Resources

Platforms

The products and services a website is built on or served by — CMS, shop systems, CDNs, clouds, hosted services — and exactly how an external audit recognises each one.

cms

WordPress

The six signals that identify WordPress, why a stock install publishes its version, and which WordPress-specific checks an external audit can and cannot run.

Read
Drupal

The X-Generator header and file paths that reveal Drupal, the two security headers core sets on its own, and the cache debugging headers that should stay off.

Read

ecommerce

WooCommerce

The cookies, endpoint and assets that reveal WooCommerce, which pages must never be cached, and what the cart cookies mean for caching and consent.

Read
Magento and Adobe Commerce

The versioned static paths, modules and cookies that reveal Magento, what the deployment version in asset URLs means, and why production mode matters.

Read

email

Google Workspace (mail)

How Google Workspace is recognised from MX records, why its DKIM selector is probed by name, and the three records that decide whether its mail authenticates.

Read
Microsoft 365 (mail)

How Microsoft 365 is recognised from MX records, why DKIM uses two CNAME selectors, and the SPF include and DMARC behaviour Microsoft documents.

Read

infrastructure

Cloudflare

The headers that prove Cloudflare is proxying, what cf-cache-status values mean, why a DNS-only record exposes the origin, and what Flexible SSL hides.

Read
GitHub Pages

The Server header that reveals GitHub Pages, the Enforce HTTPS setting, mixed content in static sites, and the domain takeover that verification prevents.

Read
Amazon S3 static website hosting

The headers and bucket URLs that reveal S3, why S3 website endpoints cannot serve HTTPS, and how a bucket root can list every object instead of an index page.

Read
Microsoft Azure (edge and hosting)

The Front Door and Azure CDN headers and default hostnames that reveal Azure, why HTTPS-only is not on by default, and how traffic can bypass Front Door.

Read

monitoring

Sentry (browser)

The SDK scripts and DSN that reveal Sentry, why Sentry calls the DSN safe to keep public, and what Session Replay masks by default.

Read
Datadog Real User Monitoring

The browser agent and intake hosts that reveal Datadog Real User Monitoring, and why browser apps carry a client token rather than an API key.

Read
New Relic Browser

The NREUM loader and beacon hosts that reveal New Relic browser monitoring, and why the key in the page is a browser key rather than a license key.

Read

Elsewhere on this site