We analyzed 100 qualifying public homepages in a controlled browser study to understand what actually reaches the browser.
The median observation recorded 107.5 browser resource entries and contacted 8 registrable domains beyond the final page s domain. Cross-domain script Resource Timing entries appeared in 92 of 100 observations.
We published the full methodology, anonymized dataset, and downloadable charts so the findings can be independently reviewed and reused:
https://cellwall.io/en/research/...
We would especially value feedback on the methodology and what the security community would like examined in the next edition.