CRO9 Stack Health Audit · Free

Grade your stack in under 10 minutes

We check the same 50+ external signals a security auditor would — infrastructure sprawl, TLS validity, missing security headers, framework EOL, leaked dev artifacts, stale assets. You get a letter grade, detailed findings, and a prioritized fix list by email.

1
2
3
Website
What to check
Where to send it

What are we auditing?

Enter the website you want graded. Apex domain or any subdomain — we'll map the rest.

Infrastructure map
Subdomain sweep + CT logs + DNS. Where everything actually lives.
TLS + header audit
Cert validity, cipher posture, HSTS/CSP/X-Frame + cookie flags.
Stack fingerprint
Framework, runtime, frontend, CDN — and whether any is EOL.
Attack surface
50+ sensitive paths — .env, .git, phpinfo, debug tools, backups.
Asset freshness
Last-modified headers reveal the real maintenance pulse.
Remediation plan
Every finding ranked. Every fix given an effort estimate.