Live Data

Security Trends Across 9,260 Websites

Aggregated insights from every free and paid security scan we've run. See the most common vulnerabilities and how the web stacks up.

9,260

Scans completed

32

Avg risk score

48%

Security Headers (of findings)

48,415

Total findings

9,200+ Websites scanned with ShipShield

48,400+vulnerabilities detected

Findings by Category

Size represents frequency. Color represents dominant severity.

Most Common Issues

Top findings ranked by how often they appear across all scans.

1.No security.txt found
Exposed Paths
info64%
2.Missing Permissions-Policy
Security Headers
low55%
3.Missing Content-Security-Policy (CSP)
Security Headers
high50%
4.Missing Referrer-Policy
Security Headers
low47%
5.No DMARC record found
Dns
medium45%
6.Missing X-Frame-Options
Security Headers
medium42%
7.Missing X-Content-Type-Options
Security Headers
medium37%
8.No SPF record found
Dns
medium35%
9.Detected technologies: Next.js, React
Technology
info25%
10.CORS allows all origins (wildcard *)
Cors
medium21%
11.Missing Strict-Transport-Security (HSTS)
Security Headers
high18%
12.X-Powered-By header exposed: Next.js
Server Info
low13%
13.Cookie "geo" missing HttpOnly flag
Cookies
medium6%
14.Cookie "geo" missing SameSite attribute
Cookies
low6%
15.Cookie "geo" missing Secure flag
Cookies
medium6%

Severity Distribution

Breakdown of all findings by severity level.

critical101 (0%)
high6,767 (14%)
medium19,240 (40%)
low12,368 (26%)
info9,842 (20%)

Only available with ShipShield ($25)

Go Deeper With a Full Codebase Audit

The free scan checks what's visible from the outside. A full ShipShield audit connects to your GitHub repo and analyzes your actual source code, dependencies, infrastructure, and more, covering 5,000,000+ vulnerability signatures.

Exposed Secrets

API keys, credentials, and tokens buried in code and git history

Auth & Authorization

Missing auth checks, weak JWT config, privilege escalation paths

Injection Vulnerabilities

SQL injection, XSS, SSRF, and command injection in your source code

Dependency CVEs

Known vulnerabilities across npm, pip, cargo, and go packages

AI Business Logic Review

AI-powered analysis of input validation, race conditions, and logic flaws

Sensitive Data Flows

PII logging, unencrypted data transmission, and storage issues

Infrastructure Security

Rate limiting, request size limits, and file upload restrictions

Docker & Container Scanning

Container misconfigs, exposed ports, running as root, OS-level CVEs

License Compliance

GPL/AGPL copyleft detection across all your dependencies

SBOM Generation

SPDX-format Software Bill of Materials for compliance and audits

Supply Chain Security

Typosquatting detection and suspicious package analysis

Professional PDF Report

Detailed findings with severity ratings, code references, and AI-powered fix suggestions

Get a Full Codebase Audit for $25

Scans complete in 2-8 minutes · Automatic refund if scan fails