Scanned sites / semrush.com / 2026-10-08-2102

semrush.com scan from 10/8/2026, 9:02:22 PM DR 92

DR is Ahrefs Domain Rating (0-100, backlink strength), used under its Domain Rating License.

Scan 2026-10-08-2102

Scanned 10/8/2026, 9:02:22 PM, finished 10/8/2026, 10:32:02 PM. Found with 42backlinks.com tool directory

Site: https://semrush.com/

Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.

77/ 100Good

On October 8, 2026 the Site Spider crawled 5000 pages and 1000 assets of semrush.com, starting from https://semrush.com/. It scored 77 out of 100, a good result. 14 of 23 checks found something to fix, led by title tags (3,193), heavy assets (25), meta descriptions (3,221); 1 check passed. Most of the points went to title tags (−6.9), heavy assets (−6), meta descriptions (−5.5). 8 checks found something the score does not count, listed as noted. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.

Security review: Medium2 medium, 3 low and 2 info findings. See the security findings ↓

Pages crawled
5000
Assets fetched
1000
Status
Completed
Checks with issues
14 of 23
CoverageJob finished, partial coverage

6,000 of 6,000 discovered URLs were fetched, 387,766 left out by the 5,000-page and 1,000-asset budget. The job finished, but the crawl did not reach everything it found. HTML only: nothing here ran JavaScript. 300 link destinations on other sites were checked, 4533 left unchecked.

  • Title tags3,193 issues
    3193 of 4102 pages have title issues. 543 noindex or canonicalized pages excluded.
    −6.9 points
  • Meta descriptions3,221 issues
    3221 of 4102 pages have meta description issues. 543 noindex or canonicalized pages excluded.
    −5.5 points
  • Headings130 issues
    130 of 4102 pages have heading issues. 543 noindex or canonicalized pages excluded.
    −0.2 points
  • Broken links41 issues
    70 internal links point at 41 broken URLs.
    −0.2 points
  • Links to other sites15 issues
    15 destinations answered with an error, 82 could not be determined (timeouts, rate limits or refusals), 4533 were left unchecked by the per-scan cap, of 300 destinations checked.
    −0.1 points
  • Redirects329 issues
    317 redirecting URLs, 15 of them chained.
    −0.3 points
  • Non-200 responses41 issues
    365 URLs did not return a 2xx response. 355 of them are pages, 41 with an error status; the rest are assets or redirects.
    −0.1 points
  • Rate limitedOK
    The site did not rate limit the crawler.
  • Indexability58 issues
    58 of 4584 indexable pages have indexability warnings. 61 pages noindex by design.
    −0.1 points
  • Image alt text604 issues
    604 of 81923 image references have no alt attribute. 963 use an empty alt (decorative), which is fine.
  • Heavy assets25 issues
    25 assets larger than 500 KB among 1000 fetched assets.
    −6 points
  • Orphan pages40 issues
    40 pages have no internal links pointing at them.
  • Sitemap coverage2,611 issues
    61 sitemaps listing 43,598+ URLs (first 5,000 entries read): 2606 crawled pages missing, 5 listed URLs broken or redirecting, 0 reachable only via the sitemap. 42,097 listed URLs not crawled within the 5000-page budget.
    −3.4 points
  • Internal link counts451 noted
    Internal link counts for 500 pages; 451 worth a look.
  • Thin content90 issues
    90 of 4102 pages have fewer than 200 words. 543 noindex or canonicalized pages excluded.
    −0.2 points
  • Duplicate content2 issues
    1 group of pages with identical HTML.
  • URL format697 noted
    697 of 5000 page URLs are harder to read, share or cache than they need to be.
  • Canonicals512 noted
    512 of 4645 pages have a canonical worth checking.
  • Robots directives66 noted
    66 pages carry a robots directive; 4579 carry none.
  • Anchor text117 noted
    117 destinations are linked without useful anchor text, or with nofollow.
  • Title and heading structure3,647 noted
    3647 of 4102 pages could use the title, heading and snippet space better. 543 noindex or canonicalized pages excluded.
  • Image weight and alt length3,626 noted
    16 images over 100 KB; 3610 with alt text over 100 characters.
  • Response anomalies61 noted
    61 URLs answered in a way worth looking at.

Where this scan sits among all scanned sites

2166 sites, median 79%, average 78%

semrush.com scores 77%, higher than 39% of the 2166 scanned sites. See the full ranking.

0541080%: 0 sites1%: 0 sites2%: 0 sites3%: 0 sites4%: 0 sites5%: 0 sites6%: 0 sites7%: 0 sites8%: 0 sites9%: 0 sites10%: 0 sites11%: 0 sites12%: 0 sites13%: 0 sites14%: 1 site15%: 0 sites16%: 0 sites17%: 0 sites18%: 0 sites19%: 0 sites20%: 0 sites21%: 1 site22%: 0 sites23%: 0 sites24%: 0 sites25%: 0 sites26%: 0 sites27%: 1 site28%: 0 sites29%: 0 sites30%: 0 sites31%: 0 sites32%: 0 sites33%: 1 site34%: 0 sites35%: 2 sites36%: 2 sites37%: 1 site38%: 3 sites39%: 2 sites40%: 2 sites41%: 2 sites42%: 0 sites43%: 2 sites44%: 1 site45%: 4 sites46%: 6 sites47%: 4 sites48%: 4 sites49%: 4 sites50%: 4 sites51%: 5 sites52%: 9 sites53%: 6 sites54%: 9 sites55%: 8 sites56%: 7 sites57%: 12 sites58%: 16 sites59%: 6 sites60%: 14 sites61%: 13 sites62%: 20 sites63%: 24 sites64%: 18 sites65%: 37 sites66%: 29 sites67%: 33 sites68%: 33 sites69%: 38 sites70%: 42 sites71%: 66 sites72%: 74 sites73%: 66 sites74%: 61 sites75%: 73 sites76%: 80 sites77%: 90 sites78%: 98 sites79%: 87 sites80%: 104 sites81%: 101 sites82%: 108 sites83%: 91 sites84%: 99 sites85%: 73 sites86%: 67 sites87%: 64 sites88%: 59 sites89%: 57 sites90%: 33 sites91%: 40 sites92%: 27 sites93%: 22 sites94%: 13 sites95%: 7 sites96%: 5 sites97%: 11 sites98%: 2 sites99%: 1 site100%: 61 sites77% here100%90%80%70%60%50%40%30%20%10%0%

Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).

Internal link map

Loading the link map...

Start page (centre)OKRedirectErrorOrphanLinked from most pagesOne inbound link or noneRings = clicks from the start page. Size = inbound links. Drag to pan, scroll to zoom, click a page to see only its links.

Fix plan

Written by gpt-4o-mini from the scan findings

Your site has several technical issues that need addressing to improve SEO performance. Prioritize fixing broken links, redirects, and title/meta description issues.

  1. 1

    Fix Broken Links

    Why: Broken links harm user experience and SEO.

    How: Identify and update or remove the 70 internal links pointing to broken URLs.

    Checks: broken-links

  2. 2

    Address Redirects

    Why: Too many redirects can slow down page load speed and confuse users.

    How: Streamline 317 redirecting URLs, especially the 15 chained redirects, to enhance site efficiency.

    Checks: redirects

  3. 3

    Resolve Non-200 Responses

    Why: URLs returning non-200 responses can negatively impact site visibility.

    How: Fix or remove 365 URLs that are not returning a 2xx response to ensure users find your content.

    Checks: status-codes

  4. 4

    Improve Title Tags

    Why: Improving title tags can enhance click-through rates from search results.

    How: Revise 3193 pages with title issues to ensure they're unique and within the 60-character limit.

    Checks: titles

  5. 5

    Enhance Meta Descriptions

    Why: Meta descriptions play a crucial role in SEO and click-through rates.

    How: Write unique meta descriptions for 3221 pages to improve search visibility and user engagement.

    Evidence: 2807 pages share the meta description "Open Trends", which usually means one template writes it for all of them.

    2,807 pages affected

    Depends on: If these pages really are the same content, the duplicate meta description is a symptom: canonicalise them to one URL instead.

    Checks: meta-descriptions

  6. 6

    Fix Heading Issues

    Why: Missing H1s can hinder SEO performance.

    How: Ensure that the 130 pages missing H1 tags have appropriate headings for better SEO.

    Checks: headings

Generated automatically; verify each change against your own site before relying on it.

Security review

Written by gpt-4o-mini from 16 checks over the crawl

The security review of semrush.com identified several issues that could impact user privacy and application security. Most notably, missing security headers, vulnerable libraries, and inadequate cookie settings were found. Addressing these will enhance the overall security posture of the site.

  • 0 high
  • 2 medium
  • 3 low
  • 2 info
  1. 1

    Insecure Cookie FlagsMedium

    Why it matters: Cookies lacking Secure, HttpOnly, and SameSite flags can be exploited, risking session hijacking.

    Fix: Set Secure, HttpOnly, and SameSite=None or SameSite=Strict on all cookies.

    Evidence: Cookie flags

  2. 2

    Vulnerable JavaScript LibraryMedium

    Why it matters: jQuery 2.2.4 has known vulnerabilities that could be exploited if used improperly.

    Fix: Upgrade jQuery to version 3.5.0 or later to mitigate known issues.

    Evidence: Vulnerable JavaScript libraries

  3. 3

    Missing Referrer PolicyLow

    Why it matters: Without a Referrer-Policy, sensitive URLs are exposed to third parties on click-throughs.

    Fix: Add a Referrer-Policy header with a value like 'no-referrer' to all HTML pages.

    Evidence: Referrer policy

  4. 4

    Server Version DisclosureLow

    Why it matters: The presence of software version information in headers can aid attackers in targeting vulnerabilities.

    Fix: Consider removing the X-Powered-By header from responses to hide version details.

    Evidence: Software version disclosure

  5. 5

    Lack of Subresource Integrity for Third-Party ScriptsLow

    Why it matters: Without Subresource Integrity, compromised third-party scripts can alter site behavior.

    Fix: Add Subresource Integrity attributes (SRI) to all external script tags.

    Evidence: Third-party scripts

  6. 6

    Missing Permissions PolicyInfo

    Why it matters: Absence of a Permissions-Policy header can lead to unnecessary exposure of browser features.

    Fix: Implement a Permissions-Policy header to restrict browser features like camera or geolocation.

    Evidence: Permissions policy

  7. 7

    Sensitive Paths Listed in robots.txtInfo

    Why it matters: Publicly accessible robots.txt can expose sensitive paths that may be vulnerable.

    Fix: Restrict access to the mentioned sensitive paths with proper authentication mechanisms.

    Evidence: Sensitive paths in robots.txt

What the checks found

  • FoundReferrer policyLow

    654 of 4645 HTML pages send referrer-policy. Without a Referrer-Policy the full page address, including any query string, is sent to every site a visitor clicks through to.

    • https://www.semrush.com/ → no referrer-policy
    • https://www.semrush.com/mcp/ → no referrer-policy
    • https://www.semrush.com/features/keyword-research/ → no referrer-policy
    • https://www.semrush.com/features/competitor-analysis/ → no referrer-policy
    • https://www.semrush.com/features/ai-visibility/ → no referrer-policy
    • https://www.semrush.com/features/prompt-research/ → no referrer-policy
    • https://www.semrush.com/features/local-seo/ → no referrer-policy
    • https://www.semrush.com/features/market-analysis/ → no referrer-policy
    • https://www.semrush.com/features/content-marketing/ → no referrer-policy
    • https://www.semrush.com/features/site-audit/ → no referrer-policy
    • https://www.semrush.com/features/digital-pr/ → no referrer-policy
    • https://www.semrush.com/features/rank-tracking/ → no referrer-policy
  • FoundPermissions policyInfo

    No HTML page sends permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.

    • https://www.semrush.com/ → no permissions-policy
    • https://www.semrush.com/signup/?src=main_banner&custom=ai-seo&redirect_to=%2Fseo%2F&trial=force → no permissions-policy
    • https://www.semrush.com/login/?src=header → no permissions-policy
    • https://www.semrush.com/signup/?src=header → no permissions-policy
    • https://www.semrush.com/one/ → no permissions-policy
    • https://www.semrush.com/mcp/ → no permissions-policy
    • https://www.semrush.com/stats/ → no permissions-policy
    • https://www.semrush.com/kb/request-demo/ → no permissions-policy
    • https://www.semrush.com/features/keyword-research/ → no permissions-policy
    • https://www.semrush.com/features/competitor-analysis/ → no permissions-policy
    • https://www.semrush.com/features/ai-visibility/ → no permissions-policy
    • https://www.semrush.com/features/prompt-research/ → no permissions-policy
  • FoundCookie flagsMedium

    11 of 12 cookies are missing protective flags. Without HttpOnly a script can read the cookie; without Secure it travels over plain HTTP; without SameSite it is sent on cross-site requests.

    • GCLB (set by https://semrush.com/) lacks Secure, SameSite
    • PHPSESSID (set by https://www.semrush.com/) lacks SameSite
    • SSO-JWT (set by https://www.semrush.com/) lacks SameSite
    • site_csrftoken (set by https://www.semrush.com/signup/?src=main_banner&custom=ai-seo&redirect_to=%2Fse…) lacks Secure
    • localization (set by https://www.semrush.com/blog/) lacks Secure, HttpOnly, SameSite
    • ahoy_visitor (set by https://www.semrush.com/news/) lacks Secure, HttpOnly
    • ahoy_visit (set by https://www.semrush.com/news/) lacks Secure, HttpOnly
    • app_center_csrf_token (set by https://www.semrush.com/apps/) lacks Secure, HttpOnly, SameSite
    • csrftoken (set by https://www.semrush.com/listing-management/) lacks Secure, HttpOnly
    • refer_source (set by https://www.semrush.com/billing/offers/buy/y6eei2i6) lacks SameSite
    • usertype (set by https://www.semrush.com/billing/offers/buy/y6eei2i6) lacks HttpOnly, SameSite
  • FoundVulnerable JavaScript librariesMedium

    1 library with published vulnerabilities: jQuery 2.2.4. Whether they are exploitable depends on how the site uses them, but each has a fixed release.

    • jQuery 2.2.4 in https://cdnjs.cloudflare.com/ajax/libs/jquery/2.2.4/jquery.min.js: CVE-2015-9251 (XSS via cross-domain AJAX), CVE-2019-11358 (prototype pollution), CVE-2020-11022, CVE-2020-11023 (XSS via HTML passed to DOM methods); fixed in 3.5.0
  • NoteSoftware version disclosure

    Responses name the framework in an X-Powered-By header but hide the version.

    • server: nginx (5989 responses)
    • x-powered-by: Next.js (2 responses)
  • NoteThird-party scripts

    Scripts run from 7 other domains without Subresource Integrity, so a compromise of any of them changes what runs on this site. (Tag managers and analytics rarely support SRI; a Content-Security-Policy that names these hosts is the usual control.)

    • static.semrush.com (71 script tags)
    • cdn.speedcurve.com (6 script tags)
    • lp.semrush.com (5 script tags)
    • cdn.jsdelivr.net (2 script tags)
    • cdnjs.cloudflare.com (2 script tags)
    • cdn.semrush.com (1 script tag)
    • www.google.com (1 script tag)
  • NoteSensitive paths in robots.txt

    robots.txt lists 3 paths that look private. robots.txt is public and does not restrict access, so it doubles as a map for anyone probing the site; those paths need real access control.

    • Disallow: /admin/
    • Disallow: /seo-old/*
    • Disallow: /login/*
9 checks passed
  • OKHTTPS

    All 4645 crawled pages were served over HTTPS.

  • OKHTTP Strict Transport Security

    strict-transport-security is set on all 4645 HTML pages.

  • OKContent Security Policy

    A Content-Security-Policy is set on 767 of 4645 pages.

  • OKClickjacking protection

    x-frame-options is set on all 4645 HTML pages.

  • OKMIME sniffing protection

    x-content-type-options is set on all 4645 HTML pages.

  • OKMixed content

    No HTTPS page loads a script, stylesheet, font or image over plain HTTP.

  • OKForms over HTTPS

    5 forms found, all on HTTPS pages posting to HTTPS addresses.

  • OKKeys and secrets in page code

    No API keys, tokens or private keys were found in the sampled HTML and scripts.

  • OKExposed files and listings

    None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.

A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.

Sites scoring near semrush.com

Their neighbours in the SEO rank table, which orders every scanned site by health score.

DR is Ahrefs Domain Rating (0-100, backlink strength), used under its Domain Rating License.

This report was produced by the DIY SEO Hub Site Spider crawling semrush.com from its pages as published, the way a search engine does. It shows summary figures only.

Own semrush.com?

semrush.com scan 2026-10-08-2102 | DIY SEO Hub