ResearchIWSS · 2026

Italian Web Security Study

How is the Italian web
configured for security?

A large-scale passive measurement study of the externally observable security configuration of the .it subset in the Tranco top-1M dated July 8, 2026.

10.022.it domains in scope
10.020completed scans
8.829HTTP-reachable sites
87,3%TLS 1.3

Observed adoption of selected controls

41,8%X-Frame-Options
37,6%X-Content-Type-Options
32,8%HSTS
18,7%CSP
11,2%Permissions-Policy
2,4%security.txt

These percentages measure observable configuration, not the percentage of sites that are vulnerable.

A CSP header is not enough by itself

Among 1,646 Content Security Policies analyzed, only 11 matched the study's restrictive-policy criteria: default-src or script-src present, no unsafe-inline, no unsafe-eval and no wildcard sources.

11 / 1.646policies met the restrictive criteria

Primary sources

Full interactive analysis on f-hack

Perseo hosts this concise research summary. The complete interactive analysis, charts and detailed methodology live on f-hack, while the paper is archived on Zenodo.