Site / Server Audit
A read-only, non-intrusive checklist for assessing the security posture of a website you have authorization to audit. Every check is passive — it does not exploit, brute-force, or modify the target.
When to invoke
- Onboarding a new client site, before deploy, after an infrastructure change
- Periodic re-audit (quarterly is a reasonable cadence for production)
- After any security advisory affecting the stack (Apache/nginx/PHP/WordPress/Node)
- When deciding whether t
[Description truncada. Veja o README completo no GitHub.]