Open research data
Inspect the aggregate evidence
Download the approved anonymized observations, aggregate results, exclusions, and source checksums.
100 rows
One anonymous record for each included public-homepage observation.
Anonymized observations
Per-observation metrics without domains, ranks, URLs, query strings, or deterministic sample order.
Aggregate summary
Exact denominators, medians, quartiles, ranges, and boolean counts used in the report.
Source checksums
SHA-256 hashes for the frozen study inputs used during collection and analysis.
Data dictionary
Fields in the public CSV are intentionally limited to the metrics required to reproduce the aggregate findings.
observation_id- Anonymous record identifier. It does not preserve source rank or sample order.
resource_timing_entries- Number of browser Resource Timing entries retained for the observation.
additional_registrable_domains- Unique registrable domains other than the final page's registrable domain.
has_cross_domain_script_entry- Whether Resource Timing contained an initiator type of script across the registrable-domain boundary.
csp_header_present- Whether the included homepage response contained an enforced Content-Security-Policy header.
csp_report_only_present- Whether the response contained a Content-Security-Policy-Report-Only header.
has_cross_domain_dom_script- Whether the final DOM contained an in-scope cross-registrable-domain script source.
has_integrity_attribute- Whether at least one in-scope final-DOM script element had a non-empty integrity attribute.
Responsible interpretation
Do not use these records to infer vulnerability, compromise, ownership, data exfiltration, or compliance. The public dataset cannot identify or rank the observed organizations.