CMS
Contentful Website Audit
Contentful: we saw the CDN. The origin is still your framework.
· Configuration notes, not a newsroom.
ctfassets.net is a fingerprint, not a CMS you configure in our UI. SiteRune still scores the Next/Nuxt/Astro (or unknown) origin that embeds Contentful.
COWhat SiteRune checks on this stack
- CMS / framework fingerprint from HTML, headers, cookies, and generator tags — fingerprint-based, not a plugin inventory
- Titles, meta descriptions, canonicals, H1, and robots on the homepage and walked interiors
- Security headers a crawler can see: HTTPS, HSTS, CSP, framing, nosniff, Referrer-Policy, Permissions-Policy
- HTML TTFB, compression, and Cache-Control on the document — not a Lighthouse filmstrip
- AI-bot robots policy, llms.txt, and Organization / FAQ / Article JSON-LD
Common problems
- Marketing homepage looks finished; interior templates ship empty titles or leftover noindex
- Hosted CMS cannot set HSTS/CSP, so the brief tells you to put a proxy in front instead of inventing an admin UI
- A security plugin's 'block AI' preset Disallows GPTBot on a site that wanted citations
- Session cookies or no-store on every anonymous GET, so the CDN never caches HTML
Headless is not a get-out-of-headers card
If images come from Contentful and HTML from Next.js, the Next.js playbook applies. We may list Contentful in the ecosystem. Missing HSTS is still an origin/CDN problem.
What Contentful will not do for you
It will not publish llms.txt, robots.txt, or security.txt. Those are origin files. JSON-LD is your template. SiteRune will not tell you to 'optimize the Contentful space' as a security finding.
FAQ
How do you know this is my stack?
Fingerprints in HTML, headers, cookies, and generator tags. Confidence is a score, not a certificate. Unknown stacks stay generic — we will not invent a CMS.
Do I need an account?
Three guest scans, no card. Create a free account when you want history and more interiors.
Run it on a live URL
Same scan engine. Guest scans stay free.