is there any app for windows that checks for basic OS security settings (firewall, FDE, automatic updates, etc.) and tells you how to fix it if not? like https://paretosecurity.com/ but for windows
Secure Unmanaged Devices Without MDM

Non-invasive device monitoring for modern workforces. Stay compliant without full device control.

Pareto Security
@bcrypt not sure if something like https://learn.cisecurity.org/cis-cat-lite is useful. It checks against CIS benchmarks.
CIS-CAT Lite

CIS-CAT Lite is the free assessment tool developed by the CIS (Center for Internet Security, Inc.). CIS-CAT Lite helps users implement secure configurations for multiple technologies.