Just finished building a security audit tool (and fixed the bit I forgot)
Well to be fair a member on here mentioned it and when I find your name m8 I will give you the credit…I forgot the body lol. Whoops! but now it is complete
It started because I kept running my site through Mozilla's HTTP Observatory and wanted to understand exactly how it scored things. If you read their docs, they explain how the scoring blocks break down, and if you dig deeper, how the individual bits inside those blocks are scored too. So I reflected that same scoring into my own tool.
Then came the grind: run my site through Observatory, change one thing, test again, over and over, until my scores matched theirs section by section. Once it lined up with Mozilla, I had a scoring chart that mirrored Observatory for every parameter.
From there I started building depth into it: DNS, mail-spoofing protection (SPF/DMARC/DKIM), and known software vulnerabilities via the CVE database, the stuff Observatory doesn't touch. So now it does everything Observatory does, plus a fair bit more.
Then someone pointed out something obvious: I'd been checking everything around the page (headers, TLS, DNS, mail) but not the page itself. I'd forgotten the body. That's now fixed. There's a new Page Content & Error Pages section that reads what your page actually exposes:
- secret API keys or tokens left in the HTML or scripts (shown masked, never in full)
- HTML comments giving away passwords, TODOs, staging or internal addresses
- source-map files that hand out your original code
- error pages that show stack traces, debug pages, SQL errors or exact software versions
- directory listings ("Index of /")
- plus, for information: email addresses on show, scripts loaded from other websites, and inline code that weakens your CSP
It's all passive. It reads the page and asks for one address that doesn't exist to see your error page, nothing a normal browser wouldn't do. That's 64 checks now.
You can run it on the whole site or on one individual page. That makes fixing things much easier: fix a page, re-test just that page, and see straight away whether the fix worked, without waiting on a full-site scan.
I've tested it against 200 of the internet's biggest sites and CMS platforms to make sure it holds up: real, varying scores, no false positives, no rubber-stamping everyone as fine. I tested the new body checks the same way, against sites built to fail, and against a tutorial page full of example stack traces to make sure code examples don't get flagged as real errors.
My own security audit page scores 150/A+ on Observatory, so I must have got something right. That's Mozilla's tool, not mine, so it's easy to verify.
The other thing that shocked me was how many security scanners out there are absolute crap. While building this I ran my own site through loads of them, and some just made things up. One reckoned I had a server and missing headers my site doesn't even have; another failed me for having no CAA record when I've clearly got one. That's half the reason I was so dead set on no false positives. Most of these tools cry wolf, and that's worse than telling you nothing.
The tool page is locked right down, and it should be. It's my own audit page, so it'd be a joke if that one wasn't tight.
Now I'm working through the rest page by page. The write-up page still sits at 76 because I've not tightened its CSP yet, and I've left that on show on purpose. There's no point building a tool that flags weaknesses if I go and hide my own.
Source: r/u/Jaycee-AIWebPageSEO · by /u/Jaycee-AIWebPageSEO