Scott Helme
Security researcher who founded Report URI and has crawled the top million websites since 2016, measuring how the web actually adopts HTTPS, HSTS, CSP and the rest of the browser security toolkit. He writes the results up at scotthelme.co.uk.
Scott Helme did not write this page.
We collected these quotes from things they published elsewhere, and every quote links to where it was said. They have no account here and have not endorsed this site. Quotes are word for word; the short line under each one is our own restatement, not their wording. Their own site. Is this you? Claim it or ask us to remove it. Or tell us what is wrong here.
-
Their wordsThe web really is more secure than it was a decade ago.
↗Top 1 Million Analysis – June 2026: Ten Years of Web Securityscotthelme.co.uk 1st of 4 in this piece
-
Our reading
HTTPS is now simply how the web works, and the long tail of plain-HTTP sites shrinks every year.
Their wordsHTTPS is now simply how the web works, and the long tail of plain-HTTP sites is shrinking every year.
↗Top 1 Million Analysis – June 2026: Ten Years of Web Securityscotthelme.co.uk 2nd of 4 in this piece
-
Their wordsA lot of HSTS deployments are weaker than they look.
↗Top 1 Million Analysis – June 2026: Ten Years of Web Securityscotthelme.co.uk 3rd of 4 in this piece
-
Their wordsSo while CSP adoption has more than doubled, nearly half of all policies are in need of some TLC.
↗Top 1 Million Analysis – June 2026: Ten Years of Web Securityscotthelme.co.uk 4th of 4 in this piece
- 10 years earlier
-
Our reading
Every website needs HTTPS, including a static site with no login and nothing sensitive on it.
Their wordsSupporting HTTPS on your site has so much more to offer than just protecting passwords and user's sensitive data.
↗Still think you don't need HTTPS?scotthelme.co.uk 1st of 2 in this piece
-
Their wordsWhen you serve your pages over HTTP, anyone along the transport layer can do basically anything they want to your pages. More and more often it's becoming increasingly common for somebody in the chain of custody to do something to your pages that you don't want them to do.
↗Still think you don't need HTTPS?scotthelme.co.uk 2nd of 2 in this piece