Bao gồm từ Free

Site Trust & Security: site trust and security signals measured from a real crawl

Một bảng điểm có giới hạn cho các tín hiệu độ tin cậy của trang web đã thu thập, các header và những phép dò bên ngoài được hỗ trợ.

Tổng quan

What are site trust and security signals, and what is Site Trust & Security?

Site trust and security signals are what a browser, a crawler and a visitor can observe about how safely a site is served: HTTPS everywhere, HTTP redirecting to HTTPS, the security response headers present and how strong they are, and no insecure content on secure pages. Site Trust & Security is Novaverb's bounded scorecard for those signals, measured from your own crawl, with an ownership-gated exposure scan for the checks that need permission to run.

Site Trust & Security chấm điểm các tín hiệu tin cậy HTTP và tiêu đề bảo mật của trang web của bạn từ một lần thu thập thông tin thực, đồng thời chạy một bản pentest tự động đối với các cổng cơ sở dữ liệu bị lộ và các tệp sao lưu bị rò rỉ.

Năng lực

What does the site trust and security scorecard measure?

The site trust and security scorecard measures what your own pages return: HTTPS coverage across every crawled URL, whether HTTP redirects to HTTPS, the six security response headers with Content Security Policy strength graded, and mixed content on secure pages resolved to the URLs carrying it. A weighted trust score summarizes the measured factors, and an exposure scan for open database ports and leaked backup files runs only after you verify domain ownership.

  • HTTPS coverage across every crawled URL and HTTP-to-HTTPS redirects
  • The six security response headers, with CSP strength graded
  • Mixed content on secure pages, resolved to the URLs that carry it
  • A weighted trust score built from measured factors only
  • An exposure scan for open database ports and leaked backup files, gated on verified ownership
  • A copy-ready fix with every finding, such as the exact server directive
Đối tượng là ai

Who is site trust and security for?

Site trust and security is for people who must answer for how a site is served without becoming security engineers: a marketing lead asked whether the site is safe, an SEO who knows a header or a redirect gap is a fix they can own, an agency reporting trust to a client with the pages named, and a business owner who wants to know which findings are real before paying anyone to fix them.

Marketing leads

Answer 'is the site safe to buy from?' with a measured score and the factors behind it.

SEOs

Own the fixes that are yours: redirects, mixed content and the headers a template controls.

Đại lý

Report trust signals per page with a copy-ready fix beside each finding.

Chủ doanh nghiệp

Run the exposure scan on the domain you verified and see which findings are real.

Tại sao các đội chọn nó

Why measure site trust and security from your own crawl?

Measure site trust and security from your own crawl because most security tools either bury you in raw scanner noise or quietly guess at gaps they never measured, and both leave you unable to say which findings are real. Site Trust & Security scores only factors it observed on your pages, names the page behind every finding, and runs the deeper scan only on a domain you proved you own.

Tổng quan mức độ tin cậy

Điểm tin cậy tổng hợp từ các tín hiệu thực, HTTPS, tiêu đề và cấu hình được ghi lại để bạn thấy được rủi ro trước khi phải trả giá.

Kiểm thử bảo mật tự động

Phát hiện các cổng cơ sở dữ liệu bị lộ và các tệp sao lưu bị rò rỉ (.sql dumps, .env, .git) âm thầm rò rỉ dữ liệu của bạn.

Phạm vi tiêu đề

Phạm vi bao phủ HSTS, CSP và X-Frame-Options được phân loại, với cách khắc phục chính xác cho từng khoảng trống.

Cách nó hoạt động

How does the site trust and security workflow run?

The site trust and security workflow runs in four steps. Crawl the site so the scorecard has real responses to read; let the factors be scored, HTTPS coverage, redirects, headers and mixed content; verify domain ownership when you want the exposure scan for open ports and leaked backups; then fix each finding against the page it came from, and let the next crawl recompute the score.

1

Thu thập dữ liệu trang web

The scorecard reads the responses your own pages returned: protocol, redirects, headers and the resources secure pages load.

2

Cho điểm các yếu tố

HTTPS coverage, HTTP-to-HTTPS redirects, the six security headers with CSP graded and mixed content become a weighted trust score and a per-header scorecard.

3

Xác minh quyền sở hữu

The exposure scan for open database ports and leaked backup files can affect a live host, so it runs only on a domain you have verified you own.

4

Sửa từng phát hiện

Every finding names the page and carries a copy-ready fix. The score is recomputed from the next crawl, so a fix is confirmed by measurement.

Bên trong Tin cậy & bảo mật site

A site trust and security score built from measured factors

01

The weighted trust score summarizes only what the crawl observed: how much of the site is served over HTTPS, whether HTTP redirects to it, which security headers are present and how strong the Content Security Policy is, and whether secure pages load insecure resources. With no crawled pages the state is an honest insufficient, never a fabricated zero-score at-risk verdict.

  • HTTPS coverage and redirects
  • Six headers, CSP graded
  • Insufficient, never fabricated
Bên trong Tin cậy & bảo mật site

A per-header site trust and security scorecard that names the page

02

Each of the six security response headers gets its own line: present, missing or weak, and on which pages, with mixed-content findings resolved to the URLs carrying them. Every finding carries real evidence and a copy-ready fix, such as the exact server directive to add a header or hide a version string, so the ticket you write contains the change rather than a category.

  • Header state per page
  • Mixed content resolved to URLs
  • Copy-ready fix per finding
Bên trong Tin cậy & bảo mật site

An ownership-gated exposure scan for site trust and security

03

The automated scan for exposed database ports, TLS weaknesses and leaked backup files runs only on a domain you have verified you own, because a probe that could affect a live host must not be pointed at someone else's. Others see no scan and no verdict; you see the findings on your own host with their evidence, and the next run confirms a closed port or a removed file by measurement.

  • Runs only on a verified domain
  • Ports, TLS and backup leaks
  • Confirmed by the next run
So sánh

Site trust and security from measured factors vs. raw scanner noise

Raw scanner noise lists every rule a generic tool could fire, on hosts it never asked permission to probe, and leaves you to sort real from theoretical. Site trust and security from measured factors scores only what your pages returned, names the page and the fix for each finding, and runs the invasive checks only on a domain you verified. One is a dump; the other is a scorecard you can act on.

Raw scanner noise
  • Every rule fired, real or theoretical
  • Probes pointed at hosts nobody verified
  • A verdict with no page behind it
  • A zero score when nothing was measured
Site Trust & Security in Novaverb
  • Only factors measured on your own pages
  • The exposure scan runs on a verified domain only
  • Every finding names the page and carries a copy-ready fix
  • No crawled pages means an honest insufficient state
Dữ liệu thực

What data does site trust and security read?

Site trust and security reads what your own pages returned to the crawl: the protocol each URL was served on, the redirect from HTTP, the six security response headers and the Content Security Policy value, and the resources secure pages loaded. The exposure scan adds observations of your verified host's ports, TLS and reachable backup paths. Nothing is inferred from a template or another site.

The project crawl

Protocol, redirects, response headers and loaded resources for every captured URL.

Header grading

The six security headers, with the Content Security Policy graded for strength, not just presence.

Ownership verification

The proof that a domain is yours, which is what unlocks the exposure scan.

Earlier crawls and scans

The score is recomputed each crawl, so a fix is confirmed by measurement rather than assumed.

Đầu ra

What can you produce from the site trust and security scorecard?

What you can produce from the site trust and security scorecard is a fix list with its proof: a weighted trust score with its factors, a per-header scorecard naming the pages, mixed-content findings resolved to URLs, exposure-scan results on your verified host, a copy-ready fix for every finding, and a before-and-after when the next crawl recomputes the score.

Weighted trust score with factorsPer-header scorecard by pageHTTPS coverage and redirect findingsMixed-content URLsExposure-scan results on a verified hostCopy-ready fixesScore history across crawlsExports for tickets
Sự khác biệt trung thực

How is Novaverb's site trust and security different?

Novaverb's site trust and security is different in its refusals. No crawled pages means an honest insufficient state, never a fabricated at-risk verdict; the active TLS, port and leak scan runs only on a domain you verified you own; and every finding carries real evidence and a copy-ready fix, so the report is a set of changes rather than a set of warnings.

No crawled pages means an honest insufficient state, never a fabricated zero-score at-risk verdict
The active TLS, port and leak scan runs only on a domain you have verified you own
Every finding carries real evidence and a copy-ready fix, such as the exact server directive
The score is recomputed from the next crawl, so a fix is confirmed by measurement
Tìm

How do site trust and security signals relate to SEO?

For SEO, site trust and security signals are the part of the crawl that search engines and visitors both read: a site served over HTTPS everywhere with clean redirects and no mixed content is easier to crawl consistently and safer to click. The scorecard turns those into page-level findings in the same workspace as the audit, so a redirect gap or an insecure resource is fixed like any other technical finding and confirmed on the next crawl.

Câu trả lời AI

How do site trust and security signals relate to AI answer visibility?

For AI answer visibility, site trust and security signals are part of whether a page is a source worth citing at all: an answer engine that fetches your page meets the same protocol, headers and redirects a browser does. The scorecard keeps those facts beside the readiness report, so a page with answer structure in place is also served in a way that does not raise a warning on the way in. Whether an engine cites it is measured separately.

Trong kế hoạch của bạn

Which plans include site trust and security?

Site trust and security is included from the Free plan for the crawl-based scorecard: HTTPS coverage, redirects, headers and mixed content. The automated exposure scan for open ports and leaked backups opens on Pro and above, on a verified domain. Tiers differ in URLs per crawl, data credits a month, seats, workspaces and history depth.

Hoạt động với

Tiêu đề bảo mật
Pentest tự động (các cổng bị lộ và rò rỉ bản sao lưu) trên Pro+
Kế hoạch

How much does site trust and security cost?

Site trust and security costs what your plan costs; it carries no separate fee, and the Free plan includes the crawl-based scorecard. Plans are priced on scale, URLs per crawl, data credits a month, seats, workspaces and history depth, and the current amounts for each tier are on the pricing page, read from one source so this page never quotes a stale number.

So sánh các gói →
Thực hành tốt nhất

Best practices for site trust and security

The best practices for site trust and security are about order and proof. Crawl first so the score reads real responses; fix HTTPS coverage and redirects before tuning headers; grade the Content Security Policy for strength, not presence; verify ownership before expecting the exposure scan; and re-crawl after each change so the score, not the deploy log, confirms it.

  • Crawl before reading the score; it measures the responses your pages returned
  • Fix HTTPS coverage and HTTP-to-HTTPS redirects before tuning individual headers
  • Treat a weak Content Security Policy as a finding, not a pass
  • Verify domain ownership to unlock the exposure scan on your own host
  • Re-crawl after each fix; the score is recomputed from measurement
Nền tảng

Site trust and security reads the same crawl as the rest of Novaverb and hands its findings on. Crawl Explorer captures the responses it grades, Site Health Audit carries the redirect and mixed-content findings in its queue, Visitor Behavior shows the field experience of the pages you secured, and Reports carry the trust score, dated, to the people who asked.

Câu hỏi thường gặp

Frequently asked questions about site trust and security

What does the site trust and security score measure?

Only factors observed on your own crawled pages: HTTPS coverage across every URL, whether HTTP redirects to HTTPS, which of the six security response headers are present and how strong the Content Security Policy is, and whether secure pages load insecure resources. The weighted score summarizes those measurements and nothing inferred.

Does the site trust and security scan touch my live server?

The crawl-based scorecard reads only what your pages returned. The exposure scan for open database ports, TLS weaknesses and leaked backup files can affect a live host, so it runs only after you verify that you own the domain, and it is available on Pro and above. Nobody can point it at a domain they have not verified.

What happens in site trust and security when the crawl captured no pages?

The state is reported as insufficient. A score computed from nothing would be a fabricated zero-score at-risk verdict, so the scorecard declines to produce one until the crawl has real responses to read, and it says so plainly instead of drawing a red gauge.

Does site trust and security tell me how to fix a finding?

Yes. Every finding names the page it came from and carries a copy-ready fix, such as the exact server directive to add a missing header, strengthen a policy or hide a version string. You apply the change on your server or template; the next crawl recomputes the score and confirms the fix by measurement.

Which security headers does site trust and security check?

The six security response headers a browser reads, with the Content Security Policy graded for strength rather than only for presence, plus HTTPS coverage, the HTTP-to-HTTPS redirect and mixed content on secure pages. Each header gets its own line in the scorecard, with the pages where it is missing or weak.

How often is the site trust and security score updated?

Every time you crawl. The scorecard is recomputed from the fresh responses, so a header you added or a redirect you fixed shows up as a changed factor rather than as a note that a deploy happened. The exposure scan runs when you request it on your verified domain, within your plan's data credits.

Score your site trust and security

Score your site trust and security by creating a free workspace and crawling your site; HTTPS coverage, redirects, headers and mixed content are scored from that crawl at once, and verifying your domain on a Pro plan unlocks the exposure scan. Compare the plans if you already know the crawl size you need.