Scanned sites / bing.com / 2026-10-05-0045

bing.com scan from 10/5/2026, 12:45:47 AM

Scan 2026-10-05-0045

Scanned 10/5/2026, 12:45:47 AM, finished 10/5/2026, 1:25:28 AM. Found with 42backlinks.com tool directory

Not a full crawl. The site rate-limited the crawler (25 requests answered 429), so the scan finished early with 4710 URLs left unfetched. Results cover what was crawled.

Site: https://bing.com/

Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.

75/ 100GoodNot a full crawl

On October 5, 2026 the Site Spider crawled 1238 pages and 52 assets of bing.com, starting from https://bing.com/. It scored 75 out of 100, a good result. 10 of 22 checks found something to fix, led by image alt text (8,782), indexability (512), title tags (490); 4 checks passed. Most of the points went to image alt text (−5.2), indexability (−4.4), title tags (−4.2). 8 checks found something the score does not count, listed as noted. 1 check was not run because the crawl fetched nothing for it. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.

Security review: Medium3 medium, 3 low and 1 info findings. See the security findings ↓

Pages crawled
1238
Assets fetched
52
Status
Completed
Checks with issues
10 of 22
CoverageJob finished, partial coverage

1,290 of 6,000 discovered URLs were fetched, 88,142 left out by the 5,000-page and 1,000-asset budget, 4,710 skipped when the crawl was cut short. The job finished, but the crawl did not reach everything it found. HTML only: nothing here ran JavaScript. 3,513 link destinations on other sites have not been checked.

  • Title tags490 issues
    490 of 501 pages have title issues. 659 noindex or canonicalized pages excluded.
    −4.2 points
  • Meta descriptions498 issues
    498 of 501 pages have meta description issues. 659 noindex or canonicalized pages excluded.
    −3.4 points
  • Headings497 issues
    497 of 501 pages have heading issues. 659 noindex or canonicalized pages excluded.
    −2.6 points
  • Broken linksOK
    0 internal links point at 0 broken URLs.
  • Links to other sitesNot checked
    Not checked: the crawl fetched nothing this check can look at.
  • Redirects53 issues
    56 redirecting URLs, 0 of them chained.
    −0.2 points
  • Non-200 responses56 noted
    56 URLs did not return a 2xx response. 54 of them are pages, 0 with an error status; the rest are assets or redirects.
  • Rate limited24 issues
    24 URLs (24 pages) answered HTTP 429 on every try, so the crawler backed off and moved on without analysing them. A site that throttles crawlers this hard can throttle search engines too.
    −0.1 points
  • Indexability512 issues
    512 of 565 indexable pages have indexability warnings. 595 pages noindex by design.
    −4.4 points
  • Image alt text8,782 issues
    8782 of 10192 image references have no alt attribute. 394 use an empty alt (decorative), which is fine.
    −5.2 points
  • Heavy assetsOK
    0 assets larger than 500 KB among 52 fetched assets.
  • Orphan pages28 issues
    28 pages have no internal links pointing at them.
    −0.1 points
  • Sitemap coverage501 issues
    1 sitemap listing 0 URLs: 501 crawled pages missing, 0 listed URLs broken or redirecting, 0 reachable only via the sitemap.
    −2.6 points
  • Internal link counts429 noted
    Internal link counts for 500 pages; 429 worth a look.
  • Thin content312 issues
    312 of 501 pages have fewer than 200 words. 659 noindex or canonicalized pages excluded.
    −2.2 points
  • Duplicate contentOK
    0 groups of pages with identical HTML.
  • URL format1,231 noted
    1231 of 1238 page URLs are harder to read, share or cache than they need to be.
  • Canonicals1,159 noted
    1159 of 1160 pages have a canonical worth checking.
  • Robots directives625 noted
    625 pages carry a robots directive; 535 carry none.
  • Anchor text1,666 noted
    1666 destinations are linked without useful anchor text, or with nofollow.
  • Title and heading structure162 noted
    162 of 501 pages could use the title, heading and snippet space better. 659 noindex or canonicalized pages excluded.
  • Image weight and alt length10 noted
    0 images over 100 KB; 10 with alt text over 100 characters.
  • Response anomaliesOK
    No redirect loops, header redirects or pages served as something other than HTML.

Where this scan sits among all scanned sites

2072 sites, median 79%, average 78%

bing.com scores 75%, higher than 31% of the 2072 scanned sites. See the full ranking.

0521030%: 0 sites1%: 0 sites2%: 0 sites3%: 0 sites4%: 0 sites5%: 0 sites6%: 0 sites7%: 0 sites8%: 0 sites9%: 0 sites10%: 0 sites11%: 0 sites12%: 0 sites13%: 0 sites14%: 0 sites15%: 0 sites16%: 0 sites17%: 0 sites18%: 0 sites19%: 0 sites20%: 0 sites21%: 1 site22%: 0 sites23%: 0 sites24%: 0 sites25%: 0 sites26%: 0 sites27%: 1 site28%: 0 sites29%: 0 sites30%: 0 sites31%: 0 sites32%: 0 sites33%: 1 site34%: 0 sites35%: 1 site36%: 2 sites37%: 2 sites38%: 3 sites39%: 2 sites40%: 2 sites41%: 1 site42%: 0 sites43%: 0 sites44%: 1 site45%: 4 sites46%: 5 sites47%: 4 sites48%: 4 sites49%: 3 sites50%: 5 sites51%: 5 sites52%: 9 sites53%: 7 sites54%: 7 sites55%: 7 sites56%: 5 sites57%: 11 sites58%: 15 sites59%: 7 sites60%: 12 sites61%: 9 sites62%: 18 sites63%: 20 sites64%: 17 sites65%: 36 sites66%: 27 sites67%: 36 sites68%: 34 sites69%: 33 sites70%: 35 sites71%: 62 sites72%: 67 sites73%: 57 sites74%: 60 sites75%: 79 sites76%: 77 sites77%: 87 sites78%: 91 sites79%: 85 sites80%: 98 sites81%: 100 sites82%: 103 sites83%: 91 sites84%: 90 sites85%: 69 sites86%: 69 sites87%: 62 sites88%: 68 sites89%: 47 sites90%: 37 sites91%: 43 sites92%: 23 sites93%: 19 sites94%: 15 sites95%: 7 sites96%: 4 sites97%: 10 sites98%: 2 sites99%: 1 site100%: 57 sites75% here100%90%80%70%60%50%40%30%20%10%0%

Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).

Internal link map

Loading the link map...

Start page (centre)OKRedirectErrorOrphanLinked from most pagesOne inbound link or noneRings = clicks from the start page. Size = inbound links. Drag to pan, scroll to zoom, click a page to see only its links.

Fix plan

Written by gpt-4o-mini from the scan findings

Your site has a solid health score but needs some important fixes for better SEO performance. Focus on resolving title, meta description, and heading issues to improve visibility.

  1. 2

    Resolve HTTP 429 Rate Limiting

    Why: 24 URLs are rate-limited, hindering crawler access and affecting indexing.

    How: Adjust server settings to allow crawlers more access and reduce throttling.

    Checks: rate-limited

  2. 6

    Fix Indexability Warnings

    Why: 512 indexable pages have issues affecting their visibility in search engines.

    How: Review and resolve canonical and viewport issues per your content strategy.

    Checks: indexability

Generated automatically; verify each change against your own site before relying on it.

Security review

Written by gpt-4o-mini from 16 checks over the crawl

The website has several security vulnerabilities, primarily related to missing security headers and cookie protections. Addressing these issues will enhance user safety and prevent possible attacks, such as clickjacking and cookie theft.

  • 0 high
  • 3 medium
  • 3 low
  • 1 info
  1. 1

    Missing HTTP Strict Transport Security (HSTS)Medium

    Why it matters: Without HSTS, users can be intercepted on initial requests that do not use HTTPS.

    Fix: Add the header `Strict-Transport-Security: max-age=31536000; includeSubDomains; preload` to all pages.

    Evidence: HTTP Strict Transport Security

  2. 2

    Lack of X-Frame-OptionsMedium

    Why it matters: Without this header, the site is vulnerable to clickjacking attacks.

    Fix: Set the header `X-Frame-Options: DENY` or use `Content-Security-Policy: frame-ancestors 'none'`.

    Evidence: Clickjacking protection

  3. 3

    Insecure Cookie FlagsMedium

    Why it matters: Cookies without HttpOnly, Secure, or SameSite flags can be vulnerable to theft and exploitation.

    Fix: Set the attributes HttpOnly, Secure, and SameSite for all sensitive cookies.

    Evidence: Cookie flags

  4. 4

    Missing X-Content-Type-OptionsLow

    Why it matters: Without this header, browsers may misinterpret file types, leading to script execution vulnerabilities.

    Fix: Add the header `X-Content-Type-Options: nosniff` to all HTML pages.

    Evidence: MIME sniffing protection

  5. 5

    Mixed Content IssuesLow

    Why it matters: Loading resources over HTTP can expose users to man-in-the-middle attacks even on HTTPS pages.

    Fix: Update resource URLs to use HTTPS instead of HTTP.

    Evidence: Mixed content

  6. 6

    Third-Party Scripts without Subresource IntegrityLow

    Why it matters: Lack of integrity checks means that compromised third-party scripts could run malicious code.

    Fix: Consider implementing a Content-Security-Policy that limits the domains of scripts and evaluates their integrity.

    Evidence: Third-party scripts

  7. 7

    Missing Permissions PolicyInfo

    Why it matters: Not having a permissions-policy increases the risk from certain browser features that could be exploited.

    Fix: Implement the header `Permissions-Policy: geolocation=(self)` to restrict unnecessary permissions.

    Evidence: Permissions policy

What the checks found

  • FoundHTTP Strict Transport SecurityMedium

    153 of 1160 HTML pages send strict-transport-security. Without it a visitor who types the address without https:// can be intercepted on the first request.

    • https://www.bing.com/copilotsearch?q=&FORM=CSSCOP → no strict-transport-security
    • https://www.bing.com/maps?q=&FORM=HDRSC4 → no strict-transport-security
    • https://www.bing.com/news/search?q=&FORM=HDRSC6 → no strict-transport-security
    • https://www.bing.com/images?FORM=HDRSC2 → no strict-transport-security
    • https://www.bing.com/videos?FORM=HDRSC2 → no strict-transport-security
    • https://www.bing.com/rebates/history?filters=blackjack&FORM=MG0AUG&ocid=MG0AUG&toWww=1&redig=A736C5C0AD5E436492D201CFD7… → no strict-transport-security
    • https://www.bing.com/rebates/faq?filters=blackjack&FORM=MG0AUG&ocid=MG0AUG&toWww=1&redig=655CDA66713A424AA32E2292D7FBA3… → no strict-transport-security
    • https://www.bing.com/copilotsearch?q=Bing+AI&FORM=CSSCOP → no strict-transport-security
    • https://www.bing.com/ck/a?!&&p=301d54611e23e0b0375028b8cf001947c94c344355f1fabfee1e5547cb5fe1c1JmltdHM9MTc5MTA3MjAwMA&p… → no strict-transport-security
    • https://www.bing.com/ck/a?!&&p=69bf15e89ac824a041fe7193e6c1a11da57b0c350c2240b65833dc4bd6f44fb0JmltdHM9MTc5MTA3MjAwMA&p… → no strict-transport-security
    • https://www.bing.com/ck/a?!&&p=f6da00486a51c13f9ed9960194965ec7771554f90384d5330f631543bce38bd4JmltdHM9MTc5MTA3MjAwMA&p… → no strict-transport-security
    • https://www.bing.com/ck/a?!&&p=65a1fede66e52e72c7c4b35e90b897dd2b2acae4b6ce2f14edd643149c64e4f1JmltdHM9MTc5MTA3MjAwMA&p… → no strict-transport-security
  • FoundClickjacking protectionMedium

    33 of 1160 HTML pages send x-frame-options. Without X-Frame-Options (or a CSP frame-ancestors directive) the pages can be embedded in a frame on another site and overlaid with invisible controls.

    • https://www.bing.com/shop/deals/cashback → no x-frame-options
    • https://www.bing.com/shop/deals/cashback?setlang=fr&sid=2719E645857563B63BE4F1AC84EA628E → no x-frame-options
    • https://www.bing.com/search?q=Bing+AI&FORM=HDRSC1 → no x-frame-options
    • https://www.bing.com/copilotsearch?q=&FORM=CSSCOP → no x-frame-options
    • https://www.bing.com/news/search?q=&FORM=HDRSC6 → no x-frame-options
    • https://www.bing.com/shop/deals/cashback?FORM=SHOPTB&entryPoint=msn → no x-frame-options
    • https://www.bing.com/shop/collections?collectionpage=true&FORM=SHOPTB&entryPoint=msn → no x-frame-options
    • https://www.bing.com/images?FORM=HDRSC2 → no x-frame-options
    • https://www.bing.com/videos?FORM=HDRSC2 → no x-frame-options
    • https://www.bing.com/shop/?FORM=SHOPTB → no x-frame-options
    • https://www.bing.com/shop/deals?FORM=SHOPTB&entryPoint=msn&ocid=SHOPTB → no x-frame-options
    • https://www.bing.com/rebates/history?filters=blackjack&FORM=MG0AUG&ocid=MG0AUG&toWww=1&redig=A736C5C0AD5E436492D201CFD7… → no x-frame-options
  • FoundMIME sniffing protectionLow

    No HTML page sends x-content-type-options. Without X-Content-Type-Options: nosniff a browser may run a file as a script because of its contents rather than its declared type.

    • https://www.bing.com/?toWww=1&redig=787AA7334CC24DD280912D7780F14578 → no x-content-type-options
    • https://www.bing.com/shop/deals/cashback → no x-content-type-options
    • https://www.bing.com/?FORM=Z9FD1 → no x-content-type-options
    • https://www.bing.com/shop/deals/cashback?setlang=fr&sid=2719E645857563B63BE4F1AC84EA628E → no x-content-type-options
    • https://www.bing.com/search?q=Bing+AI&FORM=HDRSC1 → no x-content-type-options
    • https://www.bing.com/copilotsearch?q=&FORM=CSSCOP → no x-content-type-options
    • https://www.bing.com/maps?q=&FORM=HDRSC4 → no x-content-type-options
    • https://www.bing.com/news/search?q=&FORM=HDRSC6 → no x-content-type-options
    • https://www.bing.com/shop/deals/cashback?FORM=SHOPTB&entryPoint=msn → no x-content-type-options
    • https://www.bing.com/shop/collections?collectionpage=true&FORM=SHOPTB&entryPoint=msn → no x-content-type-options
    • https://www.bing.com/images?FORM=HDRSC2 → no x-content-type-options
    • https://www.bing.com/videos?FORM=HDRSC2 → no x-content-type-options
  • FoundPermissions policyInfo

    922 of 1160 HTML pages send permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.

    • https://www.bing.com/ck/a?!&&p=301d54611e23e0b0375028b8cf001947c94c344355f1fabfee1e5547cb5fe1c1JmltdHM9MTc5MTA3MjAwMA&p… → no permissions-policy
    • https://www.bing.com/ck/a?!&&p=69bf15e89ac824a041fe7193e6c1a11da57b0c350c2240b65833dc4bd6f44fb0JmltdHM9MTc5MTA3MjAwMA&p… → no permissions-policy
    • https://www.bing.com/ck/a?!&&p=f6da00486a51c13f9ed9960194965ec7771554f90384d5330f631543bce38bd4JmltdHM9MTc5MTA3MjAwMA&p… → no permissions-policy
    • https://www.bing.com/ck/a?!&&p=65a1fede66e52e72c7c4b35e90b897dd2b2acae4b6ce2f14edd643149c64e4f1JmltdHM9MTc5MTA3MjAwMA&p… → no permissions-policy
    • https://www.bing.com/ck/a?!&&p=8276f1a2ec43b2475b4d0c4e8b38fa83d4e5859b773446ce6e7397eb05222bd8JmltdHM9MTc5MTA3MjAwMA&p… → no permissions-policy
    • https://www.bing.com/ck/a?!&&p=b0470823bf6f0e12efb13de0171c8588fd90592dfab3b5c6aeb829c97793f65dJmltdHM9MTc5MTA3MjAwMA&p… → no permissions-policy
    • https://www.bing.com/ck/a?!&&p=18b6c5a5b0b9a6c4286e89c83c15c2631711b1f83d5c5c4010a34a927522dd9aJmltdHM9MTc5MTA3MjAwMA&p… → no permissions-policy
    • https://www.bing.com/ck/a?!&&p=01223bd652c86ddf85e46675a03805d01f00edae1f592bf7565fc5f5fce8614bJmltdHM9MTc5MTA3MjAwMA&p… → no permissions-policy
    • https://www.bing.com/ck/a?!&&p=4198104e5214812a0fbd153e1e4afe26422bf28c32d941ceef25009d7021f6e6JmltdHM9MTc5MTA3MjAwMA&p… → no permissions-policy
    • https://www.bing.com/ck/a?!&&p=81bc4170abda776060e9cd3dfaaf4de713dd718295bc5915092d49020b923615JmltdHM9MTc5MTA3MjAwMA&p… → no permissions-policy
    • https://www.bing.com/ck/a?!&&p=4e7f312ef3b8f922cf363e0d34f50783ca5626df00ef01f7f04da2720873c4a2JmltdHM9MTc5MTA3MjAwMA&p… → no permissions-policy
    • https://www.bing.com/ck/a?!&&p=8b5d4b2d0ec1727ad3696ed1bede5afc961565c57d7e196f3fe0919518277d12JmltdHM9MTc5MTA3MjAwMA&p… → no permissions-policy
  • FoundCookie flagsMedium

    14 of 15 cookies are missing protective flags. Without HttpOnly a script can read the cookie; without Secure it travels over plain HTTP; without SameSite it is sent on cross-site requests.

    • MUID (set by https://bing.com/) lacks HttpOnly
    • MUIDB (set by https://bing.com/) lacks Secure, SameSite
    • _EDGE_S (set by https://bing.com/) lacks Secure, SameSite
    • _EDGE_V (set by https://bing.com/) lacks Secure, SameSite
    • SRCHD (set by https://www.bing.com/?toWww=1&redig=787AA7334CC24DD280912D7780F14578) lacks Secure, HttpOnly, SameSite
    • SRCHUID (set by https://www.bing.com/?toWww=1&redig=787AA7334CC24DD280912D7780F14578) lacks Secure, HttpOnly, SameSite
    • SRCHUSR (set by https://www.bing.com/?toWww=1&redig=787AA7334CC24DD280912D7780F14578) lacks Secure, HttpOnly, SameSite
    • SRCHHPGUSR (set by https://www.bing.com/?toWww=1&redig=787AA7334CC24DD280912D7780F14578) lacks Secure, HttpOnly, SameSite
    • _SS (set by https://www.bing.com/?toWww=1&redig=787AA7334CC24DD280912D7780F14578) lacks Secure, HttpOnly, SameSite
    • ULC (set by https://www.bing.com/?toWww=1&redig=787AA7334CC24DD280912D7780F14578) lacks Secure, HttpOnly, SameSite
    • _HPVN (set by https://www.bing.com/?toWww=1&redig=787AA7334CC24DD280912D7780F14578) lacks Secure, HttpOnly, SameSite
    • MMCASM (set by https://www.bing.com/images/search?q=&FORM=HDRSC2) lacks Secure, HttpOnly, SameSite
  • FoundMixed contentLow

    481 resources on HTTPS pages are loaded over plain HTTP.

    • https://www.bing.com/search?q=Bing+AI&FORM=HDRSC1 loads image http://www.bing.com/sa/simg/facebook_sharing_5.png
    • https://www.bing.com/images?FORM=HDRSC2 loads image http://www.bing.com/sa/simg/facebook_sharing_5.png
    • https://www.bing.com/search?q=IA+Bing&FORM=HDRSC1 loads image http://www.bing.com/sa/simg/facebook_sharing_5.png
    • https://www.bing.com/search?q=Bing+AI&FORM=HDRSC1&setlang=fr&sid=276A… loads image http://www.bing.com/sa/simg/facebook_sharing_5.png
    • https://www.bing.com/search?q=Bing+AI&FPIG=6C56B2C8D7434B80A00E0EC0DB… loads image http://www.bing.com/sa/simg/facebook_sharing_5.png
    • https://www.bing.com/search?q=Bing+AI&FPIG=6C56B2C8D7434B80A00E0EC0DB… loads image http://www.bing.com/sa/simg/facebook_sharing_5.png
    • https://www.bing.com/search?q=Bing+AI&FPIG=6C56B2C8D7434B80A00E0EC0DB… loads image http://www.bing.com/sa/simg/facebook_sharing_5.png
    • https://www.bing.com/search?q=Bing+AI&FORM=000017&qpvt=Bing+AI loads image http://www.bing.com/sa/simg/facebook_sharing_5.png
    • https://www.bing.com/search?q=Bing+AI&filters=ex1%3a%22ez1%22&FORM=00… loads image http://www.bing.com/sa/simg/facebook_sharing_5.png
    • https://www.bing.com/search?q=Bing+AI&filters=ex1%3a%22ez2%22&FORM=00… loads image http://www.bing.com/sa/simg/facebook_sharing_5.png
    • https://www.bing.com/search?q=Bing+AI&filters=ex1%3a%22ez3%22&FORM=00… loads image http://www.bing.com/sa/simg/facebook_sharing_5.png
    • https://www.bing.com/search?q=Bing+AI&filters=ex1%3a%22ez5_20366_2073… loads image http://www.bing.com/sa/simg/facebook_sharing_5.png
  • NoteThird-party scripts

    Scripts run from 1 other domain without Subresource Integrity, so a compromise of any of them changes what runs on this site. (Tag managers and analytics rarely support SRI; a Content-Security-Policy that names these hosts is the usual control.)

    • r.bing.com (93 script tags)
8 checks passed, 1 not applicable
  • OKHTTPS

    All 1160 crawled pages were served over HTTPS.

  • OKContent Security Policy

    A Content-Security-Policy is set on 922 of 1160 pages.

  • OKReferrer policy

    A referrer policy is set through a <meta name="referrer"> tag.

  • OKSoftware version disclosure

    No Server or X-Powered-By header is sent.

  • OKForms over HTTPS

    17 forms found, all on HTTPS pages posting to HTTPS addresses.

  • OKKeys and secrets in page code

    No API keys, tokens or private keys were found in the sampled HTML and scripts.

  • OKExposed files and listings

    None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.

  • OKSensitive paths in robots.txt

    robots.txt does not point at admin, backup or private paths.

  • Not applicableVulnerable JavaScript libraries

    No recognisable library versions were found in the sampled scripts.

A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.

Sites scoring near bing.com

Their neighbours in the SEO rank table, which orders every scanned site by health score.

This report was produced by the DIY SEO Hub Site Spider crawling bing.com from its pages as published, the way a search engine does. It shows summary figures only.

Own bing.com?

bing.com scan 2026-10-05-0045 | DIY SEO Hub