Resources
Platforms
The products and services a website is built on or served by — CMS, shop systems, CDNs, clouds, hosted services — and exactly how an external audit recognises each one.
cms
The six signals that identify WordPress, why a stock install publishes its version, and which WordPress-specific checks an external audit can and cannot run.
ReadThe X-Generator header and file paths that reveal Drupal, the two security headers core sets on its own, and the cache debugging headers that should stay off.
Readecommerce
The cookies, endpoint and assets that reveal WooCommerce, which pages must never be cached, and what the cart cookies mean for caching and consent.
ReadThe versioned static paths, modules and cookies that reveal Magento, what the deployment version in asset URLs means, and why production mode matters.
ReadHow Google Workspace is recognised from MX records, why its DKIM selector is probed by name, and the three records that decide whether its mail authenticates.
ReadHow Microsoft 365 is recognised from MX records, why DKIM uses two CNAME selectors, and the SPF include and DMARC behaviour Microsoft documents.
Readinfrastructure
The headers that prove Cloudflare is proxying, what cf-cache-status values mean, why a DNS-only record exposes the origin, and what Flexible SSL hides.
ReadThe Server header that reveals GitHub Pages, the Enforce HTTPS setting, mixed content in static sites, and the domain takeover that verification prevents.
ReadThe headers and bucket URLs that reveal S3, why S3 website endpoints cannot serve HTTPS, and how a bucket root can list every object instead of an index page.
ReadThe Front Door and Azure CDN headers and default hostnames that reveal Azure, why HTTPS-only is not on by default, and how traffic can bypass Front Door.
Readmonitoring
The SDK scripts and DSN that reveal Sentry, why Sentry calls the DSN safe to keep public, and what Session Replay masks by default.
ReadThe browser agent and intake hosts that reveal Datadog Real User Monitoring, and why browser apps carry a client token rather than an API key.
ReadThe NREUM loader and beacon hosts that reveal New Relic browser monitoring, and why the key in the page is a browser key rather than a license key.
Read