AuditHQ
← All guides
Guide · Websites · 9 min read · Updated 2026-09-18

Website Security Scan Checklist: Keys, Headers, and Source Maps

A surface scan of what any visitor can already see in F12 — plus ops signals like health URLs and error tracking — then a ranked list of what to rotate, restrict, or add.

Scan your own site, not a rival

AuditHQ’s deep security scan runs on the website you own. It is off for homepage quick scores, compare, and competitor URLs.

Create a website project, run an audit, and open the Security panel. Free plans see counts and one header example. Pro and Company unlock the full redacted report — including a Production readiness checklist that groups findings the way a real ops review would.

Keys and tokens in the browser

The scan reads page HTML, up to eight same-origin JavaScript bundles, and request URLs already observed on that load.

It looks for Stripe live secrets, AWS access key ids, OpenAI and Anthropic keys, GitHub tokens, Slack and Twilio credentials, database connection strings, JWTs, and service_role or service-account markers.

A match is stored as type plus last four characters only. Rotate the credential at the provider first, then remove it from the client bundle, then proxy the call through a server route.

Headers, cookies, and transport

Check the document response for Content-Security-Policy, X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy, HSTS, and clickjacking protection (X-Frame-Options or CSP frame-ancestors).

If CSP is present, AuditHQ also notes whether violation reporting (report-uri / report-to) is wired — otherwise you never see when the policy blocks real traffic.

Session cookies should carry HttpOnly, Secure, and SameSite. Missing flags are listed with the cookie name, not the cookie value.

Debug leftovers and abuse posture

Published sourceMappingURL comments in production bundles hand over original source. A reachable /.git/HEAD usually means repository history is downloadable — rotate every credential that was ever committed.

If the page already called a same-origin /api/ or .json URL, AuditHQ re-reads that URL once. It records CORS wildcards and whether RateLimit-*, X-RateLimit-*, or Retry-After appeared. It does not flood the endpoint.

Production readiness: health, errors, and crawlers

Beyond F12 secrets, Pro deep scans probe a short list of public ops signals: a /api/health (or /health) style endpoint, client error-reporting SDKs such as Sentry, RFC 9116 security.txt, robots.txt, and a sitemap.

These show up as findings and as Pass / Improve / Fail rows on the Production readiness card inside Security. Some checks are advisory where false positives are common — they guide hardening, they do not invent a pentest.

What stays out of scope from outside-in scans: database replicas, billing budget alerts, load-balancer min/max, and whether your React tree has error boundaries.

Verify after you ship

Fix the listed artifacts, then re-run the project audit. The Security score, Production readiness themes, and finding list should move. Copy the AI fix prompt on the project page when you want a file-level remediation plan from the same redacted evidence.

Run this on your site

AuditHQ schedules website measurements, a deep security scan and Production readiness checklist on your own URL, waterfalls, screenshots, competitor scores, and ranked fixes.

website security scanexposed API keys JavaScriptsecurity headers checklistCSP HSTS nosniffproduction source mapsHttpOnly Secure cookiesrate limit headers 429website health check endpointsecurity.txtproduction readiness checklistAuditHQ security scan