SEO Web Insights
Paste any URL: 36 checks in 7 graded groups plus 18 technology fingerprints, with what to fix first.
Check reference
All 55 readings: 36 checks in 7 graded groups, 18 technology fingerprints and a conditional CNAME reading. Every row has its own address, so you can link a colleague straight to it.
| No. | Check | Reads | Why it matters | How to fix a warn or fail |
|---|---|---|---|---|
| Essential meta · Title, meta description, viewport, charset and language: the basics every search snippet is built from. | ||||
| Title tag | The text of the <title> element in the page <head>. | Search engines usually show the title as the headline of a result, and browsers show it on the tab. | Add a <title> to the <head> that names the page, and keep it to 60 characters or fewer so results do not cut it off. | |
| Meta description | The content of <meta name="description"> in the page <head>. | Search engines often use it as the snippet under a result, which shapes whether people click. | Add <meta name="description"> with a plain summary of the page in 160 characters or fewer. | |
| Viewport | The content of <meta name="viewport"> in the page <head>. | Without it phones lay the page out at desktop width and shrink it, and Google indexes the mobile version. | Add <meta name="viewport" content="width=device-width, initial-scale=1"> to the <head>. | |
| Character encoding | The encoding declared by <meta charset> or a Content-Type <meta http-equiv> in the page. | A declared encoding stops browsers and crawlers from guessing, which can garble accented and non-Latin text. | Declare the encoding with <meta charset="utf-8"> as the first element in the <head>. | |
| Page language | The lang attribute on the root <html> element. | It tells search engines and screen readers which language the page is in, so results and speech match it. | Set the page language on the root element, for example <html lang="en">. | |
| Crawlability · Whether robots.txt and an XML sitemap are where crawlers look for them. | ||||
| robots.txt | Whether the site serves a robots.txt file at its root. | Crawlers read it first to learn which paths they may fetch and where the sitemap is. | Publish a robots.txt file at the site root; one that allows everything and names your sitemap is enough. | |
| XML sitemap | A Sitemap: line in robots.txt whose address answers 200, or else /sitemap.xml at the site root. | A sitemap lists the pages you want indexed, which helps search engines find pages few links point to. | Publish an XML sitemap at /sitemap.xml, or list its address on a Sitemap: line in robots.txt. | |
| Performance · The response itself: HTTP status, page weight, redirect hops and content type. | ||||
| HTTP status | The HTTP status code of the final response, after any redirects. | Search engines index pages that answer 200; other codes tell them the page is missing, moved or failing. | Informational, never graded. | |
| HTML size | The size in kilobytes of the page HTML response body. | All of the HTML must download before the page can finish rendering, which is slowest on mobile connections. | Bring the HTML under 3000 KB, for example by moving inline scripts, styles and embedded images into separate files. | |
| Redirect chain | How many redirects were followed from the submitted address to the final page. | Each redirect adds a round trip before the page starts loading, and long chains can stop crawlers. | Link to the final address directly, or shorten the chain so the page is reached in two redirects or fewer. | |
| Content-Type | The Content-Type response header of the page. | It tells browsers how to handle the response, for example as HTML and in which character encoding. | Informational, never graded. | |
| Technical SEO · Canonical, robots meta, H1, structured data, internal and external links, word count. | ||||
| Canonical URL | The href of <link rel="canonical"> in the page <head>. | It tells search engines which address is preferred when the same page is reachable at several URLs. | Add <link rel="canonical" href="…"> pointing to the preferred, absolute URL of this page. | |
| Robots meta tag | The content of <meta name="robots"> in the page <head>; when absent, crawlers assume index, follow. | A noindex value asks search engines to leave the page out of their results. | If this page should appear in search results, remove noindex from its robots meta tag. | |
| Main heading | How many <h1> elements the page contains. | One <h1> gives the page a clear main topic for readers, screen readers and search engines. | Give the page exactly one <h1> that states its main topic, and use <h2> to <h6> for the headings under it. | |
| Structured data | The <script type="application/ld+json"> blocks on the page and their @type values. | Structured data describes the page in schema.org terms, which search engines can use for rich results. | Informational, never graded. | |
| Internal links | How many links on the page point to the same host, including relative links. | Internal links are how crawlers and visitors reach the rest of the site from this page. | Informational, never graded. | |
| External links | How many links on the page point to other hosts. | Links out show the sources a page relies on and where it sends its visitors. | Informational, never graded. | |
| Word count | The number of words of text on the page; under 300 is noted as thin content. | Very short pages can give search engines too little text to tell what the page is about. | Informational, never graded. | |
| Security · HSTS, CSP, framing and sniffing protection, referrer policy and cookie flags. | ||||
| Strict-Transport-Security | The Strict-Transport-Security response header and its max-age value. | It tells browsers to use only HTTPS for the site, which blocks downgrade attacks on later visits. | Send Strict-Transport-Security over HTTPS with a max-age of at least 15552000 seconds (six months). | |
| Content-Security-Policy | Whether the response sends a Content-Security-Policy header. | A policy limits where scripts and other resources may load from, which reduces the damage injected code can do. | Send a Content-Security-Policy header that lists the sources the page may load from, starting from default-src 'self'. | |
| X-Content-Type-Options | The X-Content-Type-Options response header, which should be exactly nosniff. | nosniff stops browsers from guessing a file type, so an uploaded file cannot be run as a script or stylesheet. | Send the header X-Content-Type-Options: nosniff on every response. | |
| X-Frame-Options | The X-Frame-Options response header, which should be DENY or SAMEORIGIN. | It stops other sites from loading the page in a hidden frame to trick visitors into clicking (clickjacking). | Send X-Frame-Options: DENY, or SAMEORIGIN if the site needs to frame its own pages. | |
| Referrer-Policy | Whether the response sends a Referrer-Policy header. | It controls how much of the page address is passed to other sites when a visitor follows a link. | Send a Referrer-Policy header, for example Referrer-Policy: strict-origin-when-cross-origin. | |
| Cookie flags | The Set-Cookie headers on the response, checked for the Secure, HttpOnly and SameSite attributes. | These attributes keep cookies off plain HTTP, out of reach of page scripts, and out of most cross-site requests. | Add the Secure, HttpOnly and SameSite attributes to the cookies this page sets. | |
| Social sharing · Open Graph and Twitter Card tags that decide how a shared link looks. | ||||
| Open Graph title | The content of <meta property="og:title"> in the page <head>. | Social networks and chat apps use it as the headline of a shared link preview. | Add <meta property="og:title" content="…"> with the title you want shown when the page is shared. | |
| Open Graph description | The content of <meta property="og:description"> in the page <head>. | Most link previews show it as the summary line under the headline. | Add <meta property="og:description" content="…"> with a one- or two-sentence summary of the page. | |
| Open Graph image | The content of <meta property="og:image"> in the page <head>. | Link previews without an image are smaller and easier to miss in a feed or a chat. | Add <meta property="og:image" content="…"> with the absolute URL of an image, ideally 1200×630 pixels. | |
| Open Graph URL | The content of <meta property="og:url"> in the page <head>. | It names the address shares should point to, so shares of different URL variants count as one page. | Informational, never graded. | |
| Open Graph type | The content of <meta property="og:type"> in the page <head>. | It says what kind of object the page is, such as website or article; readers assume website when it is absent. | Informational, never graded. | |
| Twitter card | The content of <meta name="twitter:card"> in the page <head>. | It picks the preview layout on X (Twitter); without it X falls back to the Open Graph tags. | Informational, never graded. | |
| DNS & email · A, AAAA, NS and MX records, plus SPF and DMARC for the domain’s email. | ||||
| IPv4 addresses | The A records (IPv4 addresses) of the page host name. | A records are how most browsers find the server that hosts the site. | Informational, never graded. | |
| IPv6 addresses | The AAAA records (IPv6 addresses) of the page host name. | They let visitors on IPv6 networks reach the site directly. | Informational, never graded. | |
| Name servers | The NS records of the page's domain: the nearest name at or above the page host that has name servers of its own. | Name servers answer every DNS lookup for the domain; without working ones the site cannot be found. | Set the name servers for your domain at your registrar or DNS host. | |
| Mail servers | The MX records of the page's domain. | MX records name the servers that accept email for the domain; a host that receives no mail needs none. | Informational, never graded. | |
| SPF | The TXT records of the page's domain, looking for one that starts with v=spf1. | SPF lists the servers allowed to send mail for the domain, which helps receivers reject forged senders. | Publish a TXT record starting v=spf1 that lists your mail senders, or v=spf1 -all if the domain sends no email. | |
| DMARC | The TXT records at _dmarc.<page host name>, then at _dmarc.<page's domain>, looking for one that starts with v=DMARC1. | DMARC tells receivers what to do with mail that fails SPF or DKIM, and where to send reports about it. | Publish a DMARC policy as a TXT record at _dmarc.<your domain>, for example v=DMARC1; p=none to start. | |
| Canonical name (CNAME) | The CNAME record of the page host name, shown only when it has one. | A CNAME shows the host is an alias of another name, often a CDN or hosting provider. | Informational, never graded. | |
| Technology · Fingerprints of the platforms, frameworks and hosts a page runs on. Reported, never graded. | ||||
| WordPress | wp-content or wp-includes paths, or a WordPress generator meta tag, in the page HTML. | The CMS decides which updates, plugins and security advisories apply to the site. | Informational, never graded. | |
| React | A data-reactroot attribute or Next.js build markers in the page HTML. | Pages built with a JavaScript framework may need server rendering for crawlers to see all their content. | Informational, never graded. | |
| Next.js | A __NEXT_DATA__ script or /_next/static/ paths in the page HTML. | The framework decides whether pages reach crawlers as ready HTML or are built in the browser. | Informational, never graded. | |
| Vue.js | data-v- scoped-style attributes or a __NUXT__ marker in the page HTML. | Pages built with a JavaScript framework may need server rendering for crawlers to see all their content. | Informational, never graded. | |
| Angular | An ng-version or ng-app attribute in the page HTML. | Pages built with a JavaScript framework may need server rendering for crawlers to see all their content. | Informational, never graded. | |
| Svelte | svelte- class names or a __sveltekit marker in the page HTML. | Pages built with a JavaScript framework may need server rendering for crawlers to see all their content. | Informational, never graded. | |
| jQuery | A jQuery file name, such as jquery-3.7.1.min.js or jquery.min.js, in the page HTML. | Old jQuery versions have published security advisories, so it is worth knowing which one a site loads. | Informational, never graded. | |
| Bootstrap | bootstrap.min.css or bootstrap.min.js in the page HTML. | A CSS framework shapes the page weight and the markup the page is built from. | Informational, never graded. | |
| Tailwind CSS | tailwindcss or tailwind.min.css in the page HTML. | A CSS framework shapes the page weight and the markup the page is built from. | Informational, never graded. | |
| Cloudflare | A CF-Ray response header, or cloudflare in the Server header. | A CDN in front of the site sets caching and some response headers, so it is often where header fixes go. | Informational, never graded. | |
| Nginx | A Server response header that starts with nginx. | The web server is usually where security headers and redirects are configured. | Informational, never graded. | |
| Apache | A Server response header that starts with Apache. | The web server is usually where security headers and redirects are configured. | Informational, never graded. | |
| PHP | PHP in the X-Powered-By response header. | An X-Powered-By header tells anyone which runtime the site uses; OWASP advises not sending it. | Informational, never graded. | |
| Express | Express in the X-Powered-By response header. | An X-Powered-By header tells anyone which runtime the site uses; OWASP advises not sending it. | Informational, never graded. | |
| Google Analytics | google-analytics.com, gtag/js or googletagmanager references in the page HTML. | Third-party analytics adds scripts to every page view and, in many countries, a consent requirement. | Informational, never graded. | |
| Vercel | An X-Vercel-Id response header. | The hosting platform is usually where headers, redirects and caching for the site are configured. | Informational, never graded. | |
| Netlify | An X-NF-Request-Id response header. | The hosting platform is usually where headers, redirects and caching for the site are configured. | Informational, never graded. | |
| Shopify | cdn.shopify.com or Shopify.theme references in the page HTML. | The store platform decides which headers, redirects and markup the site owner can change. | Informational, never graded. | |