Skip to main content
Back to Features
Main Page Analyzer

Homepage analyzer for security headers, request timing, and redirects

A technical audit of your homepage: HTTP security headers, request timing, protocol and HTTP version, the redirect chain, and canonical and hreflang signals.

50+ technical checks
Request timing
Free plan, no credit card
4 sites analyzed · headers, timing, redirects
SiteFindingsHTTPSHeadersTTFB
shop.acme.io4Yes3 missing810ms
acme-store.com2Yes1 missing240ms
blog.acme.dev0YesOK120ms
app.acme.io0YesOK98ms
1 site needs attention · CSP missing on shop.acme.io
Main page analysis is included in the free plan.Compare all plans

Every finding maps to a severity and standard

A sample of what a homepage scan surfaces. WebPixie checks 15+ security headers across 50+ technical checks, groups findings by severity, and ties them to recognized standards. These findings feed the composite WebPixie Site Score.

High

No Content-Security-Policy header

Removes a layer of protection against cross-site scripting.

open
Medium

HSTS max-age below six months

open
Medium

No Referrer-Policy header

open
Low

Cache-Control missing on the HTML response

open
Pass

Brotli compression enabled

pass
0 Critical1 High2 Medium1 Low1 Info
78Site Score signalsFeeds WebPixie Site Score analysis.

See exactly where homepage time goes

Each request phase is timed separately, from DNS lookup to the first byte. Your homepage is re-scanned every day, and WebPixie also records the browser-measured page load time and the rendered HTML size alongside the waterfall.

DNS lookup
24ms
TCP connect
18ms
TLS handshake
41ms
Pre-transfer
6ms
Time to first byte
112ms
Content download
63ms
Total264ms

See which HTTP protocols your site supports

WebPixie reports the protocols negotiated on the request, so you can confirm HTTP/2 is on and HTTPS is enforced.

HTTP/1.1HTTP/2HTTP/3HTTPSHTTPS redirect

Trace every redirect, hop by hop

A 200 at the end does not mean the path was clean. WebPixie traces each hop, so an extra redirect or an HTTP-to-HTTPS gap shows up instead of hiding behind the final response.

301http://acme.io/
308https://acme.io/
200https://www.acme.io/

3 requests · 2 redirects before the page loads. Each hop adds a round trip.

Review the canonical and language alternates engines read

WebPixie extracts the canonical URL and hreflang alternates on the homepage, so you can review the version your markup asks engines to prefer.

Canonicalhttps://www.acme.io/

Language alternates (hreflang)

x-defaulthttps://www.acme.io/
enhttps://www.acme.io/en
trhttps://www.acme.io/tr

How WebPixie analyzes your main page

Your homepage is often the first page visitors, crawlers, and bots see, so a problem there has wide reach. WebPixie loads your homepage and measures the whole request: the HTTP version and protocol, the redirect chain, the status code, request timing, content size, and the security headers returned. These findings feed WebPixie Site Score analysis alongside the other data WebPixie collects.

The header analysis covers 15+ security headers across 50+ checks, including HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, the cross-origin policies (COOP, COEP, CORP), CORS, Cache-Control, and cookie flags. A missing or weak header is flagged with its severity, so you can see which defenses are in place and which are absent.

Request timing and delivery sit in the same report. WebPixie shows where time goes across the request, whether HTTP to HTTPS is actually enforced, and whether the canonical and hreflang on the homepage point where you expect. Daily snapshots also capture browser-side signals such as JS console errors, cookies the page sets, and local and session storage contents, feeding checks like cookie security and mixed content alongside the header and timing analysis.

01

Review homepage security header findings

15+ headers, 50+ checks, each with a severity

Security headers are easy to misconfigure and easy to forget after a deploy. WebPixie checks HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, the cross-origin policies, CORS, and cookie flags. Each finding carries a severity, so a missing Content-Security-Policy, which removes a layer of protection against cross-site scripting, ranks above a cosmetic gap.

02

See where homepage time goes

Request timing, content size, HTTP version

A slow homepage costs conversions and visibility. WebPixie measures the request end to end, from DNS and connection setup through TLS and time to first byte, and reports the content size and the HTTP version negotiated. You can see whether the page is served over HTTP/2 and where the largest delays sit. Alongside the waterfall, WebPixie also records the browser-measured page load time and the rendered HTML size, so a bloated page or a slow client-side render shows up too.

03

Confirm HTTPS is actually enforced

The full redirect chain, hop by hop

An http URL that does not redirect to https, or a chain that bounces through extra hops, adds latency and weakens trust. WebPixie follows the redirect chain hop by hop and shows the response headers at each step, so you can confirm http to https is enforced and the chain is as short as it should be.

04

Check homepage canonical and hreflang

The signals engines read first

The homepage is a key crawl entry point, so its canonical and hreflang signals carry weight. WebPixie extracts the canonical target and checks whether it is self-referencing or points elsewhere, including cross-domain. It reads the hreflang alternates and flags non-reciprocating pairs, where one locale links to another that does not link back. This shows which URL is being signaled as the original, and it works alongside the site-wide view from the indexability checker.

Analyze your homepage in 60 seconds

Free plan, no credit card. Included on every plan.

Everything you need to monitor a website. In one workspace.

A quick look at other WebPixie features.

Why teams choose WebPixie for homepage analysis

Set up in 60 seconds

No agent to install and no access to your server needed. Enter a domain and WebPixie analyzes the homepage from its own servers.

Your whole site in one workspace

Main Page analysis sits next to uptime, SSL, DNS, domain, and link health in one dashboard. Its header and homepage checks feed your WebPixie Site Score.

Headers and timing together

One report covers security headers, request timing, and redirects, so you fix the homepage in one place.

Frequently Asked Questions

Common questions about the Main Page Analyzer.

The Main Page Analyzer checks the technical health, security posture, and SEO-critical signals on your homepage. WebPixie calls the homepage and evaluates response time, protocol support, HTTPS enforcement, redirect chains, canonical URL, hreflang tags, meta tags, cache directives, cookie attributes, and HTTP security headers. Header checks include HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP, COEP, CORP, CORS, and Cache-Control. The Main Page Analyzer assigns findings a severity level such as CRITICAL, HIGH, MEDIUM, LOW, or INFO so teams can decide what to fix first. It complements Indexability Checker checks for crawl and indexing signals, and uptime monitoring checks for ongoing availability and response behavior.

Yes, you can monitor campaign landing pages and find out fast when one is broken, slow, or incorrect. Uptime monitoring can check each landing page for reachability, response time, expected status code, redirects, and body keywords such as a campaign headline or form text. This helps catch issues like expired pages, failed deployments, broken tracking redirects, server errors, and missing conversion elements while campaigns are active. You can configure alerts through the notification channels available on your plan, so marketing, growth, or DevOps teams can respond before budget is wasted. For page-quality issues beyond availability, the Main Page Analyzer can surface caching, header, redirect, canonical, and meta problems that may affect conversion or search visibility. Use the Link Crawler to find broken links connected to campaign pages.

The connection-timing waterfall in the Main Page Analyzer breaks a homepage request into timed phases, so you can see where load time is spent. It records DNS lookup, TCP connection, TLS handshake, pre-transfer wait, time to first byte, content download, and the total, each as its own measurement. When a page feels slow, the waterfall shows whether the delay sits in DNS resolution, the TLS handshake, or the server's time to first byte, which points you at the layer to fix. It runs alongside the request and redirect path, HTTP protocol support flags, and canonical data on the Main Page view. This timing data, along with the browser-measured page load time and the rendered HTML size, is live today; Lighthouse-based SEO and performance scoring is in development and not yet part of the analysis. The waterfall complements response-time trends from uptime monitoring, and you can compare plan limits on the pricing page.

Yes, WebPixie shows response time data for landing pages during uptime checks. Uptime monitoring measures how long each monitored page takes to respond from the selected monitoring locations, so you can spot slowdowns, timeouts, and regional access problems while campaigns are running. This is especially useful for ad landing pages, checkout entry points, lead forms, and campaign pages where slow server response can reduce conversions. WebPixie can also validate expected status codes and body keywords, helping confirm that the page is both reachable and serving the right campaign content. The Main Page Analyzer adds technical context by checking response time, protocol behavior, redirect chains, cache headers, cookies, and other header-related issues. For broken or slow linked destinations, combine this with the Link Crawler.

Yes. The Main Page Analyzer detects which protocols your homepage supports and shows flags for HTTP, HTTP/2, HTTP/3, HTTPS, and whether HTTP redirects to HTTPS. These flags tell you whether visitors and crawlers can negotiate a faster HTTP/2 or HTTP/3 connection or are falling back to older protocols. The same view records the full request and redirect path with per-hop headers, the canonical URL and its alternates, and the connection-timing waterfall, so a missing HTTPS redirect or an unexpected hop is visible in one place. Protocol and header signals here overlap with what SSL monitoring validates on the certificate side, which is why teams often watch both. You can compare plan limits on the pricing page.

Ready to review your homepage signals?

Free plan, no credit card. Headers, timing, redirects, and browser diagnostics in one view.