Web Server Security Audit Checklist: Nginx & Apache
Nginx and Apache - what they expose and how they are configured.
Your web server is the one process the entire internet is invited to talk to. Everything it exposes, it exposes to everyone: a stray directory listing, a forgotten .git folder, a version banner that tells a scanner which exploit to try.
- Read-only, safe on production
- No agent installed
- ~68s for the category
- 10 distros auto-detected
How much of this is serious?
Severity of all 36 Web Server checks, as the scripts rate them.
- 8High severity22%
- 18Medium severity50%
- 10Low severity28%
What these audits cover
- HSTS, CSP, framing, MIME sniffing, referrer and permissions policy headers
- Protocol versions, cipher suites, certificate validity and HTTPS redirection
- Directory listing, hidden files, stray backups, permitted methods and status endpoints
- Version disclosure, worker privileges, request limits and log configuration
What they do not cover
- Application vulnerabilities. These audits read server configuration, not the code behind it.
- A live web application scan. Nothing here crawls your routes or submits forms.
- CDN and WAF configuration. If Cloudflare terminates TLS, the headers a visitor sees may not be the ones this reads.
The 6 Web Server audits
Security headers are the cheapest wins here and the most commonly missing: a handful of lines in a config file.
Security Headers
SoonHSTS, CSP, framing, MIME sniffing, referrer and permissions policy
Configuration Hardening
SoonFile permissions, web root ownership, request limits and modules
Content Exposure
SoonDirectory listing, hidden files, backups, methods and status endpoints
TLS Configuration
SoonProtocol versions, cipher suites, certificates and HTTPS redirection
Identification & Patching
SoonServer inventory, version disclosure, worker privileges and pending updates
Logging & Monitoring
SoonAccess and error logging, log permissions, rotation and WAF presence
Other categories
Web Server security questions
Run all 36 Web Server checks, in one click
CtrlOps runs these audits over your existing SSH connection - no agents, no scripts to manage. $7/user/month after a 1 month free trial - no credit card required.
✓ Start instantly·✓ No credit card·✓ No sneaky autorenewals