Observed adoption of selected controls
41,8%X-Frame-Options
37,6%X-Content-Type-Options
32,8%HSTS
18,7%CSP
11,2%Permissions-Policy
2,4%security.txt
These percentages measure observable configuration, not the percentage of sites that are vulnerable.
Italian Web Security Study
A large-scale passive measurement study of the externally observable security configuration of the .it subset in the Tranco top-1M dated July 8, 2026.
These percentages measure observable configuration, not the percentage of sites that are vulnerable.
Among 1,646 Content Security Policies analyzed, only 11 matched the study's restrictive-policy criteria: default-src or script-src present, no unsafe-inline, no unsafe-eval and no wildcard sources.
Primary sources
Perseo hosts this concise research summary. The complete interactive analysis, charts and detailed methodology live on f-hack, while the paper is archived on Zenodo.