CyberBadger Labs · Research

Guelph, Ontario Business Website Security

539 sites scanned · Guelph Ontario · August 2026 · passive, public data only · 2 scans tracked

We ran a passive, read-only security scan of 539 Guelph Ontario business websites, using only what any browser or mail server can already see. Most can be impersonated in email, and the typical independent business site scores a D+. Here is what the outside of Guelph Ontario's small-business web looks like, and how to close the most common gaps.

86.6%
of independent Guelph Ontario businesses can be impersonated in email.

How Guelph Ontario grades out

Every site gets one A to F grade. The typical independent Guelph Ontario business scores a D+.

A
C
D+
D
A 7.5%B 5.5%C 18.6%D+ 32.7%D 32%D- 1.4%F 2.3%
Typical grade by category
Email
F
Headers
B
TLS
A+
DNS
A+
Cookies
A+
Software
A+

The overall grade is held down by its weakest category. The rest of the region’s web is often in far better shape.

What we found, and how to fix it

Share of independent businesses with each gap, next to Guelph Ontario's 99 chains and franchises for comparison. Every one is fixable.

86.6%
Local
59.6%
Chains
Can be impersonated in email (no DMARC enforcement)
381 of 440 sites
How to fix this →
1.6%
Local
0%
Chains
Running software with a known CVE
7 of 440 sites
How to fix this →
69.1%
Local
100%
Chains
WordPress sites exposing their admin usernames
105 of 152 WordPress sites
How to fix this →
75.7%
Local
64.6%
Chains
No Content-Security-Policy header
333 of 440 sites
How to fix this →
51.8%
Local
32.3%
Chains
Missing core security headers
228 of 440 sites
How to fix this →
61.6%
Local
52.5%
Chains
No HSTS (browsers can be downgraded to HTTP)
271 of 440 sites
How to fix this →
28.9%
Local
22.2%
Chains
No SPF record
127 of 440 sites
How to fix this →
14.3%
Local
10.1%
Chains
Not enforcing HTTPS
63 of 440 sites
How to fix this →
2.7%
Local
1%
Chains
Expired or untrusted TLS certificate
12 of 440 sites
How to fix this →

Context: 34.5% of these sites run WordPress (152 of 440). Running WordPress is not a problem in itself; it just means the WordPress-specific gaps above apply.

What Guelph Ontario gets right

Security basics a good share of these businesses already have in place.

83.9%enforce HTTPS
94.5%have a valid, trusted certificate
13.4%enforce DMARC (quarantine or reject)
33%send a strong HSTS header
25%have a strict SPF record (-all)

How Guelph Ontario has changed

2 scans since July 2026. Lower is better on every line.

Spoofable email
86.6%▼ 0.4 pts
was 87%
No HTTPS
14.3%▼ 1.7 pts
was 16%
No HSTS
61.6%▼ 2.6 pts
was 64.2%
0%25%50%75%100%July 2026August 2026Spoofable emailNo HTTPSNo HSTS

Grade mix over time

D
C
July 2026
typ. D+
D
C
August 2026
typ. D+

Where does your site land?

Run the same free scan on your own website and get your grade, plus the exact fixes, in under a minute. No login.

Run a free security scan

Method & sources

  • Passive and read-only: public DNS records plus a single homepage request per site. No logins, no test emails, no active or intrusive testing.
  • Sites were drawn from OpenStreetMap within Guelph Ontario's administrative boundary, deduplicated by domain. 539 of 569 sites had a reachable website and were scored; the rest had no reachable website.
  • Of those, the headline figures cover the 440 independent businesses; the 99 chains and franchises (a domain at many locations, or carrying a brand tag) were set aside so the numbers reflect locally-owned businesses.
  • Figures are aggregate and anonymized: no individual business is named.

Data sources: © OpenStreetMap contributors.

Cite this report

CyberBadger Labs, "Guelph, Ontario Business Website Security" (2026). n=539 guelph ontario business websites. Data: © OpenStreetMap contributors.