Security

Does site security affect how machines treat my site?

Security is about how safely your site is served: an encrypted connection, the headers that harden it, a clean Safe Browsing record and a published way to report a problem. It matters to a machine because a machine that can't trust the connection or the content has every reason to leave the page out of what it shows people. Below are the 6 checks in this course, what each one looks for, and what good looks like. We read what your server sends from the outside; we can't audit what runs behind it.

All 6 checks count toward your headline score.

The checks in this course

6 checks

Served over a secure HTTPS connection

Why does my site need HTTPS?

HTTPS is a baseline trust and ranking signal; browsers warn users away from insecure pages, and AI engines skip them.

What good looks like Every page loads over HTTPS with a valid, unexpired certificate.

Read more about HTTPS

HTTP redirects to HTTPS

Should http:// redirect to https:// on my site?

If the insecure http:// version still loads, you split trust and risk duplicate content.

What good looks like http:// requests 301-redirect to the https:// version.

Read more about the HTTPS redirect

No mixed (insecure) content

What is mixed content, and why does it break secure pages?

Browsers outright block insecure scripts, styles and frames on an https page — breaking the page — and auto-upgrade insecure images/media, which then break if the host doesn't serve https.

What good looks like Every script, style, frame, image and media file is referenced over https.

Read more about mixed content

Core security headers are set

Which security headers should your site send?

Headers like HSTS, X-Content-Type-Options and a referrer policy harden the site and are a recognised best-practice signal.

What good looks like HSTS, X-Content-Type-Options, X-Frame-Options/CSP frame-ancestors, and a Referrer-Policy are present.

Read more about security headers

Not flagged for malware or phishing

Is my site flagged as unsafe, and what happens if it is?

A site flagged by Google Safe Browsing is hidden behind warnings and won't be recommended.

What good looks like The site is clean in Google Safe Browsing.

Read more about Safe Browsing flags

security.txt is published

What is security.txt, and should your site have one?

A /.well-known/security.txt (RFC 9116) gives security researchers a standard way to report a vulnerability — a maturity signal shipped by Google, GitHub and Meta.

What good looks like A /.well-known/security.txt with the two fields RFC 9116 requires: Contact: and a future Expires: date.

Read more about security.txt

Words you'll meet here

How does your page read to a machine?

A free scan checks these 6 and everything else in about 20 seconds — no signup.

Scan your site free

Rather have it handled? No pitch, just a plain-English chat.

Book a call

The other courses

See all 66 checks