Skip to content
SEOSage

Features / Security headers check

Security headers check: HSTS, CSP and the rest

SEOSage looks at the response your home page sends and tells you which of the common protective headers are missing. It runs in every crawl.

Download SEOSage

Jump to: The screen · What it checks · Examples · How it works · Questions

See security headers check in 18 seconds

SEOSage checks the home page for five security headers and names the ones that are missing in the Issues list.

Read the video transcript

Is your site missing security headers? SEOSage looks for five of them, on the home page. If any are missing, the Issues list names them. Start your fourteen-day free trial at seosage.co.

See which headers are missing

If any are missing, the Issues list shows Security headers missing, a notice, with the names of the headers.

Issues · Security headers missing
Security headers missingChecked once for each site.
IssueWhat it says
Security headers missing Notice
/
The home page does not send: Content-Security-Policy, Referrer-Policy. These headers protect visitors from clickjacking and content-type tricks.
door left open. lock it.

The five headers it looks for

  • Strict-Transport-Security (HSTS): Tells browsers to use https only
  • Content-Security-Policy (CSP): Limits where scripts and other files can load from
  • X-Frame-Options: Stops other sites from showing your page inside a frame
  • X-Content-Type-Options: Stops browsers from guessing a file type
  • Referrer-Policy: Controls how much address information is sent to other sites

Good to know

These headers protect your visitors and your site. SEOSage reports them as a notice, not an error, because many sites run without some of them.

The check reads the home page response, once for each site. HSTS is only checked when the home page uses https, and X-Frame-Options is not reported if your Content-Security-Policy already sets frame-ancestors.

What the issue says

The message in the Issues list looks like this:

  • Security headers missing. The home page does not send: Content-Security-Policy, Referrer-Policy. These headers protect visitors from clickjacking and content-type tricks.

How it works in three steps

  1. Crawl the website.The check runs with all the others.
  2. Open Security headers missing.It is in the Issues list, under Security, and names the headers that are not sent.
  3. Add the headers on your server.Then crawl again to confirm.

Related: local site audit · SEO crawler · free page check.

Questions about this check

What are security headers?

They are instructions your server sends with a page. They tell the browser how to handle https, framing, file types, scripts and referrer information.

Which security headers does SEOSage check?

HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and Referrer-Policy.

Does it check every page?

It reads the response of the home page, once for each site.

Is a missing header an error?

No. It is shown as a notice. The headers protect visitors, and many sites do not send all of them.

How do I add a security header?

On your server or host. Where depends on your setup, for example the web server settings, a plugin or the host's control panel.

Can SEOSage check a site on my own computer?

Yes. Local sites such as localhost:3000 are crawled with all the checks.

Try it on your own site

Download SEOSage for Mac or Windows. $19 a month or $149 a year, free for 14 days, no page limits.

Download SEOSage