πŸ”„ Topic

The website mini-audit project grew up: it got a real name β€” WebCheckup β€” a scored repeatable rubric, professional PDF reports, and landing pages plus report templates in four languages.


🎯 Goal

Close the gap between β€œI can audit a website” and β€œI run a repeatable paid service”: consistent scoring, credible deliverables, clear offer terms, and no claims the process cannot back up.


πŸ›  What I Did

I productized the audit service end to end.

Main areas covered:

  • rebranded the service as WebCheckup and finalized offer packaging, payment confirmation, and service tiers
  • expanded the audit checklist into a scored, repeatable rubric so two audits of the same site produce comparable results
  • launched English, Polish, and Romanian versions of the landing page alongside Italian
  • translated the outreach, follow-up, and client-report templates, with a –language flag in the tooling
  • localized the PDF generator and embedded a Unicode font so diacritics render correctly in every language
  • polished the report PDF with a cover, severity colours, charts, and auto-filled screenshots
  • removed an unsupported security.txt claim from the flow β€” the check referenced an endpoint the process did not actually verify
  • deployed the remediation fixes from the latest self-audit and hardened the landing page

πŸ”— Key Cybersecurity Connections

Assessment work lives or dies on consistency and honesty. A scored rubric turns opinion into a measurement that can be repeated and compared. And removing the unsupported security.txt claim mattered more than adding any feature: a report that asserts something unverified is not a small bug, it is the exact failure that makes audits worthless.

Localization has a trust angle too β€” a security report a client cannot read in their own language does not change their behavior.


πŸ” Investigation Questions

  • Would two runs of the rubric on the same site produce the same score?
  • Does every claim in the report trace to an actual performed check?
  • Do the translated templates keep severity meanings intact?
  • Does the PDF render correctly for names and text in all four languages?
  • Are the offer terms explicit about what is and is not included?

🚨 Detection Opportunities

Quality checks for an audit service:

  • report contains a finding with no corresponding evidence artifact
  • rubric score drifts between runs with no site change
  • translated template diverges from the canonical version
  • PDF generated with missing glyphs or broken screenshots
  • landing page claims a check the rubric does not contain

Example:

project=webcheckup
signal=report_claim_without_evidence
risk_area=unverified_assertion_in_deliverable
triage=trace_claim_to_rubric_check_and_evidence_file

🧭 MITRE ATT&CK Techniques

No direct mapping claimed. This is assessment methodology and deliverable integrity work.


πŸ—Ί Visual Investigation Diagram

Ad-hoc checklist
    ↓
Scored repeatable rubric
    ↓
Evidence-backed findings
    ↓
Localized templates + PDF
    ↓
Clear offer and terms
    ↓
Service someone can actually buy

⚠ Challenges

The rubric was the hard part. Turning β€œI look at the site and notice things” into scored checks forced me to define what each finding means, how severe it is, and what evidence proves it.


πŸ“š What I Learned

I learned that productizing is mostly subtraction: removing vague claims, removing improvisation, removing steps that cannot be repeated. What is left is smaller but defensible.


➑ Next Steps

  • Run the full rubric against a fresh real site in each language
  • Keep the evidence-per-claim rule absolute
  • Watch whether the multilingual pages actually bring different traffic
  • Version the rubric so score changes are explainable

🧠 Reflection

Deleting the unsupported security.txt claim was a two-minute change and the most important one. It set the rule for the whole service: no check, no claim.


🧩 Lessons Learned

What worked

The scored rubric and per-claim evidence discipline.

What broke

A claim in the flow that no check actually verified.

Why it broke

Early drafts described the service I wanted, not the checks I had.

Fix / takeaway

Every deliverable sentence must trace back to a performed, evidenced check.


πŸ“ˆ Skill Progression Context

This supports my cybersecurity progression because repeatable methodology, evidence handling, and honest reporting are exactly what separates professional assessment work from opinions in a PDF.


πŸ˜„ TL;DR

The mini-audit became WebCheckup: scored, evidenced, four languages, and zero unverified claims.