Report:  Server & Tech Stack

We are checking the server technology and software used to build the website, frameworks and analytics tools

Server and tech stack analysis is crucial for understanding the underlying infrastructure and security measures of a website. It helps identify potential vulnerabilities, optimize performance, and ensure compliance with best practices. By analyzing the server technology, frameworks, and analytics tools, we can assess the security posture of the website and make recommendations for improvement. This includes checking for missing security headers, frameworks, and analytics tools, as well as evaluating the server's configuration and performance metrics.

Recommendations

  • Use a trusted server technology like Nginx or Apache
  • Use a trusted framework like Ruby on Rails or Django
  • Use a trusted analytics tool like Google Analytics or Matomo
  • Use a trusted security header like Content Security Policy (CSP) and X-Frame-Options

Common issues

  • Missing Content Security Policy, this is critical for preventing XSS and injection attacks
  • Missing X-XSS-Protection, this helps prevent XSS attacks
  • Missing X-Frame-Options, this prevents clickjacking

Detected tech

Detected tech description


Other reports