Start with HTTPS
Search engines, browsers, analytics, and users all expect public pages to settle on HTTPS. Check the clear-text version so old links and typed URLs do not strand visitors on HTTP.
Security headers · HTTPS and source evidence
Run a bounded public check for HTTPS delivery, clear-text HTTP redirect behavior, HSTS, Content-Security-Policy, frame protection, nosniff, referrer policy, permissions policy, cross-origin declarations, mixed-content candidates, and unnecessary technology disclosure.
No sample security score, SSL grade, TLS certificate verdict, vulnerability claim, compliance badge, ranking benefit, or manufactured recommendation appears before a live bounded request.
Security posture supports trust and crawl quality
Search engines, browsers, analytics, and users all expect public pages to settle on HTTPS. Check the clear-text version so old links and typed URLs do not strand visitors on HTTP.
CSP, HSTS, frame protections, and permissions policies are safest when rolled out with template knowledge and testing. This report shows the declarations that deserve review.
Mixed-content and third-party resource candidates often live in templates, tag managers, embeds, and legacy media. Pair this tool with resource and waterfall checks for execution evidence.