Perform an authorized passive web baseline covering headers, cookies, CORS, metadata, sensitive paths, and API signals. Use it before active testing or code changes against an Internet-facing application.