A 2026 study of 4,688 U.S. small-business websites found that 49.7% met none of seven security header criteria. HSTS was the most common header at 43.8% adoption, while X-Content-Type-Options: nosniff appeared on 39.7% of sites. Most other security headers showed poor adoption rates across the sampled directory-listed businesses.