Skip to content
Blog
Report

State of the Swamp: what the scans keep finding

We don't run surveys. We run scans. So instead of guessing what vibe-coded security looks like, here's what it actually looks like — pulled live from our own corpus, first-party and zero-PII.

The buckingfugs crewJuly 7, 20264 min read

Every number here comes from the 53 domains we've scanned, counted once each at their most recent scan so a re-scan never skews the math. No estimates, no panel of “experts” — just what the passive checks found.

68%

scored under 90 on their first scan — at least one thing worth fixing, sitting in the open.

What's wrong out there

Broken down by the thing a shakedown artist would screenshot. Each one links to how to fix it:

Does fixing it actually work?

Of the 43 domains that came back for a second look, comparing each one's first scan to its latest:

16%

improved their score

7 up · 35 held · 1 slipped.

+18.6

avg points gained

Among the domains that improved.

9

issues closed

Failing checks fixed across every re-scan, all-time.

28%

came back to re-scan

Of every domain we've ever seen.

That's the whole thesis in two numbers: most of this is cheap to fix, and when people see it, they fix it.

How we count

Everything above is passive and non-intrusive — DNS lookups and public HTTP responses, nothing attacked or broken. It's first-party (our own scans, not a third-party dataset) and zero-PII: we store the domain's security facts, never who ran the scan. Each domain is counted once, at its latest result, so the numbers reflect the current state of the swamp rather than whoever scanned most often.

Want the always-live version, with running totals? It's on the State of the Swamp dashboard.

Run a scan and see where you land against the rest of the swamp.

Scan your site free →