The world's top 1,000 websites have patched the "Heartbleed" security flaw to protect servers from exploitation, but 2% of the millions of sites were still vulnerable as of last week, according to the California-based security firm.
On Thursday, California-based Menifee conducted a survey of one million top websites based on their rankings on Alexa Internet, which collects internet traffic data.
Of the top 1,000 Alexa sites, all had been patched with the latest OpenSSL Libraries, Daniel Cid, Sucuri's Chief Technology Officer, confirmed in an email on Sunday. Heartbleed, the nickname for the flaw in OpenSSL, an open-source cryptographic library that powers SSL (Secure Sockets Layer) or TLS (Transport Layer Security) encryption, was discovered by Neel Mehta, a security engineer at Google, and researchers at security services firm Codenomicon, earlier this month.

