Features / Security headers check
Security headers check: HSTS, CSP and the rest
SEOSage looks at the response your home page sends and tells you which of the common protective headers are missing. It runs in every crawl.
Jump to: The screen · What it checks · Examples · How it works · Questions
See security headers check in 18 seconds
SEOSage checks the home page for five security headers and names the ones that are missing in the Issues list.
Read the video transcript
Is your site missing security headers? SEOSage looks for five of them, on the home page. If any are missing, the Issues list names them. Start your fourteen-day free trial at seosage.co.
See which headers are missing
If any are missing, the Issues list shows Security headers missing, a notice, with the names of the headers.
/The home page does not send: Content-Security-Policy, Referrer-Policy. These headers protect visitors from clickjacking and content-type tricks.
The five headers it looks for
- Strict-Transport-Security (HSTS): Tells browsers to use https only
- Content-Security-Policy (CSP): Limits where scripts and other files can load from
- X-Frame-Options: Stops other sites from showing your page inside a frame
- X-Content-Type-Options: Stops browsers from guessing a file type
- Referrer-Policy: Controls how much address information is sent to other sites
Good to know
These headers protect your visitors and your site. SEOSage reports them as a notice, not an error, because many sites run without some of them.
The check reads the home page response, once for each site. HSTS is only checked when the home page uses https, and X-Frame-Options is not reported if your Content-Security-Policy already sets frame-ancestors.
What the issue says
The message in the Issues list looks like this:
- Security headers missing. The home page does not send: Content-Security-Policy, Referrer-Policy. These headers protect visitors from clickjacking and content-type tricks.
How it works in three steps
- Crawl the website.The check runs with all the others.
- Open Security headers missing.It is in the Issues list, under Security, and names the headers that are not sent.
- Add the headers on your server.Then crawl again to confirm.
Related: local site audit · SEO crawler · free page check.
Questions about this check
What are security headers?
They are instructions your server sends with a page. They tell the browser how to handle https, framing, file types, scripts and referrer information.
Which security headers does SEOSage check?
HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and Referrer-Policy.
Does it check every page?
It reads the response of the home page, once for each site.
Is a missing header an error?
No. It is shown as a notice. The headers protect visitors, and many sites do not send all of them.
How do I add a security header?
On your server or host. Where depends on your setup, for example the web server settings, a plugin or the host's control panel.
Can SEOSage check a site on my own computer?
Yes. Local sites such as localhost:3000 are crawled with all the checks.
More SEOSage features
Every check and tool in the app, each with its own page.
SEO crawler Crawl settings Local site audit Custom extraction Internal linking tool Orphan pages Link strength Canonical tag checker Title tag width checker URL structure checker Keyword cannibalization Search Console quick wins Competitor analysis Weekly SEO to-do list Fix and re-check White-label reports Ask Claude All features
Try it on your own site
Download SEOSage for Mac or Windows. $19 a month or $149 a year, free for 14 days, no page limits.