Skip to content

CMS

Shopify audit: app JS, images, and headers Shopify will not let you set

· Configuration notes, not a newsroom.

SiteRune's Shopify fingerprint, Hydrogen vs Online Store, and why Cloudflare in front is in the playbook.

The tax is almost always apps

Shopify TTFB and INP on storefronts we fetch are usually app embeds plus unoptimized product images. The playbook: remove unused apps, defer remaining embeds, image_url with width and webp, keep JSON-LD product schema intact.

Online Store and Hydrogen fingerprint differently. We will not tell a Hydrogen storefront to install a theme app.

Headers you cannot set in the admin

CSP, HSTS, and frame-ancestors often need a proxy. SiteRune will say to put Cloudflare (or equivalent) in front for headers Shopify's admin will not expose. That is configuration, not a CDN upsell essay.

Run it on a live URL

The brief will name your CMS and attach the files. Three guest scans, no card.

https://