A 20-minute website security audit: CSP, HSTS, SPF/DMARC, and CAA explained for developers
Most of a site's basic security posture is visible from outside: HTTP response headers and a few DNS records. You don't need access to the codebase to check them, and you don't need a scanner to read
siteory.hashnode.dev7 min read