Security headers on 4,688 small-business websites: 49.7% met none of 7 criteria
rackcrunch.com
rackcrunch.com
But.. what does it mean? Why enforce certain headers? Why enforce certain options? There is a section which kinda looks at this, but not really.
You have a bunch of links at the end for resources, but why not just provide the rationale for each rule or option inclusion in the article as well? What does each prevent or allow and why?