Earlier quoted context omitted.
Counterpoint: most websites are not useful. If we only count useful websites a much higher percentage of them are using XSLT. But useful websites are much less likely to be infested by the all consuming Goo admalware.
[Citation needed] Seriously, i doubt this.
There was a time where the standard way to build a highly interactive SPA was using SOAP services on the backend combined with iframes on the front end that executed XSLT in the background to update the DOM.
Obviously such an approach is extremely out of date and you won't find it on any websites you use. But, a lot of critical enterprise software was built this way and is kind of stuck like this.