Original research · Q3 2026

    Website Health Report Q3 2026

    We measured 236 live websites continuously between 16 June 2026 – 14 September 2026 and aggregated what we found. Only 3.5% set all six standard security headers, and 91.9% miss the 2.5 second mobile Largest Contentful Paint threshold — the median site takes 7.2 seconds. Every figure below carries its sample size, and the data is free to quote with attribution.

    Security headers

    Every site was measured on the six response headers a browser actually acts on. Adoption is far lower than the security industry's guidance implies.

    3.5%

    Only 3.5% of websites set all six standard security headers.

    The full set is free to add and takes one server config change, yet almost nobody completes it.

    Sample: 226 sites, latest check each · How we monitor this

    57.1%

    57.1% of websites send a Content-Security-Policy header.

    CSP is the most adopted of the six — and still nearly half of sites go without.

    Sample: 226 sites · How we monitor this

    30.1%

    30.1% of websites send HTTP Strict-Transport-Security.

    Without HSTS a first visit over plain HTTP can still be intercepted, even on a site with a valid certificate.

    Sample: 226 sites · How we monitor this

    8.8%

    Only 8.8% of websites set a Permissions-Policy header.

    The least adopted header of the six, and the one most often missing from hosting defaults.

    Sample: 226 sites · How we monitor this

    15.5% / 34.1% / 36.3%

    15.5% set X-Frame-Options, 34.1% set Referrer-Policy and 36.3% set X-Content-Type-Options.

    Clickjacking and MIME-sniffing protections are the most commonly forgotten of all.

    Sample: 226 sites · How we monitor this

    2.7%

    Just 2.7% of websites earn an A grade on their security headers overall.

    Header grading is the cheapest security win available, and it is almost universally left on the table.

    Sample: 226 sites · How we monitor this

    TLS certificates

    Certificate configuration is in much better shape than headers — automated renewal has clearly worked — but the tail is still real.

    65.8%

    65.8% of websites score an A or A+ on their TLS configuration.

    Certificates are the one area where defaults have genuinely improved the baseline.

    Sample: 236 sites · How we monitor this

    95 / 100

    The median TLS configuration score is 95 out of 100.

    Most remaining deductions come from protocol and cipher support, not from expiry — the opposite of what teams monitor for.

    Sample: 236 sites · How we monitor this

    Domain expiry

    A lapsed domain takes a site down more completely than any server fault, and unlike a certificate it is rarely renewed automatically.

    3.3%

    3.3% of domains are within 30 days of expiry at any given moment.

    Roughly one domain in thirty is a month away from going dark, usually without anyone on the team knowing.

    Sample: 235 domains, latest lookup each · How we monitor this

    Mobile performance

    Measured with Lighthouse against the mobile profile, which is the profile Google ranks on. These are the hardest numbers in the report to look at.

    59 mobile / 76 desktop

    The median mobile performance score is 59 out of 100; on desktop it is 76.

    The typical site is a passable desktop experience and a failing mobile one.

    Sample: 1,496 Lighthouse runs · How we monitor this

    91.9%

    91.9% of websites exceed the 2.5 second Largest Contentful Paint threshold on mobile.

    Core Web Vitals' headline metric is failed by nine sites in ten — the pass rate, not the failure rate, is the anomaly.

    Sample: 658 mobile runs · How we monitor this

    7.2s

    The median mobile Largest Contentful Paint is 7.2 seconds — nearly three times the threshold.

    Not a near miss. The typical mobile visitor waits over seven seconds for the main content.

    Sample: 658 mobile runs · How we monitor this

    17.2%

    17.2% of websites have a Cumulative Layout Shift above 0.1 on mobile.

    Layout stability is the one Core Web Vital most sites already pass.

    Sample: 1,496 Lighthouse runs · How we monitor this

    How we measured this

    Every figure is an aggregate over checks Lemwatch already ran for paying and free accounts between 16 June 2026 – 14 September 2026. Sites are counted once: where a site was checked many times, we take its most recent result so that heavily monitored sites cannot skew a percentage. Performance figures are Lighthouse runs and are reported per run, not per site, because the same site is legitimately measured on both mobile and desktop.

    No customer, domain, URL or account identifier appears in this report, and none is used to produce it. The published output is counts and percentages only.

    What we deliberately left out. Outage duration and mean time to recovery: only one incident in the window had a verified resolution timestamp, and one observation is not a statistic. DNSSEC adoption: the field is not reliably populated by our collector. Sitemap breakage rates: 22 distinct sitemaps is too small a sample to publish. We would rather ship four sections we can stand behind than eight we cannot.

    Sample bias, stated plainly. These are sites someone chose to monitor, which skews toward small business, agency-managed and SaaS properties rather than the largest sites on the web. Read the numbers as a picture of the long tail, not of the Fortune 500.

    Citing this report

    Free to reuse, including commercially, with a link back. Suggested citation:

    Lemwatch, "Website Health Report Q3 2026", 2026-09-14.
    https://lemwatch.com/research/website-health-report

    13 statistics in this edition. Updated quarterly; the next edition covers October to December 2026.

    See where your own site lands

    Headers, certificate, domain expiry and mobile speed, checked against the same benchmarks used in this report.

    Check my site free
    Data collected and verified: by the Lemwatch research team.