Skip to content

Search PixyScan

Product
Explore · Trust

Keep your site safe and trusted

Browsers warn visitors away from sites with expired certificates or unsafe files, and search engines notice too. The Trust view checks your SSL certificate, your security headers and any file still loaded over plain http, on every page.

early warning before expiry
30 days
early warning before expiry
security headers checked
4
security headers checked
views: overview, table, http files
3
views: overview, table, http files
app.pixyscan.com/w/…/s/…/trust
The Trust overview: the certificate card with issuer and soonest expiry, and the header coverage card counting pages without HSTS, CSP, clickjacking protection and a referrer policy.

What it shows you

Three things that make a site trusted

  • The certificate

    Who issued it, when it expires, and how many pages expire within 30 days or have already expired. An expired certificate shows visitors a full-page warning.

  • Header coverage

    Security headers are instructions your server sends with every page. The view counts pages missing each one, so you can fix them in your server settings once.

  • Insecure content

    Scripts, images and styles loaded over http:// on a secure page. Browsers block insecure scripts outright and mark the page as not fully secure.

The headers

What each header protects you from

Each one is a single line in your server or CDN settings. Add it once and it covers every page.

  1. HSTS

    Tells browsers to always use https for your site, even if someone types http.

    Strict-Transport-Security: max-age=31536000

  2. CSP

    Lists where scripts and files may load from, which blocks most injected code.

    Start in report-only mode, then enforce a policy such as default-src 'self'.

  3. Clickjacking

    Stops other sites showing your page inside a hidden frame to trick clicks.

    X-Frame-Options: SAMEORIGIN, or frame-ancestors in your CSP.

  4. Referrer-Policy

    Controls how much of your page address is passed on when visitors click away.

    Referrer-Policy: strict-origin-when-cross-origin

What it finds

Trust problems, worst first

Certificate and http problems are critical: visitors see them straight away. Missing headers are quieter but just as easy to fix.

  • Critical

    A page is served over http, not https

    Browsers label the page “Not secure”, and anything typed into it can be read on the way.

    How to fix: Install a certificate (Let's Encrypt is free) and send every http address to https with a 301 redirect.

  • Critical

    The SSL certificate has expired

    Visitors see a full-page warning and most will leave.

    How to fix: Renew the certificate now, reload your server, and turn on automatic renewal.

  • Critical

    Scripts or styles load over http

    Browsers block them, so parts of your page can break or look wrong.

    How to fix: Change each http:// address in the Insecure content tab to https://.

  • Critical

    Images or other files load over http

    The page is marked as not fully secure, and the padlock disappears.

    How to fix: Load every image, video and font from an https:// address.

  • Important

    The certificate expires within 30 days

    If renewal fails, the site goes behind a warning on the day it expires.

    How to fix: Renew early, and check your server or CDN is serving the new certificate.

  • Important

    HSTS, CSP or clickjacking protection is missing

    Without them, your visitors are easier to attack, even if your site itself is fine.

    How to fix: Add the header from the table above to your server or CDN settings.

Inside the app

From the certificate to every http file

The certificate's issuer and soonest expiry, and how many pages lack each security header.

app.pixyscan.com/w/…/s/…/trustLive demo
SEO Test Site
DU

Click around: it is a working copy of the screen, filled with our test site's data.

Your health score

Security problems cost real points

Each check is weighted by its severity: Critical 10, Important 5, Standard 2. Trust checks sit in the Delivery & Trust category, which counts at half that weight. Fixing a critical problem on every page wins all of its points back.

How the score works
category weight in the score
0.5×
category weight in the score
base weight of a critical check
10
base weight of a critical check
base weight of an important check
5
base weight of an important check
base weight of a standard check
2
base weight of a standard check

The checks behind this screen

Check categories shown here

These groups of checks feed the numbers on this screen. Each one is explained on the score page.

  • Delivery & Trust

    37 checks

    These checks cover HTTPS, SSL certificates (including ones about to expire), outdated TLS versions, security headers, mixed content, compression, render-blocking scripts and page size. On Hobby and above, once you add your own Google API key, they also flag poor Core Web Vitals (Google's measures of loading speed and visual stability) and Lighthouse findings such as unused code, oversized images and short cache times.

FAQ

Common questions about this feature

Does PixyScan change my server settings?

No. It reads the headers and certificate your server sends and tells you what to change. You or your host make the change.

Will it warn me before my certificate expires?

Yes. Pages whose certificate expires within 30 days are flagged as an Important issue on every scan, and the Certificate expiring filter lists them.

Can I export the results?

Yes, from Hobby up. Export security headers or Export insecure content downloads CSV, Excel or JSON.

Continue the product tour

Previous and next features

Features follow the order of the app’s menu. See the full list to jump to any of them.

See all 19 features

See what is wrong with your site

Add your site and get your score, your to-do list and a fix guide for every problem. Free for one site and 500 pages a month, with no time limit.

Nothing to install · Cancel any time