VPNRank.io

vpnrank.io research

Link rot in library privacy and security guides

Libraries publish some of the most trusted privacy advice on the web. We checked every outbound link in 328 pages of it. 20 of 72 privacy and cybersecurity guides send readers to at least one page that no longer exists — and the scanner’s own first answer, 56.7%, was wrong by a factor of three.

Re-scanned quarterlyCurrent edition: September 2026 · swept 2026-09-15

Corpus
328 guide pages found through each library’s own public sitemap, with hosts largely derived from the Hipo university domains list (MIT licence).
Links checked
5,194 URLs; 846 unique reader-facing links in on-topic guides after scoping.
Verification
DNS through Google and Cloudflare public resolvers, both must agree. Every flagged link then re-fetched and judged by hand.
Analysis
Sofía Giménez, Privacy, Jurisdiction & No-Logs Reviewer
Bar chart: the scanner's raw verdict says 56.7% of pages carry a dead link; counting only reader-facing links and confident failures in on-topic guides gives 16.5% of pages and 27.8% of guides
One sweep, three possible headlines. Verified September 2026.

Key findings, September 2026

  • 20 of 72 guides (27.8%) carry at least one confidently dead link. Counted per page instead of per guide, it is 39 of 236 pages (16.5%). At link level, 36 of the 741 links we could read are dead (4.9%).
  • Consumer privacy guides rot more than cybersecurity subject guides. 10 of 26 privacy guides against 10 of 46 cybersecurity guides. Both groups are small, so read this as a direction rather than a gap to the decimal.
  • The privacy tools themselves mostly survive; the advice around them does not. The tools’ own sites are dead at 1.5%. What disappears is the explainer, the law summary and the agency page that told a reader why to use them.
  • A naive scan overstates rot roughly threefold. Read straight, the same sweep says 56.7% of pages carry a dead link. Most of that is library databases asking an anonymous visitor to sign in, tracking scripts, and projects that moved house and still work.

Free to quote with attribution to vpnrank.io. Please state the edition month. Individual guides and libraries are deliberately not named.

More than a quarter of library privacy and security guides send readers to a page that is gone

Research guides are the quiet backbone of privacy education. When a public library runs a digital-safety workshop, or a university teaches a first-year privacy-literacy session, the reading list usually lives on a guide page: a curated set of links to tools, explainers, laws and agencies, maintained by a librarian who chose each one. Those pages carry real authority. They rank, they are linked from course syllabi, and a reader who lands on one has every reason to trust where it points.

The links, though, are only as good as the web they point into, and that web moves. Across the 72 guides in this edition that are genuinely about privacy or security, 20 link to at least one page that answers with a hard failure: a 404 or 410, a domain that no longer exists on either public DNS resolver we ask, or an address typed wrongly when the link was added. That is 27.8% of guides. It is not a catastrophe — at link level the rate is 4.9% — but it means a reader working through one of these guides has better than a one-in-four chance of hitting a dead end.

Guide typeGuidesWith a dead linkDead links / readable linksWhat it doesn't automatically prove
Personal privacy and online safety2610 (38.5%)18 / 406 (4.4%)That these guides are neglected. They link out more, and to more short-lived pages (news articles, campaign pages), so they have more to lose.
Cybersecurity subject guides4610 (21.7%)18 / 335 (5.4%)That they are healthier. 15.4% of their links could not be read at all, the highest share of any group — security vendors block automated visitors hardest.
Both, the headline group7220 (27.8%)36 / 741 (4.9%)That every dead link harms a reader equally. A dead donation page and a dead law summary are counted the same.
Off-target, excluded163 (18.8%)5 / 76Pages the discovery pattern matched that are not privacy guides — library password help, food security, national security studies. Shown so the exclusion is visible.
Confident failures only: HTTP 404/410, domain gone on both public resolvers, or a malformed address. Links that could not be read are excluded from the denominator. Guides are counted once however many tabs they have. Swept 2026-09-15.

The tools survive; the explanation of why to use them is what dies

The obvious guess is that privacy tools are the fragile part — small projects, volunteer maintainers, apps that are abandoned. The data says the opposite. Links that point at a privacy or security tool’s own site are the most durable category we measured. The rot sits one layer out, in the material that gives a tool its context: a newspaper piece explaining how to change streaming-app privacy settings, a legal information institute’s summary of the Privacy Act, a national cybersecurity campaign’s page on shopping safely online, a public-health agency’s HIPAA explainer.

The few tool links that do fail are instructive. Three of them are not decay at all — they were added with the protocol typed twice (http://https//), so a Tor download, a tracker blocker and a mobile Tor client have been unreachable from the day they were pasted in. One more is a genuine reorganisation: a well-known privacy developer moved the page for its Android Tor app, and the old address now returns a 404.

Where the link pointsReadable linksDeadRateWhat it doesn't automatically prove
Privacy or security tool6511.5%Counts only the tools' own sites. Three further tool links were mistyped and appear as malformed, not here.
Government8955.6%Agency renames (a department moving to a new domain) redirect and are counted as reachable, which flatters this row.
University17774.0%Mostly research centres and course pages — rot here is usually a reorganised departmental site.
Non-profit (.org)158106.3%Includes advocacy groups whose campaign pages are retired when the campaign ends — expected, not negligent.
Commercial and other243135.3%News articles and vendor pages. Paywalls that return a normal page are counted as working.
Hosted doc or free site900.0%Too few links to read a rate from. Reported so the row is not silently dropped.
Destination type is read from the dead link's own domain: a named list of tool sites, then .gov/.mil, .edu/.ac, .org, and everything else. On-topic guides only, unique links per guide, September 2026.

The spread between categories is narrow — every institutional type sits within a couple of points of the others — and that is itself a finding. Government pages are not more stable than commercial ones, and universities do not maintain their own research-centre pages better than non-profits maintain campaign material. Rot here behaves like weather, not like negligence by any one kind of publisher.

Practical rule

Link to the tool’s own homepage and to the primary source, not to an article about either. In this sweep the tools’ own sites were the most durable links on the page; the explainers written about them were the first to disappear.

Why the scanner’s first answer, 56.7%, would have been a false headline

The easiest version of this study takes about twenty minutes and produces a striking number. Point a link checker at the pages, count every URL that does not come back clean, and report the share of pages with at least one failure. On this corpus that number is 56.7% — 186 of 328 pages. It would make a good headline, and it is wrong for three separate reasons that are worth spelling out, because every one of them is a trap any link-rot study falls into by default.

Stacked bar of what 846 reader-facing links in 72 guides lead to: 651 answer normally, 47 moved to another site and still reachable, 36 dead, 5 land on a homepage, 2 ask for a sign-in, 105 could not be read
After scoping, most links work, and the biggest non-working slice is links we could not read — which is never counted as dead. September 2026.
  • Not every URL on a page is a link a reader follows: 2,729 of the URLs in the raw sweep were not reader-facing links at all — analytics beacons, script and widget addresses, embedded configuration. A dead tracking script is not a broken reading list.
  • Library links are supposed to stop strangers: 734 reader-facing links pointed into licensed databases, proxy servers, single sign-on and campus systems. From outside the institution every one of them redirects to a login page, which a naive checker reads as “moved to another site”. For the student the guide was written for, they work.
  • A redirect is usually a move, not a death: 47 links in the on-topic guides now land on a different domain — a privacy project that changed its domain, an agency that was renamed, a vendor that rebranded, a DOI resolving to its publisher. They are reachable and we count them as reachable. A handful do land somewhere unrelated, so this choice slightly understates rot rather than inflating it.

There is a fourth, smaller correction that matters for fairness rather than size. LibGuides sites split one guide into several tabs, and a box of links is often repeated on every tab. Counting pages lets one broken box on a twelve-tab guide count twelve times. Collapsing tabs into guides is why the guide-level rate (27.8%) is higher than the page-level one (16.5%): it stops a single large guide dominating, and it answers the question a reader actually has, which is whether the guide they opened is sound.

What the dead links are, without naming who links to them

The table lists every distinct destination that failed in this edition. It names the site that removed or lost the page, never the library guide that links to it — the point is to describe the web these guides depend on, not to single out a librarian for a page someone else deleted. Anchor text is the words the guide used for the link.

DestinationLinked asWhat happenedWhat it doesn't automatically prove
morseinstitute.orgSupport the LibraryHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
libraryfreedom.orgInvite Library FreedomHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
flickr.comFlickrHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
au.af.milHQ Air UniversityThe domain no longer resolves on either public resolverA domain can be re-registered by someone else later, which would turn a dead link into a hijacked one.
af.milFOIAHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
computer.orgIEEE Computing Now blogNow lands on the site's homepage; the page is goneThe site survives; only the specific page was removed or reorganised.
libguides.pratt.eduPratt Institute Library Internet and Data Privacy GuideHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
belmont.libguides.comPrivacy Laws, Belmont UniversityHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
library.indianapolis.iu.eduData SupportHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
resources.infosecinstitute.comhttps://resources.infosecinstitute.com/The domain no longer resolves on either public resolverA domain can be re-registered by someone else later, which would turn a dead link into a hijacked one.
owasp.orgOWASP: Open Web Application Security ProjectHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
tcs.comTata Consultancy Services: Cyber Security CommunityHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
uon.cyberlearn.appGo to the CyberLearn portalHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
houstonisd.orgCybersafetyHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
cybersecurity.tamu.eduTexas A&M Cybersecurity CenterHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
guardianproject.infoTor OrbotHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
http://https//www.torproject.org/download/TorThe address itself is mistyped, so it never workedNot decay: a typo when the link was added. The tool behind it is alive.
http://https//www.eff.org/privacybadgerPrivacy BadgerThe address itself is mistyped, so it never workedNot decay: a typo when the link was added. The tool behind it is alive.
cnet.comUpdating streaming service privacy settingsHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
http://https//guardianproject.info/apps/orbot/Tor OrbotThe address itself is mistyped, so it never workedNot decay: a typo when the link was added. The tool behind it is alive.
cisecurity.orgCyberSecurity Information Sharing ActHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
cdc.govHIPAA - Health Insurance Portability and Accountability Act 1996HTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
law.cornell.eduFreedom of Information Act (FOIA)HTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
law.cornell.eduPrivacy Act of 1974HTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
knightfoundation.orgFree Expression Research Series: CollegeHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
en.ryte.comMore infoNow lands on the site's homepage; the page is goneThe site survives; only the specific page was removed or reorganised.
staysafeonline.orgStaySafeOnline.orgNow lands on the site's homepage; the page is goneThe site survives; only the specific page was removed or reorganised.
staysafeonline.orgMobile DevicesHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
staysafeonline.orgOnline ShoppingHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
loudtreemedia.comWhat the hack with Adam Levine podcastHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
http://10.0.4.33/s41288-022-00266-610.1057/s41288-022-00266-6The address itself is mistyped, so it never workedNot decay: a typo when the link was added. The tool behind it is alive.
citeseerx.ist.psu.eduCiteSeerXHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
defense.govArmed with ScienceHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
cisa.govUnited States Computer Emergency Readiness Team (US-CERT)Now lands on the site's homepage; the page is goneThe site survives; only the specific page was removed or reorganised.
cia.govpublicationsHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
cfr.orgCouncil on Foreign Relations - National SecurityHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
endnote.comEndNote BasicHTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
tudublin.iehere.HTTP 404 — the page no longer existsThe content may exist at a new address the link was never updated to.
Every distinct confidently dead or homepage-bounced destination in on-topic guides, September 2026. Each was re-fetched independently with a browser user agent and confirmed by hand on 2026-09-15.

A recently edited guide is not a recently checked one

LibGuides prints a “Last Updated” date in every guide footer, which invites an obvious hypothesis: old guides rot, fresh guides don’t. The stamp turns out to be a weak signal. It records the last edit to any box on the guide, not the last time anyone checked the links, and most guides in the corpus carry a recent date — 54 of the 70 dated guides were touched in the past twelve months. Of those, 14 still carry a dead link (25.9%).

Last editedGuidesWith a dead linkWhat it doesn't automatically prove
under 1 year ago5414 (25.9%)An edit date says someone changed something, not that the links were re-checked.
1 to 2 years ago74 (57.1%)Too few guides to read a rate from. Shown as a count so it is not mistaken for a trend.
2 to 4 years ago62 (33.3%)Too few guides to read a rate from. Shown as a count so it is not mistaken for a trend.
over 4 years ago30 (0.0%)Too few guides to read a rate from. Shown as a count so it is not mistaken for a trend.
Guide age from the LibGuides "Last Updated" footer, measured to 2026-09-15. 2 guides had no stamp and are omitted from this table only.

The older buckets hold only 16 guides between them (6 with a dead link), which is not enough to say whether age predicts rot in this corpus, and we are not going to pretend otherwise. What the data does support is the narrower claim in the heading: a guide being edited recently is no assurance that its links work.

How the sweep works, and the traps it is built to avoid

Discovery is deterministic, which is what makes the study repeatable. We derive candidate library hosts from the open Hipo university domains list for the United States, United Kingdom, Canada, Australia, New Zealand and Ireland, keep hosts that run a LibGuides site with its own public sitemap, and select guides whose address matches a privacy or security topic pattern. Each matched guide is then expanded into its sibling tabs, because the link lists usually sit one tab in. This edition’s corpus is 328 pages; all 328 were readable on the day of the sweep.

  • The local resolver lies: the machine running the sweep has returned false “no such domain” answers for live sites. Every lookup goes to Google and Cloudflare public DNS over HTTPS instead, and a domain is only called gone when both agree.
  • Bot protection is not death: a site that answers 403 or 503 to an automated visitor is recorded as unreadable, never as dead. 105 links (12.4%) ended up there.
  • A dead deep link can hide behind a live homepage: a removed page that redirects to a bot-protected front page answers 403, so the redirect is judged before the status code.
  • Topic is checked by hand: the discovery pattern matches “security” in senses that have nothing to do with privacy — food security, national security, a library’s own privacy statement, instructions for a database password. Every guide title was reviewed and 42 pages were set aside as off-target.

Measured precision. Every link the classifier flagged was re-fetched with a different client and judged by hand. Before the review changed any rules, 36 of 38 links it called confidently dead were confirmed. The two errors were a live security-news site whose article about an expired domain tripped the parked-domain detector, and an unreachable raw IP address that could not be proven gone. The softer “deep link now lands on the homepage” verdict fared worse: 6 of 11, because a project moving to a new domain looks identical to a page being deleted. That is why the headline uses confident failures only, why homepage bounces are reported separately, and why a move to another site is now never counted as a loss.

Why a VPN comparison site measured this, and what we get out of it

vpnrank.io earns commission when readers buy a VPN through our links, and it is fair to ask why such a site is auditing library reading lists. The honest answer is that privacy guides are the neighbourhood we work in, and the same scanner that measures this also finds broken links on pages we might one day ask to cite our own tools. We say that plainly so it can be weighed.

It is also why the study is built the way it is. No guide or library is named. No VPN is recommended, and nothing here is a pitch. The figures are deliberately conservative: where a link could not be read, or had merely moved, we counted it in the guide’s favour. A study written to generate outreach would have published the 56.7% number. The corpus, the classification rules and the hand-review record are kept in version control with the rest of our research, and a librarian who wants the specific dead links on their own guide can ask for them at [email protected].

The next edition re-scans the same corpus, so the change is the story

A single sweep is a snapshot. The measurement that matters is decay over time: of the links that worked this quarter, how many will be gone next quarter, and how many of today’s dead links get fixed. So each edition re-runs the same corpus with the same classification rules and the same hand review, and reports the difference alongside the new level. Guides published after this edition are added to the corpus but kept out of the like-for-like comparison, so a wider corpus never reads as a change in rot.

The next scan is due in December 2026. Every edition states the date it was swept, and earlier editions are kept rather than overwritten.

Related research