SEO Web Insights

Paste any URL: 36 checks in 7 graded groups plus 18 technology fingerprints, with what to fix first.

1TiTitle tag 2StHTTP status 3MdMeta description 4VpViewport 5HsStrict-Transport-Security 6CpContent-Security-Policy 7XcX-Content-Type-Options 8XfX-Frame-Options 9RpReferrer-Policy 10CkCookie flags 11CsCharacter encoding 12LgPage language 13OtOpen Graph title 14OdOpen Graph description 15OiOpen Graph image 16OuOpen Graph URL 17OyOpen Graph type 18TcTwitter card 19Rtrobots.txt 20SmXML sitemap 21CnCanonical URL 22RmRobots meta tag 23HdMain heading 24JlStructured data 25IlInternal links 26ElExternal links 27WcWord count 28PsHTML size 29RdRedirect chain 30CtContent-Type 31AIPv4 addresses 32AaIPv6 addresses 33NsName servers 34MxMail servers 35SpSPF 36DmDMARC
CNAME & technology 37CmCanonical name (CNAME) 38WpWordPress 39ReReact 40NxNext.js 41VuVue.js 42AgAngular 43SvSvelte 44JqjQuery 45BsBootstrap 46TwTailwind CSS 47CfCloudflare 48NgNginx 49ApApache 50PhPHP 51ExExpress 52GaGoogle Analytics 53VcVercel 54NlNetlify 55ShShopify

Check reference

All 55 readings: 36 checks in 7 graded groups, 18 technology fingerprints and a conditional CNAME reading. Every row has its own address, so you can link a colleague straight to it.

No.CheckReadsWhy it mattersHow to fix a warn or fail
Essential meta · Title, meta description, viewport, charset and language: the basics every search snippet is built from.
Title tagThe text of the <title> element in the page <head>.Search engines usually show the title as the headline of a result, and browsers show it on the tab.Add a <title> to the <head> that names the page, and keep it to 60 characters or fewer so results do not cut it off.
Meta descriptionThe content of <meta name="description"> in the page <head>.Search engines often use it as the snippet under a result, which shapes whether people click.Add <meta name="description"> with a plain summary of the page in 160 characters or fewer.
ViewportThe content of <meta name="viewport"> in the page <head>.Without it phones lay the page out at desktop width and shrink it, and Google indexes the mobile version.Add <meta name="viewport" content="width=device-width, initial-scale=1"> to the <head>.
Character encodingThe encoding declared by <meta charset> or a Content-Type <meta http-equiv> in the page.A declared encoding stops browsers and crawlers from guessing, which can garble accented and non-Latin text.Declare the encoding with <meta charset="utf-8"> as the first element in the <head>.
Page languageThe lang attribute on the root <html> element.It tells search engines and screen readers which language the page is in, so results and speech match it.Set the page language on the root element, for example <html lang="en">.
Crawlability · Whether robots.txt and an XML sitemap are where crawlers look for them.
robots.txtWhether the site serves a robots.txt file at its root.Crawlers read it first to learn which paths they may fetch and where the sitemap is.Publish a robots.txt file at the site root; one that allows everything and names your sitemap is enough.
XML sitemapA Sitemap: line in robots.txt whose address answers 200, or else /sitemap.xml at the site root.A sitemap lists the pages you want indexed, which helps search engines find pages few links point to.Publish an XML sitemap at /sitemap.xml, or list its address on a Sitemap: line in robots.txt.
Performance · The response itself: HTTP status, page weight, redirect hops and content type.
HTTP statusThe HTTP status code of the final response, after any redirects.Search engines index pages that answer 200; other codes tell them the page is missing, moved or failing.Informational, never graded.
HTML sizeThe size in kilobytes of the page HTML response body.All of the HTML must download before the page can finish rendering, which is slowest on mobile connections.Bring the HTML under 3000 KB, for example by moving inline scripts, styles and embedded images into separate files.
Redirect chainHow many redirects were followed from the submitted address to the final page.Each redirect adds a round trip before the page starts loading, and long chains can stop crawlers.Link to the final address directly, or shorten the chain so the page is reached in two redirects or fewer.
Content-TypeThe Content-Type response header of the page.It tells browsers how to handle the response, for example as HTML and in which character encoding.Informational, never graded.
Technical SEO · Canonical, robots meta, H1, structured data, internal and external links, word count.
Canonical URLThe href of <link rel="canonical"> in the page <head>.It tells search engines which address is preferred when the same page is reachable at several URLs.Add <link rel="canonical" href="…"> pointing to the preferred, absolute URL of this page.
Robots meta tagThe content of <meta name="robots"> in the page <head>; when absent, crawlers assume index, follow.A noindex value asks search engines to leave the page out of their results.If this page should appear in search results, remove noindex from its robots meta tag.
Main headingHow many <h1> elements the page contains.One <h1> gives the page a clear main topic for readers, screen readers and search engines.Give the page exactly one <h1> that states its main topic, and use <h2> to <h6> for the headings under it.
Structured dataThe <script type="application/ld+json"> blocks on the page and their @type values.Structured data describes the page in schema.org terms, which search engines can use for rich results.Informational, never graded.
Word countThe number of words of text on the page; under 300 is noted as thin content.Very short pages can give search engines too little text to tell what the page is about.Informational, never graded.
Security · HSTS, CSP, framing and sniffing protection, referrer policy and cookie flags.
Strict-Transport-SecurityThe Strict-Transport-Security response header and its max-age value.It tells browsers to use only HTTPS for the site, which blocks downgrade attacks on later visits.Send Strict-Transport-Security over HTTPS with a max-age of at least 15552000 seconds (six months).
Content-Security-PolicyWhether the response sends a Content-Security-Policy header.A policy limits where scripts and other resources may load from, which reduces the damage injected code can do.Send a Content-Security-Policy header that lists the sources the page may load from, starting from default-src 'self'.
X-Content-Type-OptionsThe X-Content-Type-Options response header, which should be exactly nosniff.nosniff stops browsers from guessing a file type, so an uploaded file cannot be run as a script or stylesheet.Send the header X-Content-Type-Options: nosniff on every response.
X-Frame-OptionsThe X-Frame-Options response header, which should be DENY or SAMEORIGIN.It stops other sites from loading the page in a hidden frame to trick visitors into clicking (clickjacking).Send X-Frame-Options: DENY, or SAMEORIGIN if the site needs to frame its own pages.
Referrer-PolicyWhether the response sends a Referrer-Policy header.It controls how much of the page address is passed to other sites when a visitor follows a link.Send a Referrer-Policy header, for example Referrer-Policy: strict-origin-when-cross-origin.
Cookie flagsThe Set-Cookie headers on the response, checked for the Secure, HttpOnly and SameSite attributes.These attributes keep cookies off plain HTTP, out of reach of page scripts, and out of most cross-site requests.Add the Secure, HttpOnly and SameSite attributes to the cookies this page sets.
Social sharing · Open Graph and Twitter Card tags that decide how a shared link looks.
Open Graph titleThe content of <meta property="og:title"> in the page <head>.Social networks and chat apps use it as the headline of a shared link preview.Add <meta property="og:title" content="…"> with the title you want shown when the page is shared.
Open Graph descriptionThe content of <meta property="og:description"> in the page <head>.Most link previews show it as the summary line under the headline.Add <meta property="og:description" content="…"> with a one- or two-sentence summary of the page.
Open Graph imageThe content of <meta property="og:image"> in the page <head>.Link previews without an image are smaller and easier to miss in a feed or a chat.Add <meta property="og:image" content="…"> with the absolute URL of an image, ideally 1200×630 pixels.
Open Graph URLThe content of <meta property="og:url"> in the page <head>.It names the address shares should point to, so shares of different URL variants count as one page.Informational, never graded.
Open Graph typeThe content of <meta property="og:type"> in the page <head>.It says what kind of object the page is, such as website or article; readers assume website when it is absent.Informational, never graded.
Twitter cardThe content of <meta name="twitter:card"> in the page <head>.It picks the preview layout on X (Twitter); without it X falls back to the Open Graph tags.Informational, never graded.
DNS & email · A, AAAA, NS and MX records, plus SPF and DMARC for the domain’s email.
IPv4 addressesThe A records (IPv4 addresses) of the page host name.A records are how most browsers find the server that hosts the site.Informational, never graded.
IPv6 addressesThe AAAA records (IPv6 addresses) of the page host name.They let visitors on IPv6 networks reach the site directly.Informational, never graded.
Name serversThe NS records of the page's domain: the nearest name at or above the page host that has name servers of its own.Name servers answer every DNS lookup for the domain; without working ones the site cannot be found.Set the name servers for your domain at your registrar or DNS host.
Mail serversThe MX records of the page's domain.MX records name the servers that accept email for the domain; a host that receives no mail needs none.Informational, never graded.
SPFThe TXT records of the page's domain, looking for one that starts with v=spf1.SPF lists the servers allowed to send mail for the domain, which helps receivers reject forged senders.Publish a TXT record starting v=spf1 that lists your mail senders, or v=spf1 -all if the domain sends no email.
DMARCThe TXT records at _dmarc.<page host name>, then at _dmarc.<page's domain>, looking for one that starts with v=DMARC1.DMARC tells receivers what to do with mail that fails SPF or DKIM, and where to send reports about it.Publish a DMARC policy as a TXT record at _dmarc.<your domain>, for example v=DMARC1; p=none to start.
Canonical name (CNAME)The CNAME record of the page host name, shown only when it has one.A CNAME shows the host is an alias of another name, often a CDN or hosting provider.Informational, never graded.
Technology · Fingerprints of the platforms, frameworks and hosts a page runs on. Reported, never graded.
WordPresswp-content or wp-includes paths, or a WordPress generator meta tag, in the page HTML.The CMS decides which updates, plugins and security advisories apply to the site.Informational, never graded.
ReactA data-reactroot attribute or Next.js build markers in the page HTML.Pages built with a JavaScript framework may need server rendering for crawlers to see all their content.Informational, never graded.
Next.jsA __NEXT_DATA__ script or /_next/static/ paths in the page HTML.The framework decides whether pages reach crawlers as ready HTML or are built in the browser.Informational, never graded.
Vue.jsdata-v- scoped-style attributes or a __NUXT__ marker in the page HTML.Pages built with a JavaScript framework may need server rendering for crawlers to see all their content.Informational, never graded.
AngularAn ng-version or ng-app attribute in the page HTML.Pages built with a JavaScript framework may need server rendering for crawlers to see all their content.Informational, never graded.
Sveltesvelte- class names or a __sveltekit marker in the page HTML.Pages built with a JavaScript framework may need server rendering for crawlers to see all their content.Informational, never graded.
jQueryA jQuery file name, such as jquery-3.7.1.min.js or jquery.min.js, in the page HTML.Old jQuery versions have published security advisories, so it is worth knowing which one a site loads.Informational, never graded.
Bootstrapbootstrap.min.css or bootstrap.min.js in the page HTML.A CSS framework shapes the page weight and the markup the page is built from.Informational, never graded.
Tailwind CSStailwindcss or tailwind.min.css in the page HTML.A CSS framework shapes the page weight and the markup the page is built from.Informational, never graded.
CloudflareA CF-Ray response header, or cloudflare in the Server header.A CDN in front of the site sets caching and some response headers, so it is often where header fixes go.Informational, never graded.
NginxA Server response header that starts with nginx.The web server is usually where security headers and redirects are configured.Informational, never graded.
ApacheA Server response header that starts with Apache.The web server is usually where security headers and redirects are configured.Informational, never graded.
PHPPHP in the X-Powered-By response header.An X-Powered-By header tells anyone which runtime the site uses; OWASP advises not sending it.Informational, never graded.
ExpressExpress in the X-Powered-By response header.An X-Powered-By header tells anyone which runtime the site uses; OWASP advises not sending it.Informational, never graded.
Google Analyticsgoogle-analytics.com, gtag/js or googletagmanager references in the page HTML.Third-party analytics adds scripts to every page view and, in many countries, a consent requirement.Informational, never graded.
VercelAn X-Vercel-Id response header.The hosting platform is usually where headers, redirects and caching for the site are configured.Informational, never graded.
NetlifyAn X-NF-Request-Id response header.The hosting platform is usually where headers, redirects and caching for the site are configured.Informational, never graded.
Shopifycdn.shopify.com or Shopify.theme references in the page HTML.The store platform decides which headers, redirects and markup the site owner can change.Informational, never graded.