Audit a public-facing site or server for common misconfigurations without sending exploit traffic. Covers DNS hygiene, TLS and HSTS, security headers, exposed paths (.git, .env, backups), cookie flags, and software fingerprinting. Invoke when onboarding a new client site, before launch, after infrastructure changes, or as periodic re-audit.
The exact command may vary by repository. Check the README on GitHub.
For the skill author
Drop this on your repo README
Shows your skill is listed on Skillteca, generates a backlink and trackable traffic.
[](https://www.skillteca.com.br/skills/site-server-audit?utm_source=badge&utm_medium=readme&utm_campaign=badge)
One short email with only the new Segurança skills. 4 minutes of reading, no spam, unsubscribe with one click.
You confirm your email on the first send. No spam. Unsubscribe with one click.
Site / Server Audit
A read-only, non-intrusive checklist for assessing the security posture of a website you have authorization to audit. Every check is passive — it does not exploit, brute-force, or modify the target.
When to invoke
Onboarding a new client site, before deploy, after an infrastructure change
Periodic re-audit (quarterly is a reasonable cadence for production)
After any security advisory affecting the stack (Apache/nginx/PHP/WordPress/Node)
When deciding whether t
[Description truncada. Veja o README completo no GitHub.]