What an outsider can see about your site
Certificates, security headers and what a site says about itself for no reason. We demand only what matters to an ordinary website.
Which security headers do you need and what do they do?
An ordinary site needs six: HSTS, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, X-Frame-Options and Permissions-Policy. Five of them are a single line in the server config, while CSP needs tuning — which is exactly why it gives the most.
What do you check to judge a website's security?
Four things are checkable from outside: whether the TLS certificate is valid and HTTP redirects to HTTPS, whether security headers are sent, whether the page has mixed content, and whether admin or configuration paths are publicly reachable. The fourth layer — patching — is only visible from inside.
Other areas
SEO
Indexing, titles, structure, links and what all of it costs. Each article answers one question and rests on a primary source.
GEO and AI
GEO, AEO and AI SEO are one body of work measured by three questions. Here is what each means and what to actually change on the page.
Speed
Core Web Vitals, the PageSpeed score and what they actually measure. A number without an address changes nothing, so we talk about specific files.