Skip to content

CMS

TYPO3 Website Audit

TYPO3 audit: realurl leftovers, cache, and headers at the vhost

· Configuration notes, not a newsroom.

SiteRune fingerprints TYPO3 from generator and HTML. Treat it as a serious PHP CMS: cache, fewer extensions on the home, nginx headers.

TYPO3 Website AuditTY

What SiteRune checks on this stack

  • CMS / framework fingerprint from HTML, headers, cookies, and generator tags — fingerprint-based, not a plugin inventory
  • Titles, meta descriptions, canonicals, H1, and robots on the homepage and walked interiors
  • Security headers a crawler can see: HTTPS, HSTS, CSP, framing, nosniff, Referrer-Policy, Permissions-Policy
  • HTML TTFB, compression, and Cache-Control on the document — not a Lighthouse filmstrip
  • AI-bot robots policy, llms.txt, and Organization / FAQ / Article JSON-LD

Common problems

  • Marketing homepage looks finished; interior templates ship empty titles or leftover noindex
  • Hosted CMS cannot set HSTS/CSP, so the brief tells you to put a proxy in front instead of inventing an admin UI
  • A security plugin's 'block AI' preset Disallows GPTBot on a site that wanted citations
  • Session cookies or no-store on every anonymous GET, so the CDN never caches HTML

Enterprise CMS, same crawler

We still fetch HTML and headers. Indexed search, workspaces, and backend are out of scope. Public pages need titles, canonicals, sitemap, HTTPS, HSTS.

Extensions vs edge

Do not install a 'security headers' extension that also rewrites robots to block AI. Put headers on the vhost. Publish llms.txt. SiteRune will not crawl typo3/ backend.

FAQ

How do you know this is my stack?

Fingerprints in HTML, headers, cookies, and generator tags. Confidence is a score, not a certificate. Unknown stacks stay generic — we will not invent a CMS.

Do I need an account?

Three guest scans, no card. Create a free account when you want history and more interiors.

Run it on a live URL

Same scan engine. Guest scans stay free.

https://