With the World Cup in full swing, we got curious: how well configured are the official stadium websites for the 16 host venues across the US, Canada and Mexico? So we ran a FIFA World Cup 2026 stadium security scan on all of them.

TL;DR: every single stadium site had a weak or missing Content-Security-Policy header. Half had HSTS problems. One had a session cookie with zero protections. High traffic does not mean high security.

Methodology

We scanned the official website for each of the 16 confirmed FIFA World Cup 2026 host venues, checking TLS/SSL, security headers, cookie security, DNS hardening and exposed paths. Each site gets an A–F grade. Scans were run on July 3, 2026, a single point-in-time snapshot.

Results