Security headers checker

Check the five response headers that harden a site in the browser, plus any mixed content loading over plain http from an https page.

Measuring rankings in

Runs the full audit on your live site. Your report opens in your dashboard.

What this checks

This reads five response headers from your live page and reports which are set: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options and Referrer-Policy. HSTS is weighted highest because it is the one whose absence has a direct exploit. Alongside it we look for mixed content, resources requested over plain http from an https page, and forms that submit over http, which exposes whatever is typed into them.

Why it matters

These headers are not a ranking factor and they belong in a technical audit anyway, because they are cheap, they are set once at the edge, and their absence is a genuine risk rather than a theoretical one. Mixed content is the item with a visible consequence: browsers block it or mark the page as not secure, which costs trust on exactly the pages, checkout and contact forms, where trust is worth the most.

How to read a bad result

Missing HSTS is a warning; the three lower weighted headers are reported as information because sensible defaults now cover much of what they used to. Content-Security-Policy is the one that repays real thought and the one most likely to break a page if it is pasted in from an example, so introduce it in report only mode first. Insecure forms are the finding to act on today, ahead of any header.

This page leads with one dimension, and the audit behind it is the whole engine: Visibility100x scores36 checks on every page it crawls, across crawlability, on page SEO, structured data, AI and GEO, content, media, performance and security. Running it here gives you the same report a paying customer gets, on a free account with no card.

Questions people ask

Do security headers affect SEO?

Not directly. HTTPS itself is a light ranking signal, and a browser warning on a page with a form has a much larger effect on conversion than any ranking change would.

Which header should I add first?

Strict-Transport-Security, once you are certain every subdomain serves https. It is one line at the edge and it closes the downgrade attack that the others do not touch.

What is mixed content?

An https page loading an image, script or stylesheet over plain http. Browsers block the dangerous kinds outright and flag the rest, so the page either breaks quietly or looks untrustworthy.

Run your first audit
in about a minute

Free account, no card. Paste your URL and get a real, scored report of your AI and search visibility.

Measuring rankings in