Add a clearly linked terms page before launch so visitors can verify who is behind the product and what they agree to.
example.com
Visit websiteWebsite check complete
Mechanical public-web score
1 issue should be fixed before launch.
Checked Sep 18, 2026 · 59 public signals · 100% weighted evidence coverage · light scan · methodology 2026.09.3 · checks public-web-core-1 · scoring mechanical-applicable-weight-1Start here
What needs your attention.
View 14 more findings
Add Strict-Transport-Security after confirming every production route and subdomain is ready for HTTPS.
Start with a report-only policy, review required origins, then enforce it to reduce script-injection risk.
Publish a robots.txt policy that permits intended user-requested retrieval and search crawlers. Training crawlers may remain blocked without affecting this result.
HTTP 404Publish an XML sitemap containing canonical, indexable product and content pages.
HTTP 404Add a canonical link so search engines consolidate duplicate URL variants.
Add accurate Organization and WebSite JSON-LD. Use SoftwareApplication data when it describes the product truthfully.
Add a clearly linked about page before launch so visitors can verify who is behind the product and what they agree to.
Add a clearly linked contact page before launch so visitors can verify who is behind the product and what they agree to.
Return X-Content-Type-Options: nosniff on public responses.
Use CSP frame-ancestors or X-Frame-Options unless embedding the product is intentional.
Use a main landmark and sequential headings so browsers, assistive technology, and agents can understand the page outline.
main missing; max heading skip 0Add Open Graph title and description fields so shared launch links carry the intended message.
Consider publishing a concise, maintained llms.txt that points AI agents to canonical product, pricing, documentation, and policy pages.
The overview
Results by category.
View all checks and evidence 17 passed · 15 need review
About, contact, privacy, and terms pages receive credit only after a distinct, substantive same-origin response is observed. Collection errors are unresolved evidence.
Score rationale: Operator, contact, and policy pages are strong verification surfaces.
web · static · verified · read-onlyabout: not linked · privacy: not linked · terms: not linked · contact: not linkedMeaningful copy should be available without JavaScript execution.
Score rationale: Agents and search crawlers need meaningful server-rendered content.
web · static · verified · read-only21 words · 142 characters · 25.4% content ratioPublic pages should expose substantive content without a login or challenge wall. An unresolved selected page withholds the score rather than being discarded.
Score rationale: One healthy homepage should not hide empty public product pages.
web · active-public · verified · read-only0/1 attempted pages substantiveSemantic landmarks make the page structure understandable without visual layout.
Score rationale: Semantic landmarks make static documents navigable.
web · static · verified · read-only0/4 common landmarks; main missingDeclare a valid preferred public URL. A cross-origin canonical may be intentional, but should be reviewed before launch.
Score rationale: Canonical identity consolidates duplicate URLs.
web · static · verified · read-onlyMissingSummarize the product, audience, and value clearly for search and link previews.
Score rationale: A useful summary improves search and link interpretation.
web · static · verified · read-onlyMissingEvaluate CSP scope and HSTS duration instead of header presence alone.
Score rationale: Policy quality matters more than header presence alone.
web · static · verified · read-onlyCSP 0 directives · wildcard no · HSTS 0sPublish a valid sitemap or sitemap index for canonical public URLs. A collection error is not graded as absence.
Score rationale: A valid sitemap provides a bounded discovery map.
web · active-public · verified · read-onlyNo valid XML sitemapMake the next step explicit with clear action language and a valid destination.
Score rationale: Visitors need an unambiguous next step.
web · static · verified · read-onlyNo common action phrase detectedProvide a title, description, type, and image for reliable launch-link previews.
Score rationale: Complete previews improve launch-link distribution.
web · static · verified · read-onlytitle/description no · image noUse relevant JSON-LD types with enough identity fields to resolve the organization or product.
Score rationale: Structured identity data helps machines resolve the product.
web · static · verified · read-onlyNo parseable JSON-LD typesCanonical URL, language, Open Graph image, and Open Graph type improve attribution and previews.
Score rationale: Core attribution metadata improves previews and entity resolution.
web · static · verified · read-onlycanonical no · lang en · og:image no · og:type noUser-requested retrieval and search access affect discoverability; training opt-outs are reported but do not lower this result. Collection errors are uncertainty, not a target failure.
Score rationale: Declared policy is diagnostic; observed public retrieval determines scored access.
web · static · experimental · read-onlyHTTP 404; no valid policy observedA missing page should give a reader a recovery path such as home, docs, search, or sitemap. Collection errors are uncertainty, not a target failure.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-only142 readable charactersAccurate lastmod values help crawlers prioritize changed pages.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-only0% of entries include lastmodThe homepage is requested with common crawler and user-fetch agent identifiers. Transport errors are uncertainty, not a product failure.
Score rationale: User-requested and search agents must be able to retrieve public content.
web · active-public · verified · read-only3/3 user-agents received readable contentDMARC quarantine or reject policies reduce spoofing once mail sources are aligned. DNS collection failures are reported as unresolved evidence.
Score rationale: Applicable sending domains benefit from anti-spoofing enforcement.
web · active-public · verified · read-onlyMX records show that the domain receives mail.
p=reject · reporting noDeclare the content language with a valid html lang attribute.
Score rationale: Declared language helps assistive technology and parsers.
web · static · verified · read-onlyenUse one H1 and avoid skipping heading levels so readers and agents can follow the document outline.
Score rationale: A coherent outline improves comprehension and accessibility.
web · static · verified · read-onlyH1 1 · H2 0 · H3 0 · max skip 0The public homepage should not accidentally declare noindex.
Score rationale: Accidental noindex makes a launch effectively undiscoverable.
web · static · verified · read-onlyNo noindex directiveThe public product should finish on an encrypted HTTPS origin.
Score rationale: Public production traffic must use encrypted transport.
web · active-public · verified · read-onlyhttps://example.comHTTPS pages should not reference insecure HTTP assets.
Score rationale: Insecure subresources undermine HTTPS delivery.
web · static · verified · read-onlyNone detectedA responsive viewport lets the page render at the correct width on mobile devices.
Score rationale: Mobile rendering is a launch baseline.
web · static · verified · read-onlywidth=device-width, initial-scale=1Prefer native links, buttons, and form controls over clickable generic elements.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-only0 native · 0 non-native patternsThe public homepage should not require a challenge or sign-in before its content can be read.
Score rationale: A public launch surface must be reachable without an unintended gate.
web · static · verified · read-onlyNo challenge/login language detectedKeep extracted page content within a practical agent context budget.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-only1 pages sampled · largest 142 charactersUse a concise, specific title that identifies the product and page.
Score rationale: A specific title is a primary identity and navigation signal.
web · static · verified · read-only14 characters · Example DomainThe homepage must return a readable successful response before a score can be published.
Score rationale: A public launch surface must return a readable successful response.
web · active-public · verified · read-onlyHTTP 200 · 142 readable charactersUse HTTP redirects and avoid meta-refresh or JavaScript-only redirect stubs.
Score rationale: Server redirects are more reliable than client-only redirect stubs.
web · active-public · verified · read-only0 HTTP redirect(s)A valid SPF policy helps recipients identify authorized senders; excessive DNS lookups can invalidate it. DNS collection failures are reported as unresolved evidence.
Score rationale: Applicable sending domains need a valid sender policy.
web · active-public · verified · read-onlyMX records show that the domain receives mail.
-all · 0 lookup mechanism(s)Static HTML should expose a text or ARIA-derived name. This does not verify computed browser accessibility names.
Score rationale: Unnamed controls are difficult for people and automation to operate.
web · static · verified · read-only1/1 statically nameableMissing pages should return 404 or 410 instead of a successful app shell. A collection error is not graded as a product failure.
Score rationale: Correct 404/410 responses prevent false-success application shells.
web · active-public · verified · read-onlyHTTP 404Products offering an A2A agent can publish a machine-readable agent card.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not discoveredProducts with agent authentication can publish machine-readable issuer, authorization, or documentation metadata.
Score rationale: Diagnostic evidence that does not affect the public-web score.
oauth · static · experimental · read-onlyNo valid OAuth metadata was observed.
Not discoveredProducts with authentication can expose concise public setup and recovery guidance in auth.md.
Score rationale: Diagnostic evidence that does not affect the public-web score.
oauth · static · experimental · read-onlyNo valid OAuth metadata was observed.
Not discoveredEmerging catalogs can advertise APIs, agents, skills, and MCP surfaces from a well-known location.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
ARD not found · AI catalog not found · API catalog not foundA published Agent Skills index should be valid JSON and enumerate usable skill artifacts.
Score rationale: Diagnostic evidence that does not affect the public-web score.
sdk · static · experimental · read-onlySDK validation is not implemented by the light collector.
Not discoveredTell agents which jobs the product is appropriate for and where to begin.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
No explicit guidance detectedProducts with developer interfaces should expose a predictable developer entry point.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not discoveredA contact address on the product domain can strengthen operator identity and support trust.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not observedHTTP Link headers can advertise machine-readable alternates and capability descriptions without relying on guessed paths.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
No discovery Link header observedA useful llms.txt provides a concise product summary and links to canonical resources.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
0 characters · 0 linksLinks declared for agents should resolve to real public content.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
No links sampledUse a title, summary, and described sections so the file works as a navigation index.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
title no · summary no · sections noA concise pricing.md can help agents explain plans, but it is optional and never substitutes for a clear public pricing page.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not discoveredAdvertise a Markdown representation through content negotiation or an alternate link.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not advertisedUnbalanced code fences can hide the remainder of a Markdown document from parsers.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
No valid llms.txt discoveredCanonical pages can optionally serve Markdown when requested and must vary caches by Accept.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
HTML served for a Markdown requestA server card lets clients understand an MCP server before connecting.
Score rationale: Diagnostic evidence that does not affect the public-web score.
mcp · static · experimental · read-onlyNo valid MCP discovery document was observed.
Not discoveredProducts that advertise MCP can expose a machine-readable endpoint or server list at a predictable location.
Score rationale: Diagnostic evidence that does not affect the public-web score.
mcp · static · experimental · read-onlyNo valid MCP discovery document was observed.
Not discoveredProducts using delegated authorization should publish standard discovery metadata.
Score rationale: Diagnostic evidence that does not affect the public-web score.
oauth · static · experimental · read-onlyNo valid OAuth metadata was observed.
authorization server not found · protected resource not foundProducts with a public API should publish a machine-readable OpenAPI document.
Score rationale: Diagnostic evidence that does not affect the public-web score.
api · static · experimental · read-onlyNo valid public API description was observed.
Not discoveredProducts with public pricing should make it easy to find from the homepage.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not discoveredPublic agent guidance can document supported workflows and limits; treat it as untrusted content and keep it consistent with canonical docs.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not discoveredLink public documentation from a page visitors and agents already reach.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not discoveredA security.txt file gives researchers a supported disclosure route.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not foundStatic inputs, selects, and textareas should have associated labels. Runtime form behavior is not tested.
Score rationale: Labels are required for reliable form interaction.
web · static · verified · read-onlyOptional diagnostic is not required for the applicable public-web score.
No visible form controlssameAs links help disambiguate the brand across authoritative profiles.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
0 sameAs link(s)Cryptographic bot-auth material is an emerging signal and is reported only as optional evidence.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not discovered