CyberBadger Labs · Research

Hamilton, Ontario Business Website Security

819 sites scanned · Hamilton Ontario · July 2026 · passive, public data only

We ran a passive, read-only security scan of 819 Hamilton Ontario business websites, using only what any browser or mail server can already see. Most of these WordPress sites expose their admin usernames, and the typical independent business site scores a D+. Here is what the outside of Hamilton Ontario's small-business web looks like, and how to close the most common gaps.

68.9%
of Hamilton Ontario WordPress sites expose their admin usernames.

How Hamilton Ontario grades out

Every site gets one A to F grade. The typical independent Hamilton Ontario business scores a D+.

A
C
D+
D
A 8.1%B 6.7%C 19%D+ 33.3%D 29.5%D- 1.4%F 2.3%

What we found, and how to fix it

Share of independent businesses with each gap, next to Hamilton Ontario's 155 chains and franchises for comparison. Every one is fixable.

84.6%
Local
61.9%
Chains
Can be impersonated in email (no DMARC enforcement)
562 of 664 sites
How to fix this →
2.4%
Local
0%
Chains
Running software with a known CVE
16 of 664 sites
How to fix this →
68.9%
Local
75%
Chains
WordPress sites exposing their admin usernames
166 of 241 WordPress sites
How to fix this →
72.1%
Local
57.4%
Chains
No Content-Security-Policy header
479 of 664 sites
How to fix this →
57.5%
Local
42.6%
Chains
Missing core security headers
382 of 664 sites
How to fix this →
61%
Local
52.3%
Chains
No HSTS (browsers can be downgraded to HTTP)
405 of 664 sites
How to fix this →
27.1%
Local
17.4%
Chains
No SPF record
180 of 664 sites
How to fix this →
17.5%
Local
13.5%
Chains
Not enforcing HTTPS
116 of 664 sites
How to fix this →
2.9%
Local
3.9%
Chains
Expired or untrusted TLS certificate
19 of 664 sites
How to fix this →

Context: 36.3% of these sites run WordPress (241 of 664). Running WordPress is not a problem in itself; it just means the WordPress-specific gaps above apply.

What Hamilton Ontario gets right

Security basics a good share of these businesses already have in place.

80.3%enforce HTTPS
94%have a valid, trusted certificate
15.4%enforce DMARC (quarantine or reject)
32.2%send a strong HSTS header
26.4%have a strict SPF record (-all)

This is Hamilton Ontario’s baseline

First scan July 2026. When Hamilton Ontario is re-scanned, this section becomes a timeline showing what improved and what slipped.

Where does your site land?

Run the same free scan on your own website and get your grade, plus the exact fixes, in under a minute. No login.

Run a free security scan

Method & sources

  • Passive and read-only: public DNS records plus a single homepage request per site. No logins, no test emails, no active or intrusive testing.
  • Sites were drawn from OpenStreetMap within Hamilton Ontario's administrative boundary, deduplicated by domain. 819 of 895 sites had a reachable website and were scored; the rest had no reachable website.
  • Of those, the headline figures cover the 664 independent businesses; the 155 chains and franchises (a domain at many locations, or carrying a brand tag) were set aside so the numbers reflect locally-owned businesses.
  • Figures are aggregate and anonymized: no individual business is named.

Data sources: © OpenStreetMap contributors.

Cite this report

CyberBadger Labs, "Hamilton, Ontario Business Website Security" (2026). n=819 hamilton ontario business websites. Data: © OpenStreetMap contributors.