HTTPS is a ranking signal, and a broken certificate or a "not secure" warning can wipe out trust and traffic overnight. Security also covers the response headers browsers now expect. Here is what the audit checks and why each one matters.
Security and SEO overlap more than people expect. Google treats HTTPS as a ranking signal, browsers actively warn users away from insecure pages, and a lapsed certificate takes a site fully offline until it is renewed.
The failures here are unusually harsh because they are all-or-nothing. A missing meta description costs you some click-through; an expired TLS certificate throws a full-page browser warning that stops almost every visitor at the door, and it happens the moment the certificate lapses, with no gradual decline to notice first. The same goes for a protocol downgrade or a mixed-content warning: the page still exists, but the browser makes it look untrustworthy, and both users and search engines respond to that.
Two things sit under this category. First, the transport layer: the TLS certificate and the protocol used to serve every page over HTTPS. Second, the response headers a modern site is expected to send, which harden the site against attacks and signal to browsers that it is maintained.
The two areas the audit checks, each with the fixes that clear them.
Certificate expiry, name mismatches, outdated protocol versions and weak ciphers, and mixed content, the failures that trigger a browser "not secure" warning and how to clear each one.
HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and secure cookie flags: what each header does, and the one-line configuration that adds it.
Grounded in the real checks the crawler runs on every site.
Free to start. Get warned before a certificate lapses or a header goes missing.
Start my free audit