CMS
Strapi audit: the API is not the website
· Configuration notes, not a newsroom.
A Strapi mention in HTML is a weak fingerprint. SiteRune scores the public frontend. Headers and llms.txt live there, not on /admin.
Do not paste the API URL
If you scan the Strapi admin or the raw API host, you get a useless brief. Scan the Next/Nuxt/Astro site people see. We skip obvious admin paths.
Node origin
Self-hosted Strapi plus a Node frontend: nginx or a CDN for HTML cache and security headers. We will not recommend a WordPress plugin. CORS and API auth are out of scope — not a pentest.
Run it on a live URL
The brief will name your CMS and attach the files. Three guest scans, no card.