This barometer relies solely on our real operational data, aggregated at continental scale — no modeling, no extrapolation.
Loading real data…
Without this header, visitors remain exposed to HTTPS downgrade attacks on their first connection.
Without DMARC, nothing prevents an attacker from spoofing the domain for phishing campaigns targeting customers or partners.
Missing SPF makes it easier to send fraudulent emails impersonating the analyzed domain.
The server's real IP address is exposed directly on the internet, allowing any application-layer filtering to be bypassed.
An admin access point reachable from the internet is a prime target for brute-force attempts.
MySQL, MongoDB, or Elasticsearch reachable with no authentication from the outside — the equivalent of leaving the door wide open on customer, financial, or operational data.
An invalid certificate exposes users to man-in-the-middle attacks and undermines trust.
A free scan is all it takes to compare your exposure to these numbers, in minutes.
These numbers are recalculated continuously over a rolling 90-day window — not a static study, not a statistical extrapolation of the whole continent, just what we actually observe on the ground, updated in real time.