Scanned sites / semrush.com / 2026-10-05-1930

semrush.com scan from 10/5/2026, 7:30:30 PM

Scan 2026-10-05-1930

Scanned 10/5/2026, 7:30:30 PM, finished 10/5/2026, 8:59:16 PM. Found with 42backlinks.com tool directory

Site: https://semrush.com/

Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.

77/ 100Good

On October 5, 2026 the Site Spider crawled 5000 pages and 1000 assets of semrush.com, starting from https://semrush.com/. It scored 77 out of 100, a good result. 13 of 22 checks found something to fix, led by title tags (3,200), heavy assets (24), meta descriptions (3,220); 1 check passed. Most of the points went to title tags (−6.9), heavy assets (−6), meta descriptions (−5.5). 8 checks found something the score does not count, listed as noted. 1 check was not run because the crawl fetched nothing for it. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.

Security review: Medium2 medium, 3 low and 2 info findings. See the security findings ↓

Pages crawled
5000
Assets fetched
1000
Status
Completed
Checks with issues
13 of 22
CoverageJob finished, partial coverage

6,000 of 6,000 discovered URLs were fetched, 381,173 left out by the 5,000-page and 1,000-asset budget. The job finished, but the crawl did not reach everything it found. HTML only: nothing here ran JavaScript. 4,811 link destinations on other sites have not been checked.

  • Title tags3,200 issues
    3200 of 4108 pages have title issues. 539 noindex or canonicalized pages excluded.
    −6.9 points
  • Meta descriptions3,220 issues
    3220 of 4108 pages have meta description issues. 539 noindex or canonicalized pages excluded.
    −5.5 points
  • Headings128 issues
    128 of 4108 pages have heading issues. 539 noindex or canonicalized pages excluded.
    −0.2 points
  • Broken links41 issues
    70 internal links point at 41 broken URLs.
    −0.2 points
  • Links to other sitesNot checked
    Not checked: the crawl fetched nothing this check can look at.
  • Redirects327 issues
    315 redirecting URLs, 15 of them chained.
    −0.3 points
  • Non-200 responses41 issues
    364 URLs did not return a 2xx response. 353 of them are pages, 41 with an error status; the rest are assets or redirects.
    −0.1 points
  • Rate limitedOK
    The site did not rate limit the crawler.
  • Indexability58 issues
    58 of 4586 indexable pages have indexability warnings. 61 pages noindex by design.
    −0.1 points
  • Image alt text603 issues
    603 of 82050 image references have no alt attribute. 953 use an empty alt (decorative), which is fine.
  • Heavy assets24 issues
    24 assets larger than 500 KB among 1000 fetched assets.
    −6 points
  • Orphan pages40 issues
    40 pages have no internal links pointing at them.
  • Sitemap coverage2,999 issues
    28 sitemaps listing 35,164+ URLs (first 5,000 entries read): 2994 crawled pages missing, 5 listed URLs broken or redirecting, 0 reachable only via the sitemap. 34,045 listed URLs not crawled within the 5000-page budget.
    −3.9 points
  • Internal link counts451 noted
    Internal link counts for 500 pages; 451 worth a look.
  • Thin content90 issues
    90 of 4108 pages have fewer than 200 words. 539 noindex or canonicalized pages excluded.
    −0.2 points
  • Duplicate content2 issues
    1 group of pages with identical HTML.
  • URL format694 noted
    694 of 5000 page URLs are harder to read, share or cache than they need to be.
  • Canonicals508 noted
    508 of 4647 pages have a canonical worth checking.
  • Robots directives66 noted
    66 pages carry a robots directive; 4581 carry none.
  • Anchor text117 noted
    117 destinations are linked without useful anchor text, or with nofollow.
  • Title and heading structure3,653 noted
    3653 of 4108 pages could use the title, heading and snippet space better. 539 noindex or canonicalized pages excluded.
  • Image weight and alt length3,638 noted
    16 images over 100 KB; 3622 with alt text over 100 characters.
  • Response anomalies61 noted
    61 URLs answered in a way worth looking at.

Where this scan sits among all scanned sites

2083 sites, median 79%, average 78%

semrush.com scores 77%, higher than 39% of the 2083 scanned sites. See the full ranking.

0541070%: 0 sites1%: 0 sites2%: 0 sites3%: 0 sites4%: 0 sites5%: 0 sites6%: 0 sites7%: 0 sites8%: 0 sites9%: 0 sites10%: 0 sites11%: 0 sites12%: 0 sites13%: 0 sites14%: 0 sites15%: 0 sites16%: 0 sites17%: 0 sites18%: 0 sites19%: 0 sites20%: 0 sites21%: 1 site22%: 0 sites23%: 0 sites24%: 0 sites25%: 0 sites26%: 0 sites27%: 1 site28%: 0 sites29%: 0 sites30%: 0 sites31%: 0 sites32%: 0 sites33%: 1 site34%: 0 sites35%: 2 sites36%: 2 sites37%: 1 site38%: 3 sites39%: 2 sites40%: 2 sites41%: 1 site42%: 0 sites43%: 1 site44%: 1 site45%: 4 sites46%: 5 sites47%: 4 sites48%: 4 sites49%: 4 sites50%: 4 sites51%: 5 sites52%: 9 sites53%: 7 sites54%: 8 sites55%: 8 sites56%: 7 sites57%: 11 sites58%: 16 sites59%: 6 sites60%: 13 sites61%: 11 sites62%: 19 sites63%: 23 sites64%: 16 sites65%: 39 sites66%: 28 sites67%: 32 sites68%: 32 sites69%: 35 sites70%: 39 sites71%: 62 sites72%: 70 sites73%: 62 sites74%: 57 sites75%: 74 sites76%: 78 sites77%: 90 sites78%: 97 sites79%: 84 sites80%: 95 sites81%: 99 sites82%: 107 sites83%: 87 sites84%: 95 sites85%: 69 sites86%: 64 sites87%: 62 sites88%: 61 sites89%: 49 sites90%: 33 sites91%: 42 sites92%: 25 sites93%: 19 sites94%: 13 sites95%: 7 sites96%: 4 sites97%: 11 sites98%: 2 sites99%: 1 site100%: 57 sites77% here100%90%80%70%60%50%40%30%20%10%0%

Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).

Internal link map

Loading the link map...

Start page (centre)OKRedirectErrorOrphanLinked from most pagesOne inbound link or noneRings = clicks from the start page. Size = inbound links. Drag to pan, scroll to zoom, click a page to see only its links.

Fix plan

Written by gpt-4o-mini from the scan findings

The site has several issues that require attention, particularly broken links, redirects, title and meta description issues. Addressing these will enhance the SEO effectiveness and user experience significantly.

  1. 1

    Fix Broken Links

    Why: Broken links negatively impact user experience and SEO.

    How: Identify and redirect or remove the broken URLs listed in the findings.

    Checks: broken-links

  2. 2

    Resolve Redirect Chains

    Why: Chained redirects can slow down page loading and dilute SEO value.

    How: Streamline the redirects to direct users to the final destination without intermediate hops.

    Checks: redirects

  3. 3

    Update Title Tags

    Why: Issues in title tags can hinder search visibility and user engagement.

    How: Revise the titles of the affected 3200 pages to follow SEO best practices and ensure they are under 60 characters.

    Checks: titles

  4. 4

    Improve Meta Descriptions

    Why: Meta descriptions are crucial for click-through rates from search results.

    How: Craft unique meta descriptions for the 3220 pages with issues, keeping them concise and under 160 characters.

    Evidence: 2814 pages share the meta description "Open Trends", which usually means one template writes it for all of them.

    2,814 pages affected

    Depends on: If these pages really are the same content, the duplicate meta description is a symptom: canonicalise them to one URL instead.

    Checks: meta-descriptions

  5. 5

    Address Indexability Warnings

    Why: Pages with indexability warnings may not be properly indexed, impacting visibility.

    How: Examine the 58 indexable pages with warnings and ensure they are correctly configured for indexing.

    Checks: indexability

  6. 6

    Shrink Heavy Assets

    Why: Large assets can slow down page load time, affecting SEO and user experience.

    How: Optimize or restructure the 24 heavy assets over 500 KB to reduce load times.

    Evidence: 451 KB of script, loaded by 349 pages, so every visitor to any of them downloads it.

    349 pages affected

    Depends on: If it is a download rather than part of the page, weight matters less; move it out of the page instead.

    Checks: heavy-assets

Generated automatically; verify each change against your own site before relying on it.

Security review

Written by gpt-4o-mini from 16 checks over the crawl

The website semrush.com has several security issues that need addressing, primarily related to missing security headers and insecure cookies. Updating these configurations can enhance user data protection and reduce vulnerability risks.

  • 0 high
  • 2 medium
  • 3 low
  • 2 info
  1. 1

    Insecure Cookie FlagsMedium

    Why it matters: Cookies without protective flags can be easily accessed or manipulated by attackers.

    Fix: Set Secure and SameSite attributes for all cookies: e.g., Secure; SameSite=None.

    Evidence: Cookie flags

  2. 2

    Vulnerable JavaScript LibraryMedium

    Why it matters: Using jQuery 2.2.4 exposes the site to known vulnerabilities.

    Fix: Upgrade to jQuery version 3.5.0 or later.

    Evidence: Vulnerable JavaScript libraries

  3. 3

    Missing Referrer PolicyLow

    Why it matters: Without a Referrer-Policy, sensitive URL information is exposed to external sites.

    Fix: Set the header: Referrer-Policy: no-referrer.

    Evidence: Referrer policy

  4. 4

    Software Version DisclosureLow

    Why it matters: Disclosure of technologies used may aid attackers in targeting specific vulnerabilities.

    Fix: Remove or minimize X-Powered-By header output.

    Evidence: Software version disclosure

  5. 5

    Lack of Subresource Integrity for Third-Party ScriptsLow

    Why it matters: Compromised third-party scripts could allow malicious code execution.

    Fix: Implement Subresource Integrity for all external scripts or use a Content-Security-Policy.

    Evidence: Third-party scripts

  6. 6

    Missing Permissions PolicyInfo

    Why it matters: A Permissions-Policy header can limit features available to potential attackers.

    Fix: Set the header: Permissions-Policy: geolocation=(self), microphone=(), camera=().

    Evidence: Permissions policy

  7. 7

    Sensitive Paths in Robots.txtInfo

    Why it matters: Listing potentially sensitive paths can lead to increased probing by attackers.

    Fix: Review access permissions and consider removing sensitive entries from robots.txt.

    Evidence: Sensitive paths in robots.txt

What the checks found

  • FoundReferrer policyLow

    655 of 4647 HTML pages send referrer-policy. Without a Referrer-Policy the full page address, including any query string, is sent to every site a visitor clicks through to.

    • https://www.semrush.com/ → no referrer-policy
    • https://www.semrush.com/mcp/ → no referrer-policy
    • https://www.semrush.com/features/keyword-research/ → no referrer-policy
    • https://www.semrush.com/features/competitor-analysis/ → no referrer-policy
    • https://www.semrush.com/features/ai-visibility/ → no referrer-policy
    • https://www.semrush.com/features/prompt-research/ → no referrer-policy
    • https://www.semrush.com/features/local-seo/ → no referrer-policy
    • https://www.semrush.com/features/market-analysis/ → no referrer-policy
    • https://www.semrush.com/features/content-marketing/ → no referrer-policy
    • https://www.semrush.com/features/site-audit/ → no referrer-policy
    • https://www.semrush.com/features/digital-pr/ → no referrer-policy
    • https://www.semrush.com/features/rank-tracking/ → no referrer-policy
  • FoundPermissions policyInfo

    No HTML page sends permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.

    • https://www.semrush.com/ → no permissions-policy
    • https://www.semrush.com/signup/?src=main_banner&custom=ai-seo&redirect_to=%2Fseo%2F&trial=force → no permissions-policy
    • https://www.semrush.com/login/?src=header → no permissions-policy
    • https://www.semrush.com/signup/?src=header → no permissions-policy
    • https://www.semrush.com/one/ → no permissions-policy
    • https://www.semrush.com/mcp/ → no permissions-policy
    • https://www.semrush.com/stats/ → no permissions-policy
    • https://www.semrush.com/kb/request-demo/ → no permissions-policy
    • https://www.semrush.com/features/keyword-research/ → no permissions-policy
    • https://www.semrush.com/features/competitor-analysis/ → no permissions-policy
    • https://www.semrush.com/features/ai-visibility/ → no permissions-policy
    • https://www.semrush.com/features/prompt-research/ → no permissions-policy
  • FoundCookie flagsMedium

    11 of 12 cookies are missing protective flags. Without HttpOnly a script can read the cookie; without Secure it travels over plain HTTP; without SameSite it is sent on cross-site requests.

    • GCLB (set by https://semrush.com/) lacks Secure, SameSite
    • PHPSESSID (set by https://www.semrush.com/) lacks SameSite
    • SSO-JWT (set by https://www.semrush.com/) lacks SameSite
    • site_csrftoken (set by https://www.semrush.com/signup/?src=main_banner&custom=ai-seo&redirect_to=%2Fse…) lacks Secure
    • localization (set by https://www.semrush.com/blog/) lacks Secure, HttpOnly, SameSite
    • ahoy_visitor (set by https://www.semrush.com/news/) lacks Secure, HttpOnly
    • ahoy_visit (set by https://www.semrush.com/news/) lacks Secure, HttpOnly
    • app_center_csrf_token (set by https://www.semrush.com/apps/) lacks Secure, HttpOnly, SameSite
    • csrftoken (set by https://www.semrush.com/listing-management/) lacks Secure, HttpOnly
    • refer_source (set by https://www.semrush.com/billing/offers/buy/y6eei2i6) lacks SameSite
    • usertype (set by https://www.semrush.com/billing/offers/buy/y6eei2i6) lacks HttpOnly, SameSite
  • FoundVulnerable JavaScript librariesMedium

    1 library with published vulnerabilities: jQuery 2.2.4. Whether they are exploitable depends on how the site uses them, but each has a fixed release.

    • jQuery 2.2.4 in https://cdnjs.cloudflare.com/ajax/libs/jquery/2.2.4/jquery.min.js: CVE-2015-9251 (XSS via cross-domain AJAX), CVE-2019-11358 (prototype pollution), CVE-2020-11022, CVE-2020-11023 (XSS via HTML passed to DOM methods); fixed in 3.5.0
  • NoteSoftware version disclosure

    Responses name the framework in an X-Powered-By header but hide the version.

    • server: nginx (5989 responses)
    • x-powered-by: Next.js (2 responses)
  • NoteThird-party scripts

    Scripts run from 7 other domains without Subresource Integrity, so a compromise of any of them changes what runs on this site. (Tag managers and analytics rarely support SRI; a Content-Security-Policy that names these hosts is the usual control.)

    • static.semrush.com (71 script tags)
    • cdn.speedcurve.com (6 script tags)
    • lp.semrush.com (5 script tags)
    • cdn.jsdelivr.net (2 script tags)
    • cdnjs.cloudflare.com (2 script tags)
    • cdn.semrush.com (1 script tag)
    • www.google.com (1 script tag)
  • NoteSensitive paths in robots.txt

    robots.txt lists 3 paths that look private. robots.txt is public and does not restrict access, so it doubles as a map for anyone probing the site; those paths need real access control.

    • Disallow: /admin/
    • Disallow: /seo-old/*
    • Disallow: /login/*
9 checks passed
  • OKHTTPS

    All 4647 crawled pages were served over HTTPS.

  • OKHTTP Strict Transport Security

    strict-transport-security is set on all 4647 HTML pages.

  • OKContent Security Policy

    A Content-Security-Policy is set on 763 of 4647 pages.

  • OKClickjacking protection

    x-frame-options is set on all 4647 HTML pages.

  • OKMIME sniffing protection

    x-content-type-options is set on all 4647 HTML pages.

  • OKMixed content

    No HTTPS page loads a script, stylesheet, font or image over plain HTTP.

  • OKForms over HTTPS

    5 forms found, all on HTTPS pages posting to HTTPS addresses.

  • OKKeys and secrets in page code

    No API keys, tokens or private keys were found in the sampled HTML and scripts.

  • OKExposed files and listings

    None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.

A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.

Sites scoring near semrush.com

Their neighbours in the SEO rank table, which orders every scanned site by health score.

This report was produced by the DIY SEO Hub Site Spider crawling semrush.com from its pages as published, the way a search engine does. It shows summary figures only.

Own semrush.com?

semrush.com scan 2026-10-05-1930 | DIY SEO Hub