Scanned sites / youtube.com
SEO report for youtube.com
The latest Site Spider scan of youtube.com, with 1 scan on record. Each scan is at its own address, for example /domain/youtube-com/2026-09-23-1939.
Latest scan
Scanned 9/23/2026, 7:39:54 PM, finished 9/23/2026, 10:30:19 PM
Site: https://youtube.com/
Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.
On September 23, 2026 the Site Spider crawled 4154 pages and 890 assets of youtube.com, starting from https://youtube.com/. It scored 82 out of 100, a good result. 12 of 14 checks found something to fix, led by indexability (1229), orphan pages (927), thin content (604); 2 checks passed. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.
Security review: Medium5 medium, 1 low and 1 info findings. See the security findings ↓
- Pages crawled
- 4154
- Assets fetched
- 890
- Status
- Completed
- Checks with issues
- 12 of 14
- Title tags500 issues1976 of 2490 pages have title issues. 787 noindex or canonicalized pages excluded.
- Meta descriptions500 issues1714 of 2490 pages have meta description issues. 787 noindex or canonicalized pages excluded.
- Headings500 issues751 of 2490 pages have heading issues. 787 noindex or canonicalized pages excluded.
- Broken links18 issues232 internal links point at 18 broken URLs.
- Redirects499 issues861 redirecting URLs, 44 of them chained.
- Non-200 responsesOK1452 URLs did not return a 2xx response.
- Rate limitedOKThe site did not rate limit the crawler.
- Indexability1229 issues1229 of 3243 indexable pages have indexability warnings. 34 pages noindex by design.
- Image alt text439 issues439 of 59158 image references have no alt attribute. 5049 use an empty alt (decorative), which is fine.
- Heavy assets86 issues86 assets larger than 500 KB among the 100 heaviest.
- Orphan pages927 issues927 pages have no internal links pointing at them.
- Sitemap coverage500 issues19 sitemaps listing 2267 URLs: 510 crawled pages missing, 269 listed URLs broken or redirecting, 891 reachable only via the sitemap.
- Thin content604 issues604 of 2490 pages have fewer than 200 words. 787 noindex or canonicalized pages excluded.
- Duplicate content9 issues1 group of pages with identical HTML.
Where this site sits among all scanned sites
1212 sites, median 82%, average 80%
youtube.com scores 82%, higher than 49% of the 1212 scanned sites. See the full ranking.
Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).
Internal link map
Loading the link map...
Fix plan
Written by gpt-4o-mini from the scan findingsYour site has a good health score but some issues need addressing, primarily broken links and redirects. Improving title tags, meta descriptions, and fixing orphan pages will enhance SEO performance.
- 1
Fix Broken Links
Why: 232 internal links point to broken URLs, harming user experience and SEO.
How: Identify broken links and update or remove them from the site.
Checks: broken-links
- 2
Reduce Redirects
Why: 861 URLs redirect, causing delays and poor user experience.
How: Consolidate or remove unnecessary redirects, especially those in chains.
Checks: redirects
- 3
Address Non-200 Responses
Why: 1452 URLs are not returning a valid response, affecting accessibility.
How: Investigate and fix URLs generating non-200 responses.
Checks: status-codes
- 4
Enhance Title Tags
Why: 1976 pages have title issues, impacting visibility in search results.
How: Add or revise title tags to ensure uniqueness and relevance.
Checks: titles
- 5
Improve Meta Descriptions
Why: 1714 pages have meta description issues, reducing click-through rates.
How: Create unique and descriptive meta descriptions for affected pages.
Checks: meta-descriptions
- 6
Fix Orphan Pages
Why: 927 pages lack internal links, making them hard to discover.
How: Add internal links to orphan pages from related content.
Checks: orphan-pages
Generated automatically; verify each change against your own site before relying on it.
Security review
Written by gpt-4o-mini from 16 checks over the crawlThis review highlights several security issues on your website, including missing critical HTTP headers and outdated libraries. Addressing these findings will improve your protection against various web security threats.
- 0 high
- 5 medium
- 1 low
- 1 info
- 1
Missing HTTP Strict Transport Security (HSTS)Medium
Why it matters: Without HSTS, visitors can be intercepted on their first request when they miss the HTTPS prefix.
Fix: Add the header 'Strict-Transport-Security: max-age=31536000; includeSubDomains' to all responses.
Evidence: HTTP Strict Transport Security
- 2
Missing Clickjacking Protection (X-Frame-Options)Medium
Why it matters: Lack of this header allows embedding of your site in iframes, which can lead to clickjacking attacks.
Fix: Include the header 'X-Frame-Options: DENY' on all pages.
Evidence: Clickjacking protection
- 3
Missing SameSite Cookie FlagsMedium
Why it matters: Cookies without SameSite flag can be sent on cross-site requests, leading to potential CSRF attacks.
Fix: Set the SameSite attribute on cookies (e.g., 'Set-Cookie: GPS=...; SameSite=Lax') for all relevant cookies.
Evidence: Cookie flags
- 4
Vulnerable JavaScript LibrariesMedium
Why it matters: Using an outdated version of AngularJS exposes your site to known vulnerabilities.
Fix: Upgrade AngularJS to a maintained version or replace it with a newer framework.
Evidence: Vulnerable JavaScript libraries
- 5
Leaked Google API KeysMedium
Why it matters: Exposing API keys can lead to unauthorized access and misuse.
Fix: Restrict these API keys in the Google Cloud console by specifying appropriate HTTP referrer restrictions.
Evidence: Keys and secrets in page code
- 6
Missing Referrer PolicyLow
Why it matters: Without a referrer policy, sensitive URL parameters can be shared with third-party sites.
Fix: Implement 'Referrer-Policy: no-referrer' on all pages to limit referrer information.
Evidence: Referrer policy
- 7
Lack of Permissions PolicyInfo
Why it matters: Not setting this policy exposes users to potential risks from unused browser features.
Fix: Add 'Permissions-Policy: geolocation=(self), camera=()' to control feature access.
Evidence: Permissions policy
What the checks found
- FoundHTTP Strict Transport SecurityMedium
756 of 3277 HTML pages send strict-transport-security. Without it a visitor who types the address without https:// can be intercepted on the first request.
- https://www.youtube.com/creators/ → no strict-transport-security
- https://www.youtube.com/ads/ → no strict-transport-security
- https://www.youtube.com/howyoutubeworks/?utm_campaign=ytgen&utm_source=ythp&utm_medium=LeftNav&utm_content=txt&u=https%… → no strict-transport-security
- https://www.youtube.com/howyoutubeworks/our-policies/ → no strict-transport-security
- https://www.youtube.com/creators/get-started/ → no strict-transport-security
- https://www.youtube.com/creators/create/overview/ → no strict-transport-security
- https://www.youtube.com/creators/create/youtube-create-app/ → no strict-transport-security
- https://www.youtube.com/creators/create/shorts/ → no strict-transport-security
- https://www.youtube.com/creators/create/longform/ → no strict-transport-security
- https://www.youtube.com/creators/create/live/ → no strict-transport-security
- https://www.youtube.com/creators/create/podcasts/ → no strict-transport-security
- https://www.youtube.com/creators/create/ai-for-creators/ → no strict-transport-security
- FoundClickjacking protectionMedium
719 of 3277 HTML pages send x-frame-options. Without X-Frame-Options (or a CSP frame-ancestors directive) the pages can be embedded in a frame on another site and overlaid with invisible controls.
- https://www.youtube.com/t/contact_us/ → no x-frame-options
- https://www.youtube.com/creators/ → no x-frame-options
- https://www.youtube.com/ads/ → no x-frame-options
- https://www.youtube.com/t/terms → no x-frame-options
- https://www.youtube.com/howyoutubeworks/?utm_campaign=ytgen&utm_source=ythp&utm_medium=LeftNav&utm_content=txt&u=https%… → no x-frame-options
- https://www.youtube.com/howyoutubeworks/our-policies/ → no x-frame-options
- https://www.youtube.com/creators/get-started/ → no x-frame-options
- https://www.youtube.com/creators/create/overview/ → no x-frame-options
- https://www.youtube.com/creators/create/youtube-create-app/ → no x-frame-options
- https://www.youtube.com/creators/create/shorts/ → no x-frame-options
- https://www.youtube.com/creators/create/longform/ → no x-frame-options
- https://www.youtube.com/creators/create/live/ → no x-frame-options
- FoundReferrer policyLow
No HTML page sends referrer-policy. Without a Referrer-Policy the full page address, including any query string, is sent to every site a visitor clicks through to.
- https://www.youtube.com/ → no referrer-policy
- https://www.youtube.com/t/contact_us/ → no referrer-policy
- https://www.youtube.com/creators/ → no referrer-policy
- https://www.youtube.com/ads/ → no referrer-policy
- https://www.youtube.com/t/terms → no referrer-policy
- https://www.youtube.com/new → no referrer-policy
- https://www.youtube.com/howyoutubeworks/?utm_campaign=ytgen&utm_source=ythp&utm_medium=LeftNav&utm_content=txt&u=https%… → no referrer-policy
- https://www.youtube.com/howyoutubeworks/our-policies/ → no referrer-policy
- https://www.youtube.com/creators/get-started/ → no referrer-policy
- https://www.youtube.com/creators/create/overview/ → no referrer-policy
- https://www.youtube.com/creators/create/youtube-create-app/ → no referrer-policy
- https://www.youtube.com/creators/create/shorts/ → no referrer-policy
- FoundPermissions policyInfo
756 of 3277 HTML pages send permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.
- https://www.youtube.com/creators/ → no permissions-policy
- https://www.youtube.com/ads/ → no permissions-policy
- https://www.youtube.com/howyoutubeworks/?utm_campaign=ytgen&utm_source=ythp&utm_medium=LeftNav&utm_content=txt&u=https%… → no permissions-policy
- https://www.youtube.com/howyoutubeworks/our-policies/ → no permissions-policy
- https://www.youtube.com/creators/get-started/ → no permissions-policy
- https://www.youtube.com/creators/create/overview/ → no permissions-policy
- https://www.youtube.com/creators/create/youtube-create-app/ → no permissions-policy
- https://www.youtube.com/creators/create/shorts/ → no permissions-policy
- https://www.youtube.com/creators/create/longform/ → no permissions-policy
- https://www.youtube.com/creators/create/live/ → no permissions-policy
- https://www.youtube.com/creators/create/podcasts/ → no permissions-policy
- https://www.youtube.com/creators/create/ai-for-creators/ → no permissions-policy
- FoundCookie flagsMedium
2 of 8 cookies are missing protective flags. Without HttpOnly a script can read the cookie; without Secure it travels over plain HTTP; without SameSite it is sent on cross-site requests.
- GPS (set by https://www.youtube.com/) lacks SameSite
- NID (set by https://www.youtube.com/ads/) lacks SameSite
- FoundVulnerable JavaScript librariesMedium
1 library with published vulnerabilities: AngularJS 1.6.4. Whether they are exploitable depends on how the site uses them, but each has a fixed release.
- AngularJS 1.6.4 in https://ajax.googleapis.com/ajax/libs/angularjs/1.6.4/angular.min.js: end of life since January 2022; CVE-2022-25844, CVE-2022-25869, CVE-2023-26116, CVE-2023-26117, CVE-2023-26118 and later advisories will never be fixed; fixed in a maintained framework (AngularJS has no fixed release)
- FoundKeys and secrets in page codeMedium
2 credential-like values found in code served to every visitor: Google API key.
- Google API key AIzaSy…W8 (39 chars) in https://www.youtube.com/: browser keys are expected in pages, but must be restricted by HTTP referrer and API in the Google Cloud console
- Google API key AIzaSy…p0 (39 chars) in https://www.youtube.com/howyoutubeworks/static/compiled/shared.index.min.js?cac…: browser keys are expected in pages, but must be restricted by HTTP referrer and API in the Google Cloud console
- NoteContent Security Policy
A Content-Security-Policy is set, but it allows inline or eval scripts ('unsafe-inline' / 'unsafe-eval'), which removes most of its protection against injected scripts.
- https://www.youtube.com/ → require-trusted-types-for 'script', base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-MrrH2XTSdTTgECmlDB8BIQ' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval';report-uri https://csp.withgoogle.com/csp/youtube_main/strict
- https://www.youtube.com/t/contact_us/ → require-trusted-types-for 'script', base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-EAi9Hft0zF3FlXF48Omjlw' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval';report-uri https://csp.withgoogle.com/csp/youtube_main/strict
- https://www.youtube.com/ads/ → script-src 'nonce-Hd588gfqbSw4GOoDqPkXNQ' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/yt-ce-dev; base-uri 'none'
- https://www.youtube.com/t/terms → base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-KLor8rzeRbM6QUuqrVi2_g' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval';report-uri https://csp.withgoogle.com/csp/youtube_main/strict, require-trusted-types-for 'script'
- https://www.youtube.com/new → require-trusted-types-for 'script', base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-0vrWytKdbyuP7V_QfoaqDA' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval';report-uri https://csp.withgoogle.com/csp/youtube_main/strict
- https://www.youtube.com/howyoutubeworks/?utm_campaign=ytgen&utm_source=ythp&utm_medium=LeftNav&utm_content=txt&u=https%… → script-src 'nonce-J90umPE49rcNiQTPV0gNug' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/youtube-marketing; base-uri 'self'
- https://www.youtube.com/howyoutubeworks/our-policies/ → script-src 'nonce-t0kgG7E68h8GHjp3xaT_6Q' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/youtube-marketing; base-uri 'self'
- https://www.youtube.com/creators/get-started/ → script-src 'nonce-SwU3w2GDzNDotoKb3n6K1g' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/youtube-marketing; base-uri 'self'
- https://www.youtube.com/creators/create/overview/ → script-src 'nonce-fTXL38Z5Y2zbUbzFdyIXFg' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/youtube-marketing; base-uri 'self'
- https://www.youtube.com/creators/create/longform/ → script-src 'nonce-I6oAalmhsU_710kfFaqhgg' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/youtube-marketing; base-uri 'self'
- https://www.youtube.com/creators/create/ai-for-creators/ → script-src 'nonce-a3lvkUMIcNffRFVEoBkuqQ' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/youtube-marketing; base-uri 'self'
- https://www.youtube.com/creators/grow/overview/ → script-src 'nonce-lmU4a4b68BUC69y0PRWsnw' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/youtube-marketing; base-uri 'self'
- NoteThird-party scripts
Scripts run from 1 other domain without Subresource Integrity, so a compromise of any of them changes what runs on this site. (Tag managers and analytics rarely support SRI; a Content-Security-Policy that names these hosts is the usual control.)
- www.gstatic.com (28 script tags)
- NoteSensitive paths in robots.txt
robots.txt lists 1 path that look private. robots.txt is public and does not restrict access, so it doubles as a map for anyone probing the site; those paths need real access control.
- Disallow: /login
6 checks passed
- OKHTTPS
All 3277 crawled pages were served over HTTPS.
- OKMIME sniffing protection
x-content-type-options is set on all 3277 HTML pages.
- OKSoftware version disclosure
The Server header names a product without a version, and there is no X-Powered-By header.
- OKMixed content
No HTTPS page loads a script, stylesheet, font or image over plain HTTP.
- OKForms over HTTPS
2 forms found, all on HTTPS pages posting to HTTPS addresses.
- OKExposed files and listings
None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.
A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.
Earlier scans of youtube.com
No other scans of this site yet.
Sites scoring near youtube.com
Their neighbours in the SEO rank table, which orders every scanned site by health score.
- veprof.com83/100 · rank 521 · 96 pages
- www.physiomira.com82/100 · rank 571 · 37 pages
- www.tendingtoes.com82/100 · rank 571 · 23 pages
- www.germanautomotive.ca82/100 · rank 571 · 180 pages
- www.tsoralhealth.com82/100 · rank 571 · 44 pages
- www.radacutlery.com82/100 · rank 571 · 1,727 pages
This report was produced by the DIY SEO Hub Site Spider crawling youtube.com from its pages as published, the way a search engine does. It shows summary figures only.
Own youtube.com?
- Claim this site to manage the listing, hide it from the public lists, or keep it.
- Want it gone instead? Ask through the support form or e-mail support@diyseohub.com, naming youtube.com. Removal needs no account and no proof of purchase.