CyberBadger Labs · Research

Toronto Small VS Franchise website security

5,888 sites scanned · Toronto · August 2026 · passive, public data only · 2 scans tracked

We ran a passive, read-only security scan of 5,888 Toronto business websites, using only what any browser or mail server can already see. Most can be impersonated in email, and the typical independent business site scores a D. Here is what the outside of Toronto's small-business web looks like, and how to close the most common gaps.

87.7%
of independent Toronto businesses can be impersonated in email.

How Toronto grades out

Every site gets one A to F grade. The typical independent Toronto business scores a D.

C
D+
D
A 5.2%B 6.6%C 17.8%D+ 32.5%D 33%D- 1.9%F 2.8%
Typical grade by category
Email
F
Headers
B
TLS
A+
DNS
A+
Cookies
A+
Software
A+

The overall grade is held down by its weakest category. The rest of the region’s web is often in far better shape.

What we found, and how to fix it

Share of independent businesses with each gap, next to Toronto's 562 chains and franchises for comparison. Every one is fixable.

87.7%
Local
63.7%
Chains
Can be impersonated in email (no DMARC enforcement)
4,672 of 5,326 sites
How to fix this →
1.6%
Local
0.7%
Chains
Running software with a known CVE
85 of 5,326 sites
How to fix this →
72%
Local
71%
Chains
WordPress sites exposing their admin usernames
991 of 1,376 WordPress sites
How to fix this →
77.5%
Local
63.9%
Chains
No Content-Security-Policy header
4,128 of 5,326 sites
How to fix this →
56.8%
Local
39.9%
Chains
Missing core security headers
3,027 of 5,326 sites
How to fix this →
66.3%
Local
53%
Chains
No HSTS (browsers can be downgraded to HTTP)
3,533 of 5,326 sites
How to fix this →
29.3%
Local
19.8%
Chains
No SPF record
1,558 of 5,326 sites
How to fix this →
20%
Local
16.2%
Chains
Not enforcing HTTPS
1,067 of 5,326 sites
How to fix this →
3.3%
Local
3.7%
Chains
Expired or untrusted TLS certificate
178 of 5,326 sites
How to fix this →

Context: 25.8% of these sites run WordPress (1,376 of 5,326). Running WordPress is not a problem in itself; it just means the WordPress-specific gaps above apply.

What Toronto gets right

Security basics a good share of these businesses already have in place.

76.1%enforce HTTPS
92.4%have a valid, trusted certificate
12.3%enforce DMARC (quarantine or reject)
25.5%send a strong HSTS header
24.2%have a strict SPF record (-all)

How Toronto has changed

2 scans since July 2026. Lower is better on every line.

Spoofable email
87.7%▼ 0.2 pts
was 87.9%
No HTTPS
20%▼ 1.4 pts
was 21.4%
No HSTS
66.3%▲ 0.5 pts
was 65.8%
0%25%50%75%100%July 2026August 2026Spoofable emailNo HTTPSNo HSTS

Grade mix over time

D
C
July 2026
typ. D+
D
C
August 2026
typ. D

Where does your site land?

Run the same free scan on your own website and get your grade, plus the exact fixes, in under a minute. No login.

Run a free security scan

Method & sources

  • Passive and read-only: public DNS records plus a single homepage request per site. No logins, no test emails, no active or intrusive testing.
  • Sites were drawn from OpenStreetMap within Toronto's administrative boundary, deduplicated by domain. 5,888 of 6,319 sites had a reachable website and were scored; the rest had no reachable website.
  • Of those, the headline figures cover the 5,326 independent businesses; the 562 chains and franchises (a domain at many locations, or carrying a brand tag) were set aside so the numbers reflect locally-owned businesses.
  • Figures are aggregate and anonymized: no individual business is named.

Data sources: © OpenStreetMap contributors.

Cite this report

CyberBadger Labs, "Toronto Small VS Franchise website security" (2026). n=5888 toronto business websites. Data: © OpenStreetMap contributors.