30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.
| ID | Check | Passes when |
|---|---|---|
| 7.2.01 | Detect active mixed content (scripts, iframes) | None |
| 7.2.02 | Detect passive mixed content (images, video, audio) | None |
| 7.2.03 | Validate browser blocks unsafe requests | Blocked |
| 7.2.04 | Validate no HTTP resources loaded via dynamic JS | None |
| 7.2.05 | Detect mixed content hidden behind query params | None |
| 7.2.06 | Detect images hard-coded as HTTP | None |
| 7.2.07 | Detect video/audio embeds using HTTP | None |
| 7.2.08 | Detect iframe sources over HTTP | None |
| 7.2.09 | Validate no HTTP protocol fallback behaviors | None |
| 7.2.10 | Compute Page-Level Mixed Content Health Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.2.11 | Validate all JS requests use HTTPS | HTTPS |
| 7.2.12 | Validate all CSS requests use HTTPS | HTTPS |
| 7.2.13 | Validate all font files loaded over HTTPS | HTTPS |
| 7.2.14 | Detect HTTP analytics or tracking beacons | None |
| 7.2.15 | Detect HTTP script loaders (tag managers, CDN loaders) | None |
| 7.2.16 | Detect HTTP CDN fallback links | None |
| 7.2.17 | Validate map libraries load over HTTPS | HTTPS |
| 7.2.18 | Validate payment libraries loaded securely | Secure |
| 7.2.19 | Detect mixed content triggered by A/B testing tools | None |
| 7.2.20 | Compute Resource Security Integrity Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.2.21 | Validate all HTTP→HTTPS upgrades forced | Forced |
| 7.2.22 | Validate Referrer-Policy prevents insecure leakage | Secure |
| 7.2.23 | Validate CSP blocks HTTP resource loading | Blocked |
| 7.2.24 | Validate redirects do not briefly downgrade to HTTP | No downgrade |
| 7.2.25 | Detect scripts that rewrite URLs to HTTP | None |
| 7.2.26 | Validate HSTS prevents protocol downgrade | Enforced |
| 7.2.27 | Detect old plugins/themes calling HTTP APIs | None |
| 7.2.28 | Validate embedded third-party widgets enforce HTTPS | Enforced |
| 7.2.29 | Detect mixed content caused by redirects between domains | None |
| 7.2.30 | Compute Mixed Content Compliance Master Score | Finalized |
← 7.1 HTTPS / TLS Integrity7.3 CORS & Access-Control Exposure →
A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.
See plansMachine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).