Legit.Show is a directory of launched web apps, SaaS, AI tools, MCP servers and developer tools — each with an objective 7-Frame production-readiness benchmark, measured deterministically from the public surface. How we measure →


Legit.Show benchmarks every launched service it lists — measured deterministically from the public surface. See the methodology →

Cross-links · Directory · Reports · Methodology · About

Privacy · Terms · operated by Madeflo Inc., a Delaware corporation. Benchmark engine powered by commit.show.

the security-header gap · 2026 edition

The Web Security Baseline · 2026

We checked the public security posture of 1000 launched web apps, SaaS and AI tools on Legit.Show — the headers and policies a browser sees before you ever sign in. Most ship without the basics.

80%
ship with no Content-Security-Policy
across 1000 web apps we measured · according to Legit.Show · 2026

The findings

How many of the 7 do they pass

By category

What this measures

These are public-surface checks — what any browser or crawler sees from the outside, before login. They measure hygiene, not whether the product is good. Every number is a share of 1000 tested web services as of 2026-07-26.

Headers, not vibes

A CSP, HSTS and a real 404 cost minutes to add and are the line between “looks done” and “is done.” That 80% ship without even a CSP isn’t a story about bad engineers — it’s what a demo never forces you to add. Only 6% pass 6 or 7 of the seven.

A health check, not a grade

Surface signals correlate with care; they don’t prove a product is secure inside. We show exactly what was observed from the public surface, and what wasn’t — no overall score, no verdict.

Sample composition

Not a random sample — this is what we measured. The mix below is the caveat; judge it for yourself.

What we measured (1000)

The full list, so anyone can spot-check. Every item links to its public benchmark.

How this was measured →