Skip to content

Search PixyScan

Guide contents

User guide3 min

Trust

The Trust screen shows your SSL certificate, the security headers each page sends, and any files still loading over plain HTTP. Most fixes are made on your server or CDN (content delivery network), so share this screen with whoever runs them.

How to get there#

Trust is the last item in the Explore group of the site sidebar.

  1. 1

    Open Trust in the sidebar

    Open the site, then choose Trust at the bottom of Explore.

  2. 2

    Start on Overview

    Overview has two cards. The certificate is on the left. Header coverage, on the right, counts pages missing each security header.

  3. 3

    Open Table to see page by page

    Use a filter such as No HSTS or Certificate expiring to list the pages affected. Expand a row to see the headers exactly as the page sent them.

app.pixyscan.com/w/…/s/…/trust

The Trust screen's Overview: a certificate card with issuer, soonest expiry and pages expiring, and a header coverage card listing HSTS, CSP, clickjacking, referrer policy and mixed content.
The Overview tab shows the certificate and its expiry on the left, and missing security headers on the right.

The three tabs#

A summary, a row per page, and a row per insecure file.

FieldShowsWhat it does
OverviewTwo cardsThe certificate card and the Header coverage card.
TableOne row per pageWhether each page sent HSTS and CSP, how it is protected against clickjacking, its Referrer-Policy, and any mixed content.
Insecure contentOne row per fileScripts and other files loaded over http:// on an https:// page, with the page that loads them. Fix these first, because browsers block insecure scripts.

The certificate card#

Your SSL certificate gives your site the padlock in the browser.

FieldShowsWhat it does
Issued byIssuer · pagesWho issued the certificate. If pages use certificates from more than one issuer, a badge warns you.
Soonest expiryDate · in N daysThe earliest date any certificate on your site stops being valid.
Expiring within 30 daysPagesPages whose certificate is still valid but runs out in the next 30 days.
Already expiredPagesPages whose certificate has run out. Browsers warn visitors away from these.

What Header coverage checks#

Security headers are instructions your server sends to the browser with every page.

FieldIf missingWhat it does
No HSTSHTTP allowedHSTS (HTTP Strict Transport Security) tells browsers to always use HTTPS for your site. It is usually one setting on your server or CDN.
No CSPLess protectionA Content Security Policy limits which scripts can run on your pages. Test it carefully, because a wrong policy can break the site.
No clickjacking protectionCan be framedWithout X-Frame-Options or a CSP frame-ancestors rule, other sites can show your pages inside their own.
No referrer policyFull URL sharedA Referrer-Policy controls how much of your URL is passed on when visitors click a link to another site.
Insecure scripts · Insecure assetsBroken padlockThese are not headers. They count HTTPS pages that load a script or other file over plain HTTP. This is called mixed content.

Watch the certificate expiry

An expired certificate makes browsers show a full-page warning to every visitor. Check Soonest expiry here, and put the site on a schedule so it is checked regularly.

Export security headers downloads the headers page by page. Export insecure content downloads the files from that tab. Exports are included from Hobby up.

Does something here not match what you see in the app? Tell us