301→302301→302
A temporary redirect where a permanent one belongs.
Found by Redirect checker →
redirect loopredirect loop
The URL redirects back to itself and never settles.
Found by Redirect checker →
Audit

HTTPS and security headers check

HTTP URLs, mixed content, missing HSTS, insecure forms and subresources, plus a security-headers check for a single URL.

HTTPS and security headers check

Per URL

security-check and headers-check read the response headers of one page.

HTTPS and security headers check

Across a crawl

Mixed content, insecure forms and http links on https pages are reported per page.

How it works

Three steps, one saved scan

  1. Read one URL's response

    security-check sends a single GET request and reads the response headers, the cookie flags and the http-to-https redirect.

  2. Score six security headers

    HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy give a 0-100 score and an A-F grade.

  3. Flag mixed content across a crawl

    On a crawl, each page is checked for http resources, insecure form targets and missing or repeated security headers.

What it checks

Checks in this feature

CheckWhat it meansSeverityEvidence
FORM_URL_INSECUREA form submits to an http:// action, so the data it sends is not encryptedCriticalForm action URL on the page
HTTP_URLThe URL is served over http instead of httpsImportantPage URL
MIXED_CONTENTAn https page loads a resource over httpImportantPage URL and the http resource URL
INSECURE_SUBRESOURCEAn https page loads an image, script or stylesheet over httpImportantResource URL and the linking page
MISSING_HSTSThe page sends no Strict-Transport-Security headerTipResponse headers of the page
MISSING_CSPAn HTML page sends no Content-Security-Policy headerTipResponse headers of the page
MISSING_X_FRAME_OPTIONSThe page has neither X-Frame-Options nor a CSP frame-ancestors directiveTipResponse headers of the page
DUPLICATE_SECURITY_HEADERA security header is sent more than once on the same responseTipHeader name and the response that repeats it
How to run it

One command

bash
seohead security-check --url https://example.com/

Install first: installation guide. Every command also runs as an MCP tool for AI agents.

Related checks

From the check registry

HTTP_URLMIXED_CONTENTMISSING_HSTSINSECURE_SUBRESOURCEFORM_URL_INSECURE
Learn more

From the blog and glossary

FAQ

Questions

HTTPS and security headers check
No. security-check sends ordinary GET requests and reads what the site already sends. Probing for paths such as .git or .env is off by default and runs only with --probe-paths.
Each header adds points: HSTS 20, CSP 20, X-Content-Type-Options 15, X-Frame-Options 15, Referrer-Policy 15, Permissions-Policy 15. 90 or more is A, 75 B, 60 C, 40 D, 20 E, and anything lower is F. A CSP frame-ancestors directive counts for X-Frame-Options.
No. It checks that each header is present. A weak CSP that is present still gets full points.
No. security-check covers one URL. The page-level checks in this list come from a crawl, and they appear per page in the crawl results.

Check your redirects locally