Skip to content

CMS

Strapi Website Audit

Strapi audit: the API is not the website

· Configuration notes, not a newsroom.

A Strapi mention in HTML is a weak fingerprint. SiteRune scores the public frontend. Headers and llms.txt live there, not on /admin.

Strapi Website AuditST

What SiteRune checks on this stack

  • CMS / framework fingerprint from HTML, headers, cookies, and generator tags — fingerprint-based, not a plugin inventory
  • Titles, meta descriptions, canonicals, H1, and robots on the homepage and walked interiors
  • Security headers a crawler can see: HTTPS, HSTS, CSP, framing, nosniff, Referrer-Policy, Permissions-Policy
  • HTML TTFB, compression, and Cache-Control on the document — not a Lighthouse filmstrip
  • AI-bot robots policy, llms.txt, and Organization / FAQ / Article JSON-LD

Common problems

  • Marketing homepage looks finished; interior templates ship empty titles or leftover noindex
  • Hosted CMS cannot set HSTS/CSP, so the brief tells you to put a proxy in front instead of inventing an admin UI
  • A security plugin's 'block AI' preset Disallows GPTBot on a site that wanted citations
  • Session cookies or no-store on every anonymous GET, so the CDN never caches HTML

Do not paste the API URL

If you scan the Strapi admin or the raw API host, you get a useless brief. Scan the Next/Nuxt/Astro site people see. We skip obvious admin paths.

Node origin

Self-hosted Strapi plus a Node frontend: nginx or a CDN for HTML cache and security headers. We will not recommend a WordPress plugin. CORS and API auth are out of scope — not a pentest.

FAQ

How do you know this is my stack?

Fingerprints in HTML, headers, cookies, and generator tags. Confidence is a score, not a certificate. Unknown stacks stay generic — we will not invent a CMS.

Do I need an account?

Three guest scans, no card. Create a free account when you want history and more interiors.

Run it on a live URL

Same scan engine. Guest scans stay free.

https://