
Key findings, September 2026
- 20 of 72 guides (27.8%) carry at least one confidently dead link. Counted per page instead of per guide, it is 39 of 236 pages (16.5%). At link level, 36 of the 741 links we could read are dead (4.9%).
- Consumer privacy guides rot more than cybersecurity subject guides. 10 of 26 privacy guides against 10 of 46 cybersecurity guides. Both groups are small, so read this as a direction rather than a gap to the decimal.
- The privacy tools themselves mostly survive; the advice around them does not. The tools’ own sites are dead at 1.5%. What disappears is the explainer, the law summary and the agency page that told a reader why to use them.
- A naive scan overstates rot roughly threefold. Read straight, the same sweep says 56.7% of pages carry a dead link. Most of that is library databases asking an anonymous visitor to sign in, tracking scripts, and projects that moved house and still work.
Free to quote with attribution to vpnrank.io. Please state the edition month. Individual guides and libraries are deliberately not named.
More than a quarter of library privacy and security guides send readers to a page that is gone
Research guides are the quiet backbone of privacy education. When a public library runs a digital-safety workshop, or a university teaches a first-year privacy-literacy session, the reading list usually lives on a guide page: a curated set of links to tools, explainers, laws and agencies, maintained by a librarian who chose each one. Those pages carry real authority. They rank, they are linked from course syllabi, and a reader who lands on one has every reason to trust where it points.
The links, though, are only as good as the web they point into, and that web moves. Across the 72 guides in this edition that are genuinely about privacy or security, 20 link to at least one page that answers with a hard failure: a 404 or 410, a domain that no longer exists on either public DNS resolver we ask, or an address typed wrongly when the link was added. That is 27.8% of guides. It is not a catastrophe — at link level the rate is 4.9% — but it means a reader working through one of these guides has better than a one-in-four chance of hitting a dead end.
| Guide type | Guides | With a dead link | Dead links / readable links | What it doesn't automatically prove |
|---|---|---|---|---|
| Personal privacy and online safety | 26 | 10 (38.5%) | 18 / 406 (4.4%) | That these guides are neglected. They link out more, and to more short-lived pages (news articles, campaign pages), so they have more to lose. |
| Cybersecurity subject guides | 46 | 10 (21.7%) | 18 / 335 (5.4%) | That they are healthier. 15.4% of their links could not be read at all, the highest share of any group — security vendors block automated visitors hardest. |
| Both, the headline group | 72 | 20 (27.8%) | 36 / 741 (4.9%) | That every dead link harms a reader equally. A dead donation page and a dead law summary are counted the same. |
| Off-target, excluded | 16 | 3 (18.8%) | 5 / 76 | Pages the discovery pattern matched that are not privacy guides — library password help, food security, national security studies. Shown so the exclusion is visible. |
The tools survive; the explanation of why to use them is what dies
The obvious guess is that privacy tools are the fragile part — small projects, volunteer maintainers, apps that are abandoned. The data says the opposite. Links that point at a privacy or security tool’s own site are the most durable category we measured. The rot sits one layer out, in the material that gives a tool its context: a newspaper piece explaining how to change streaming-app privacy settings, a legal information institute’s summary of the Privacy Act, a national cybersecurity campaign’s page on shopping safely online, a public-health agency’s HIPAA explainer.
The few tool links that do fail are instructive. Three of them are not decay at all — they were added with the protocol typed twice (http://https//), so a Tor download, a tracker blocker and a mobile Tor client have been unreachable from the day they were pasted in. One more is a genuine reorganisation: a well-known privacy developer moved the page for its Android Tor app, and the old address now returns a 404.
| Where the link points | Readable links | Dead | Rate | What it doesn't automatically prove |
|---|---|---|---|---|
| Privacy or security tool | 65 | 1 | 1.5% | Counts only the tools' own sites. Three further tool links were mistyped and appear as malformed, not here. |
| Government | 89 | 5 | 5.6% | Agency renames (a department moving to a new domain) redirect and are counted as reachable, which flatters this row. |
| University | 177 | 7 | 4.0% | Mostly research centres and course pages — rot here is usually a reorganised departmental site. |
| Non-profit (.org) | 158 | 10 | 6.3% | Includes advocacy groups whose campaign pages are retired when the campaign ends — expected, not negligent. |
| Commercial and other | 243 | 13 | 5.3% | News articles and vendor pages. Paywalls that return a normal page are counted as working. |
| Hosted doc or free site | 9 | 0 | 0.0% | Too few links to read a rate from. Reported so the row is not silently dropped. |
The spread between categories is narrow — every institutional type sits within a couple of points of the others — and that is itself a finding. Government pages are not more stable than commercial ones, and universities do not maintain their own research-centre pages better than non-profits maintain campaign material. Rot here behaves like weather, not like negligence by any one kind of publisher.
Practical rule
Link to the tool’s own homepage and to the primary source, not to an article about either. In this sweep the tools’ own sites were the most durable links on the page; the explainers written about them were the first to disappear.
Why the scanner’s first answer, 56.7%, would have been a false headline
The easiest version of this study takes about twenty minutes and produces a striking number. Point a link checker at the pages, count every URL that does not come back clean, and report the share of pages with at least one failure. On this corpus that number is 56.7% — 186 of 328 pages. It would make a good headline, and it is wrong for three separate reasons that are worth spelling out, because every one of them is a trap any link-rot study falls into by default.

- Not every URL on a page is a link a reader follows: 2,729 of the URLs in the raw sweep were not reader-facing links at all — analytics beacons, script and widget addresses, embedded configuration. A dead tracking script is not a broken reading list.
- Library links are supposed to stop strangers: 734 reader-facing links pointed into licensed databases, proxy servers, single sign-on and campus systems. From outside the institution every one of them redirects to a login page, which a naive checker reads as “moved to another site”. For the student the guide was written for, they work.
- A redirect is usually a move, not a death: 47 links in the on-topic guides now land on a different domain — a privacy project that changed its domain, an agency that was renamed, a vendor that rebranded, a DOI resolving to its publisher. They are reachable and we count them as reachable. A handful do land somewhere unrelated, so this choice slightly understates rot rather than inflating it.
There is a fourth, smaller correction that matters for fairness rather than size. LibGuides sites split one guide into several tabs, and a box of links is often repeated on every tab. Counting pages lets one broken box on a twelve-tab guide count twelve times. Collapsing tabs into guides is why the guide-level rate (27.8%) is higher than the page-level one (16.5%): it stops a single large guide dominating, and it answers the question a reader actually has, which is whether the guide they opened is sound.
What the dead links are, without naming who links to them
The table lists every distinct destination that failed in this edition. It names the site that removed or lost the page, never the library guide that links to it — the point is to describe the web these guides depend on, not to single out a librarian for a page someone else deleted. Anchor text is the words the guide used for the link.
| Destination | Linked as | What happened | What it doesn't automatically prove |
|---|---|---|---|
| morseinstitute.org | Support the Library | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| libraryfreedom.org | Invite Library Freedom | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| flickr.com | Flickr | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| au.af.mil | HQ Air University | The domain no longer resolves on either public resolver | A domain can be re-registered by someone else later, which would turn a dead link into a hijacked one. |
| af.mil | FOIA | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| computer.org | IEEE Computing Now blog | Now lands on the site's homepage; the page is gone | The site survives; only the specific page was removed or reorganised. |
| libguides.pratt.edu | Pratt Institute Library Internet and Data Privacy Guide | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| belmont.libguides.com | Privacy Laws, Belmont University | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| library.indianapolis.iu.edu | Data Support | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| resources.infosecinstitute.com | https://resources.infosecinstitute.com/ | The domain no longer resolves on either public resolver | A domain can be re-registered by someone else later, which would turn a dead link into a hijacked one. |
| owasp.org | OWASP: Open Web Application Security Project | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| tcs.com | Tata Consultancy Services: Cyber Security Community | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| uon.cyberlearn.app | Go to the CyberLearn portal | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| houstonisd.org | Cybersafety | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| cybersecurity.tamu.edu | Texas A&M Cybersecurity Center | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| guardianproject.info | Tor Orbot | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| http://https//www.torproject.org/download/ | Tor | The address itself is mistyped, so it never worked | Not decay: a typo when the link was added. The tool behind it is alive. |
| http://https//www.eff.org/privacybadger | Privacy Badger | The address itself is mistyped, so it never worked | Not decay: a typo when the link was added. The tool behind it is alive. |
| cnet.com | Updating streaming service privacy settings | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| http://https//guardianproject.info/apps/orbot/ | Tor Orbot | The address itself is mistyped, so it never worked | Not decay: a typo when the link was added. The tool behind it is alive. |
| cisecurity.org | CyberSecurity Information Sharing Act | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| cdc.gov | HIPAA - Health Insurance Portability and Accountability Act 1996 | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| law.cornell.edu | Freedom of Information Act (FOIA) | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| law.cornell.edu | Privacy Act of 1974 | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| knightfoundation.org | Free Expression Research Series: College | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| en.ryte.com | More info | Now lands on the site's homepage; the page is gone | The site survives; only the specific page was removed or reorganised. |
| staysafeonline.org | StaySafeOnline.org | Now lands on the site's homepage; the page is gone | The site survives; only the specific page was removed or reorganised. |
| staysafeonline.org | Mobile Devices | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| staysafeonline.org | Online Shopping | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| loudtreemedia.com | What the hack with Adam Levine podcast | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| http://10.0.4.33/s41288-022-00266-6 | 10.1057/s41288-022-00266-6 | The address itself is mistyped, so it never worked | Not decay: a typo when the link was added. The tool behind it is alive. |
| citeseerx.ist.psu.edu | CiteSeerX | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| defense.gov | Armed with Science | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| cisa.gov | United States Computer Emergency Readiness Team (US-CERT) | Now lands on the site's homepage; the page is gone | The site survives; only the specific page was removed or reorganised. |
| cia.gov | publications | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| cfr.org | Council on Foreign Relations - National Security | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| endnote.com | EndNote Basic | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
| tudublin.ie | here. | HTTP 404 — the page no longer exists | The content may exist at a new address the link was never updated to. |
A recently edited guide is not a recently checked one
LibGuides prints a “Last Updated” date in every guide footer, which invites an obvious hypothesis: old guides rot, fresh guides don’t. The stamp turns out to be a weak signal. It records the last edit to any box on the guide, not the last time anyone checked the links, and most guides in the corpus carry a recent date — 54 of the 70 dated guides were touched in the past twelve months. Of those, 14 still carry a dead link (25.9%).
| Last edited | Guides | With a dead link | What it doesn't automatically prove |
|---|---|---|---|
| under 1 year ago | 54 | 14 (25.9%) | An edit date says someone changed something, not that the links were re-checked. |
| 1 to 2 years ago | 7 | 4 (57.1%) | Too few guides to read a rate from. Shown as a count so it is not mistaken for a trend. |
| 2 to 4 years ago | 6 | 2 (33.3%) | Too few guides to read a rate from. Shown as a count so it is not mistaken for a trend. |
| over 4 years ago | 3 | 0 (0.0%) | Too few guides to read a rate from. Shown as a count so it is not mistaken for a trend. |
The older buckets hold only 16 guides between them (6 with a dead link), which is not enough to say whether age predicts rot in this corpus, and we are not going to pretend otherwise. What the data does support is the narrower claim in the heading: a guide being edited recently is no assurance that its links work.
How the sweep works, and the traps it is built to avoid
Discovery is deterministic, which is what makes the study repeatable. We derive candidate library hosts from the open Hipo university domains list for the United States, United Kingdom, Canada, Australia, New Zealand and Ireland, keep hosts that run a LibGuides site with its own public sitemap, and select guides whose address matches a privacy or security topic pattern. Each matched guide is then expanded into its sibling tabs, because the link lists usually sit one tab in. This edition’s corpus is 328 pages; all 328 were readable on the day of the sweep.
- The local resolver lies: the machine running the sweep has returned false “no such domain” answers for live sites. Every lookup goes to Google and Cloudflare public DNS over HTTPS instead, and a domain is only called gone when both agree.
- Bot protection is not death: a site that answers 403 or 503 to an automated visitor is recorded as unreadable, never as dead. 105 links (12.4%) ended up there.
- A dead deep link can hide behind a live homepage: a removed page that redirects to a bot-protected front page answers 403, so the redirect is judged before the status code.
- Topic is checked by hand: the discovery pattern matches “security” in senses that have nothing to do with privacy — food security, national security, a library’s own privacy statement, instructions for a database password. Every guide title was reviewed and 42 pages were set aside as off-target.
Measured precision. Every link the classifier flagged was re-fetched with a different client and judged by hand. Before the review changed any rules, 36 of 38 links it called confidently dead were confirmed. The two errors were a live security-news site whose article about an expired domain tripped the parked-domain detector, and an unreachable raw IP address that could not be proven gone. The softer “deep link now lands on the homepage” verdict fared worse: 6 of 11, because a project moving to a new domain looks identical to a page being deleted. That is why the headline uses confident failures only, why homepage bounces are reported separately, and why a move to another site is now never counted as a loss.
Why a VPN comparison site measured this, and what we get out of it
vpnrank.io earns commission when readers buy a VPN through our links, and it is fair to ask why such a site is auditing library reading lists. The honest answer is that privacy guides are the neighbourhood we work in, and the same scanner that measures this also finds broken links on pages we might one day ask to cite our own tools. We say that plainly so it can be weighed.
It is also why the study is built the way it is. No guide or library is named. No VPN is recommended, and nothing here is a pitch. The figures are deliberately conservative: where a link could not be read, or had merely moved, we counted it in the guide’s favour. A study written to generate outreach would have published the 56.7% number. The corpus, the classification rules and the hand-review record are kept in version control with the rest of our research, and a librarian who wants the specific dead links on their own guide can ask for them at [email protected].
The next edition re-scans the same corpus, so the change is the story
A single sweep is a snapshot. The measurement that matters is decay over time: of the links that worked this quarter, how many will be gone next quarter, and how many of today’s dead links get fixed. So each edition re-runs the same corpus with the same classification rules and the same hand review, and reports the difference alongside the new level. Guides published after this edition are added to the corpus but kept out of the like-for-like comparison, so a wider corpus never reads as a change in rot.
The next scan is due in December 2026. Every edition states the date it was swept, and earlier editions are kept rather than overwritten.
Related research
- The internet censorship map — which platforms are measurably blocked, country by country, from monthly network measurements.
- The VPN affordability index — what a privacy tool costs as a share of local income.
- A blackout is not a block — measured connectivity outages against measured platform blocking.