SEO Guide · Security

Security & certificates

HTTPS is a ranking signal, and a broken certificate or a "not secure" warning can wipe out trust and traffic overnight. Security also covers the response headers browsers now expect. Here is what the audit checks and why each one matters.

Why security shows up in an SEO audit

Security and SEO overlap more than people expect. Google treats HTTPS as a ranking signal, browsers actively warn users away from insecure pages, and a lapsed certificate takes a site fully offline until it is renewed.

The failures here are unusually harsh because they are all-or-nothing. A missing meta description costs you some click-through; an expired TLS certificate throws a full-page browser warning that stops almost every visitor at the door, and it happens the moment the certificate lapses, with no gradual decline to notice first. The same goes for a protocol downgrade or a mixed-content warning: the page still exists, but the browser makes it look untrustworthy, and both users and search engines respond to that.

Two things sit under this category. First, the transport layer: the TLS certificate and the protocol used to serve every page over HTTPS. Second, the response headers a modern site is expected to send, which harden the site against attacks and signal to browsers that it is maintained.

Read the security explainers

The two areas the audit checks, each with the fixes that clear them.

The security checks we run

Grounded in the real checks the crawler runs on every site.

Keep your certificate and headers healthy

Free to start. Get warned before a certificate lapses or a header goes missing.

Start my free audit