Skip to content

CMS

Rails audit: Passenger, sessions, and a CDN in front of the app

· Configuration notes, not a newsroom.

SiteRune fingerprints Rails sessions and Passenger. Public pages should be cacheable. Headers belong in nginx or config/nginx, not a layout helper only.

Turbolinks nostalgia is not the finding

Slow TTFB on Rails is usually uncached ERB plus a session on every request. fragment caching and a CDN in front of anonymous HTML. Skip admin and account in our crawl by design.

config is the vhost

Security headers in nginx or Rack::Headers. public/llms.txt. JSON-LD in the layout. We will not emit next.config.ts because someone used Stimulus.

Run it on a live URL

The brief will name your CMS and attach the files. Three guest scans, no card.

https://