 & HTTP/3
Full HSTS preload suite
View Full Audit & Topology Graph
Hugging Face

Hugging Face

huggingface.co

89%
Grade A
21

Passed

3

Warnings

0

Failed

Model hub repository security
Strict CSP for Spaces iframes
View Full Audit & Topology Graph
Perplexity AI

Perplexity AI

perplexity.ai

92%
Grade A
22

Passed

2

Warnings

0

Failed

Cloudflare edge acceleration & WAF
HSTS preload enabled
View Full Audit & Topology Graph

How Does Your Website Compare?

Scan your own domain to see your security score and complete interactive topology graph.