Website Health Report Q3 2026
We measured 236 live websites continuously between 16 June 2026 – 14 September 2026 and aggregated what we found. Only 3.5% set all six standard security headers, and 91.9% miss the 2.5 second mobile Largest Contentful Paint threshold — the median site takes 7.2 seconds. Every figure below carries its sample size, and the data is free to quote with attribution.
Security headers
Every site was measured on the six response headers a browser actually acts on. Adoption is far lower than the security industry's guidance implies.
Only 3.5% of websites set all six standard security headers.
The full set is free to add and takes one server config change, yet almost nobody completes it.
Sample: 226 sites, latest check each · How we monitor this
57.1% of websites send a Content-Security-Policy header.
CSP is the most adopted of the six — and still nearly half of sites go without.
Sample: 226 sites · How we monitor this
30.1% of websites send HTTP Strict-Transport-Security.
Without HSTS a first visit over plain HTTP can still be intercepted, even on a site with a valid certificate.
Sample: 226 sites · How we monitor this
Only 8.8% of websites set a Permissions-Policy header.
The least adopted header of the six, and the one most often missing from hosting defaults.
Sample: 226 sites · How we monitor this
15.5% set X-Frame-Options, 34.1% set Referrer-Policy and 36.3% set X-Content-Type-Options.
Clickjacking and MIME-sniffing protections are the most commonly forgotten of all.
Sample: 226 sites · How we monitor this
Just 2.7% of websites earn an A grade on their security headers overall.
Header grading is the cheapest security win available, and it is almost universally left on the table.
Sample: 226 sites · How we monitor this
TLS certificates
Certificate configuration is in much better shape than headers — automated renewal has clearly worked — but the tail is still real.
65.8% of websites score an A or A+ on their TLS configuration.
Certificates are the one area where defaults have genuinely improved the baseline.
Sample: 236 sites · How we monitor this
The median TLS configuration score is 95 out of 100.
Most remaining deductions come from protocol and cipher support, not from expiry — the opposite of what teams monitor for.
Sample: 236 sites · How we monitor this
Domain expiry
A lapsed domain takes a site down more completely than any server fault, and unlike a certificate it is rarely renewed automatically.
3.3% of domains are within 30 days of expiry at any given moment.
Roughly one domain in thirty is a month away from going dark, usually without anyone on the team knowing.
Sample: 235 domains, latest lookup each · How we monitor this
Mobile performance
Measured with Lighthouse against the mobile profile, which is the profile Google ranks on. These are the hardest numbers in the report to look at.
The median mobile performance score is 59 out of 100; on desktop it is 76.
The typical site is a passable desktop experience and a failing mobile one.
Sample: 1,496 Lighthouse runs · How we monitor this
91.9% of websites exceed the 2.5 second Largest Contentful Paint threshold on mobile.
Core Web Vitals' headline metric is failed by nine sites in ten — the pass rate, not the failure rate, is the anomaly.
Sample: 658 mobile runs · How we monitor this
The median mobile Largest Contentful Paint is 7.2 seconds — nearly three times the threshold.
Not a near miss. The typical mobile visitor waits over seven seconds for the main content.
Sample: 658 mobile runs · How we monitor this
17.2% of websites have a Cumulative Layout Shift above 0.1 on mobile.
Layout stability is the one Core Web Vital most sites already pass.
Sample: 1,496 Lighthouse runs · How we monitor this
How we measured this
Every figure is an aggregate over checks Lemwatch already ran for paying and free accounts between 16 June 2026 – 14 September 2026. Sites are counted once: where a site was checked many times, we take its most recent result so that heavily monitored sites cannot skew a percentage. Performance figures are Lighthouse runs and are reported per run, not per site, because the same site is legitimately measured on both mobile and desktop.
No customer, domain, URL or account identifier appears in this report, and none is used to produce it. The published output is counts and percentages only.
What we deliberately left out. Outage duration and mean time to recovery: only one incident in the window had a verified resolution timestamp, and one observation is not a statistic. DNSSEC adoption: the field is not reliably populated by our collector. Sitemap breakage rates: 22 distinct sitemaps is too small a sample to publish. We would rather ship four sections we can stand behind than eight we cannot.
Sample bias, stated plainly. These are sites someone chose to monitor, which skews toward small business, agency-managed and SaaS properties rather than the largest sites on the web. Read the numbers as a picture of the long tail, not of the Fortune 500.
Citing this report
Free to reuse, including commercially, with a link back. Suggested citation:
Lemwatch, "Website Health Report Q3 2026", 2026-09-14. https://lemwatch.com/research/website-health-report
13 statistics in this edition. Updated quarterly; the next edition covers October to December 2026.
See where your own site lands
Headers, certificate, domain expiry and mobile speed, checked against the same benchmarks used in this report.

