CMS
Rails audit: Passenger, sessions, and a CDN in front of the app
· Configuration notes, not a newsroom.
SiteRune fingerprints Rails sessions and Passenger. Public pages should be cacheable. Headers belong in nginx or config/nginx, not a layout helper only.
Turbolinks nostalgia is not the finding
Slow TTFB on Rails is usually uncached ERB plus a session on every request. fragment caching and a CDN in front of anonymous HTML. Skip admin and account in our crawl by design.
config is the vhost
Security headers in nginx or Rack::Headers. public/llms.txt. JSON-LD in the layout. We will not emit next.config.ts because someone used Stimulus.
Run it on a live URL
The brief will name your CMS and attach the files. Three guest scans, no card.