Scanned sites / moz.com / 2026-10-09-0127
moz.com scan from 10/9/2026, 1:27:34 AM DR 91
DR is Ahrefs Domain Rating (0-100, backlink strength), used under its Domain Rating License.
Scan 2026-10-09-0127
Scanned 10/9/2026, 1:27:34 AM, finished 10/9/2026, 5:39:03 AM. Found with 42backlinks.com tool directory
Site: https://moz.com/
Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.
On October 9, 2026 the Site Spider crawled 4892 pages and 1066 assets of moz.com, starting from https://moz.com/. It scored 72 out of 100, a result that needs work. 14 of 23 checks found something to fix, led by heavy assets (112), meta descriptions (2,287), sitemap coverage (2,719); 1 check passed. Most of the points went to heavy assets (−6), meta descriptions (−5), sitemap coverage (−4.5). 8 checks found something the score does not count, listed as noted. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.
Security review: Medium4 medium, 1 low and 1 info findings. See the security findings ↓
- Pages crawled
- 4892
- Assets fetched
- 1066
- Status
- Completed
- Checks with issues
- 14 of 23
5,958 of 6,000 discovered URLs were fetched, 42 blocked by robots.txt, 44,893 left out by the 5,000-page and 1,000-asset budget. The job finished, but the crawl did not reach everything it found. HTML only: nothing here ran JavaScript. 300 link destinations on other sites were checked, 13817 left unchecked.
- Title tags1,275 issues1275 of 2719 pages have title issues. 937 noindex or canonicalized pages excluded.−3.5 points
- Meta descriptions2,287 issues2287 of 2719 pages have meta description issues. 937 noindex or canonicalized pages excluded.−5 points
- Headings1,271 issues1271 of 2719 pages have heading issues. 937 noindex or canonicalized pages excluded.−2.1 points
- Broken links501 issues21420 internal links point at 501 broken URLs.−2.7 points
- Links to other sites30 issues30 destinations answered with an error, 106 could not be determined (timeouts, rate limits or refusals), 13817 were left unchecked by the per-scan cap, of 300 destinations checked.−0.3 points
- Redirects738 issues748 redirecting URLs, 6 of them chained.−0.8 points
- Non-200 responses502 issues1264 URLs did not return a 2xx response. 1236 of them are pages, 502 with an error status; the rest are assets or redirects.−1.4 points
- Rate limitedOKThe site did not rate limit the crawler.
- Indexability245 issues245 of 2913 indexable pages have indexability warnings. 743 pages noindex by design.−0.7 points
- Image alt text7,908 issues7908 of 56013 image references have no alt attribute. 2802 use an empty alt (decorative), which is fine.−0.8 points
- Heavy assets112 issues112 assets larger than 500 KB among 1066 fetched assets.−6 points
- Orphan pages40 issues40 pages have no internal links pointing at them.
- Sitemap coverage2,719 issues2 sitemaps listing 0 URLs: 2719 crawled pages missing, 0 listed URLs broken or redirecting, 0 reachable only via the sitemap.−4.5 points
- Internal link counts306 notedInternal link counts for 500 pages; 306 worth a look.
- Thin content22 issues22 of 2719 pages have fewer than 200 words. 937 noindex or canonicalized pages excluded.
- Duplicate content2 issues1 group of pages with identical HTML.
- URL format595 noted595 of 4892 page URLs are harder to read, share or cache than they need to be.
- Canonicals594 noted594 of 3656 pages have a canonical worth checking.
- Robots directives2,839 noted2839 pages carry a robots directive; 817 carry none.
- Anchor text1,940 noted1940 destinations are linked without useful anchor text, or with nofollow.
- Title and heading structure1,931 noted1931 of 2719 pages could use the title, heading and snippet space better. 937 noindex or canonicalized pages excluded.
- Image weight and alt length1,057 noted244 images over 100 KB; 813 with alt text over 100 characters.
- Response anomalies17 noted17 URLs answered in a way worth looking at.
Where this scan sits among all scanned sites
2171 sites, median 79%, average 78%
moz.com scores 72%, higher than 23% of the 2171 scanned sites. See the full ranking.
Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).
Internal link map
Loading the link map...
Fix plan
Written by gpt-4o-mini from the scan findingsThe crawl revealed several critical issues, primarily broken links, redirects, non-200 responses, and missing meta descriptions. Addressing these will enhance user experience and SEO performance significantly.
- 1
Fix Broken Links
Why: 21420 internal links point to broken URLs, degrading user experience and SEO.
How: Identify broken links via the crawl report and update or remove them.
Checks: broken-links
- 2
Reduce Redirects
Why: 748 URLs have redirects, which can slow down page loading times and dilute link equity.
How: Replace redirects with direct links to the final destination or fix the chain redirects.
Checks: redirects
- 3
Resolve Non-200 Responses
Why: 1264 URLs do not return a 2xx response, impacting indexation and user experience.
How: Check error pages and update or remove broken links and assets.
Checks: status-codes
- 4
Create Meta Descriptions
Why: 2287 pages have meta description issues, affecting click-through rates.
How: Craft unique meta descriptions for pages lacking them, ensuring they are within optimal lengths.
Evidence: 303 pages have no meta description at all.
303 pages affected
Checks: meta-descriptions
- 5
Improve Sitemap Coverage
Why: 2719 pages are missing from the sitemap, risking poor indexation.
How: Update the sitemap to include all indexed pages and submit it to search engines.
Evidence: 2719 URLs: not in sitemap.
2,719 pages affected
Checks: sitemap-coverage
- 6
Address Heading Issues
Why: 1271 pages have heading issues, which can hinder SEO performance.
How: Ensure each page has a single H1 tag and appropriate headings.
Checks: headings
Generated automatically; verify each change against your own site before relying on it.
Security review
Written by gpt-4o-mini from 16 checks over the crawlThe security review identified several issues on your website that require attention. Key concerns include the absence of important response headers, insecure cookies, mixed content loading, vulnerable JavaScript libraries, and leaked secret keys. Addressing these will enhance your site's security posture.
- 0 high
- 4 medium
- 1 low
- 1 info
- 1
Insecure Cookie FlagsMedium
Why it matters: Cookies lacking Secure, HttpOnly, and SameSite flags are vulnerable to attacks, such as cross-site scripting.
Fix: Set cookies with the flags 'Secure', 'HttpOnly', and 'SameSite=Lax' or 'SameSite=Strict'.
Evidence: Cookie flags
- 2
Mixed Content Loaded Over HTTPMedium
Why it matters: Loading HTTP resources on HTTPS pages can allow tampering and expose users to security risks.
Fix: Ensure all resources are loaded over HTTPS; update links to use HTTPS.
Evidence: Mixed content
- 3
Vulnerable jQuery LibraryMedium
Why it matters: Using an outdated version of jQuery exposes the site to several vulnerabilities.
Fix: Upgrade jQuery to version 3.5.0 or later.
Evidence: Vulnerable JavaScript libraries
- 4
Leaked Google API KeysMedium
Why it matters: Exposing credential-like values can lead to unauthorized access or abuse.
Fix: Configure restrictions in the Google Cloud console for the exposed API keys.
Evidence: Keys and secrets in page code
- 5
Missing X-Content-Type-Options HeaderLow
Why it matters: Without this header, a browser might execute files as scripts based on their contents, leading to security risks.
Fix: Add the header 'X-Content-Type-Options: nosniff' to all HTML responses.
Evidence: MIME sniffing protection
- 6
Missing Permissions-Policy HeaderInfo
Why it matters: This header can limit access to browser features that could be exploited by malicious scripts.
Fix: Add 'Permissions-Policy: accelerometer=(), camera=(), geolocation=()' to all HTML responses.
Evidence: Permissions policy
What the checks found
- FoundMIME sniffing protectionLow
3432 of 3656 HTML pages send x-content-type-options. Without X-Content-Type-Options: nosniff a browser may run a file as a script because of its contents rather than its declared type.
- https://moz.com/login → no x-content-type-options
- https://moz.com/mozcast → no x-content-type-options
- https://moz.com/api/docs → no x-content-type-options
- https://moz.com/api/dashboard/usage → no x-content-type-options
- https://moz.com/freemium/keyword-explorer → no x-content-type-options
- https://moz.com/freemium/competitive-research → no x-content-type-options
- https://moz.com/freemium/local/check-listing → no x-content-type-options
- https://moz.com/subscriptions → no x-content-type-options
- https://moz.com/freemium/brand-authority-freemium-form → no x-content-type-options
- https://moz.com/api/docs/welcome → no x-content-type-options
- https://moz.com/api/dashboard → no x-content-type-options
- https://moz.com/api/docs/guides/getting-started → no x-content-type-options
- FoundPermissions policyInfo
No HTML page sends permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.
- https://moz.com/ → no permissions-policy
- https://moz.com/products/pro → no permissions-policy
- https://moz.com/products/local → no permissions-policy
- https://moz.com/products/stat → no permissions-policy
- https://moz.com/products/api → no permissions-policy
- https://moz.com/products → no permissions-policy
- https://moz.com/moz-data → no permissions-policy
- https://moz.com/explorer → no permissions-policy
- https://moz.com/link-explorer → no permissions-policy
- https://moz.com/competitive-research → no permissions-policy
- https://moz.com/products/pro/seo-toolbar → no permissions-policy
- https://moz.com/free-seo-tools → no permissions-policy
- FoundCookie flagsMedium
121 of 124 cookies are missing protective flags. Without HttpOnly a script can read the cookie; without Secure it travels over plain HTTP; without SameSite it is sent on cross-site requests.
- 09 Oct 2026 05:51:52 GMT (set by https://moz.com/images/cms/nav/ads/DiscoverAPI-TopNav-290x330.png?w=290&auto=co…) lacks Secure, HttpOnly, SameSite
- 09 Oct 2026 05:51:53 GMT (set by https://moz.com/images/assets/backgrounds/AI-Citations_homepage-hero_bg.jpg?aut…) lacks Secure, HttpOnly, SameSite
- 09 Oct 2026 05:52:33 GMT (set by https://moz.com/images/assets/features/moz-pro-product-pg-overview_ImproveVisib…) lacks Secure, HttpOnly, SameSite
- 09 Oct 2026 05:52:49 GMT (set by https://moz.com/images/assets/features/moz-pro-product-pg-overview_PathToHigher…) lacks Secure, HttpOnly, SameSite
- 09 Oct 2026 05:55:18 GMT (set by https://moz.com/images/blog/insets/MozCon-2026-Inset-Images/Crystal-Carter-MozC…) lacks Secure, HttpOnly, SameSite
- 09 Oct 2026 05:56:05 GMT (set by https://moz.com/images/blog/insets/AI-SEO.png?w=1360&h=900&auto=compress%2Cform…) lacks Secure, HttpOnly, SameSite
- 09 Oct 2026 05:56:07 GMT (set by https://moz.com/images/user/photo/726559-1605382316_2021-03-30-191432.jpg?w=160…) lacks Secure, HttpOnly, SameSite
- 09 Oct 2026 05:59:41 GMT (set by https://moz.com/images/cms/updated-content-optimization_ss.png?w=916&h=829&auto…) lacks Secure, HttpOnly, SameSite
- 09 Oct 2026 06:00:41 GMT (set by https://moz.com/images/user/photo/JB.jpg?w=160&h=160&auto=compress%2Cformat&fit…) lacks Secure, HttpOnly, SameSite
- 09 Oct 2026 02:16:20 GMT (set by https://moz.com/community/users/22308147) lacks Secure, HttpOnly, SameSite
- 09 Oct 2026 02:17:23 GMT (set by https://moz.com/community/users/22315201) lacks Secure, HttpOnly, SameSite
- 09 Oct 2026 06:01:02 GMT (set by https://moz.com/images/blog/insets/Whiteboard-Friday-Inset-Images/Miracle-How-t…) lacks Secure, HttpOnly, SameSite
- FoundMixed contentMedium
67 resources on HTTPS pages are loaded over plain HTTP, 2 of them scripts or stylesheets that browsers block or that can be tampered with in transit.
- https://moz.com/about/team/funnylookinhat loads image http://i.imgur.com/ctECATe.gif
- https://moz.com/about/team/funnylookinhat loads image http://i.imgur.com/8knHvsl.gif
- https://moz.com/blog/google-instant-fewer-changes-to-seo-than-the-ave… loads image http://blog.conductor.com/wp-content/uploads/2010/09/Research-visits-search-term-length-5…
- https://moz.com/blog/how-to-build-a-facebook-group loads image http://www.searchenginejournal.com/wp-content/uploads/2015/10/facebook-traffic-380x239.png
- https://moz.com/blog/how-to-build-a-facebook-group loads image http://www.searchenginejournal.com/wp-content/uploads/2015/10/Screen-Shot-2015-10-15-at-8…
- https://moz.com/blog/how-to-build-a-facebook-group loads image http://www.searchenginejournal.com/wp-content/uploads/2015/10/IMG_1055-380x310.png
- https://moz.com/blog/how-to-build-a-facebook-group loads image http://www.searchenginejournal.com/wp-content/uploads/2015/10/facebook-group-reach-760x27…
- https://moz.com/blog/how-to-build-a-facebook-group loads image http://www.searchenginejournal.com/wp-content/uploads/2015/10/Screen-Shot-2015-10-15-at-9…
- https://moz.com/blog/how-to-build-a-facebook-group loads image http://www.searchenginejournal.com/wp-content/uploads/2015/10/Screen-Shot-2015-10-16-at-9…
- https://moz.com/blog/how-to-build-a-facebook-group loads image http://www.searchenginejournal.com/wp-content/uploads/2015/10/Screen-Shot-2015-10-15-at-8…
- https://moz.com/blog/how-to-build-a-facebook-group loads image http://www.searchenginejournal.com/wp-content/uploads/2015/10/Screen-Shot-2015-10-16-at-9…
- https://moz.com/blog/how-to-build-a-facebook-group loads image http://www.searchenginejournal.com/wp-content/uploads/2015/10/Screen-Shot-2015-10-16-at-1…
- FoundVulnerable JavaScript librariesMedium
1 library with published vulnerabilities: jQuery 1.9.1. Whether they are exploitable depends on how the site uses them, but each has a fixed release.
- jQuery 1.9.1 in https://ajax.googleapis.com/ajax/libs/jquery/1.9.1/jquery.min.js: CVE-2015-9251 (XSS via cross-domain AJAX), CVE-2019-11358 (prototype pollution), CVE-2020-11022, CVE-2020-11023 (XSS via HTML passed to DOM methods); fixed in 3.5.0
- FoundKeys and secrets in page codeMedium
2 credential-like values found in code served to every visitor: Google API key.
- Google API key AIzaSy…gM (39 chars) in https://moz.com/_next/static/chunks/4023-2ef4432a0c1280ab.js: browser keys are expected in pages, but must be restricted by HTTP referrer and API in the Google Cloud console
- Google API key AIzaSy…tU (39 chars) in https://moz.com/_next/static/chunks/4023-2ef4432a0c1280ab.js: browser keys are expected in pages, but must be restricted by HTTP referrer and API in the Google Cloud console
- NoteSoftware version disclosure
Responses name the framework in an X-Powered-By header but hide the version.
- server: cloudflare (5958 responses)
- x-powered-by: NodeBB (1514 responses)
- NoteThird-party scripts
Scripts run from 6 other domains without Subresource Integrity, so a compromise of any of them changes what runs on this site. (Tag managers and analytics rarely support SRI; a Content-Security-Policy that names these hosts is the usual control.)
- cloud.wordlift.io (39 script tags)
- cdn.ziffstatic.com (39 script tags)
- moz-static.moz.com (156 script tags)
- static.cloudflareinsights.com (39 script tags)
- fast.wistia.com (12 script tags)
- js.hsforms.net (8 script tags)
- NoteSensitive paths in robots.txt
robots.txt lists 1 path that look private. robots.txt is public and does not restrict access, so it doubles as a map for anyone probing the site; those paths need real access control.
- Disallow: /admin-preview/*
7 checks passed
- OKHTTPS
All 3656 crawled pages were served over HTTPS.
- OKHTTP Strict Transport Security
strict-transport-security is set on all 3656 HTML pages.
- OKContent Security Policy
A Content-Security-Policy is set on 1210 of 3656 pages.
- OKClickjacking protection
x-frame-options is set on all 3656 HTML pages.
- OKReferrer policy
A referrer policy is set through a <meta name="referrer"> tag.
- OKForms over HTTPS
43 forms found, all on HTTPS pages posting to HTTPS addresses.
- OKExposed files and listings
None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.
A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.
Sites scoring near moz.com
Their neighbours in the SEO rank table, which orders every scanned site by health score.
- realenterprisesltd.comDR 373/100 · rank 1539 · 8 pages
- reginadancecity.caDR 273/100 · rank 1539 · 107 pages
- greatcanadian.caDR 2573/100 · rank 1539 · 171 pages
- www.rockymountainfenceutah.comDR 172/100 · rank 1606 · 43 pages
- www.blacksbbq.comDR 5672/100 · rank 1606 · 496 pages
- www.cdanjoyner.comDR 3472/100 · rank 1606 · 4,999 pages
DR is Ahrefs Domain Rating (0-100, backlink strength), used under its Domain Rating License.
This report was produced by the DIY SEO Hub Site Spider crawling moz.com from its pages as published, the way a search engine does. It shows summary figures only.
Own moz.com?
- Claim this site to manage the listing, hide it from the public lists, or keep it.
- Want it gone instead? Ask through the support form or e-mail support@diyseohub.com, naming moz.com. Removal needs no account and no proof of purchase.