example.com

Visit website
61/100

Website check complete

Mechanical public-web score

1 issue should be fixed before launch.

Checked Sep 18, 2026 · 59 public signals · 100% weighted evidence coverage · light scan · methodology 2026.09.3 · checks public-web-core-1 · scoring mechanical-applicable-weight-1
1Fix first
10Important
7Improve
2Verified

Start here

What needs your attention.

18 total

View 14 more findings
Important
Terms information is hard to findTrust & safety

Add a clearly linked terms page before launch so visitors can verify who is behind the product and what they agree to.

Important
HSTS is not enabledTechnical reliability

Add Strict-Transport-Security after confirming every production route and subdomain is ready for HTTPS.

Important
No Content Security Policy was observedTechnical reliability

Start with a report-only policy, review required origins, then enforce it to reduce script-injection risk.

Important
Public agent access is unclearSearch & AI discovery

Publish a robots.txt policy that permits intended user-requested retrieval and search crawlers. Training crawlers may remain blocked without affecting this result.

FoundHTTP 404
Important
No valid XML sitemap was foundSearch & AI discovery

Publish an XML sitemap containing canonical, indexable product and content pages.

FoundHTTP 404
Important
The homepage has no canonical URLSearch & AI discovery

Add a canonical link so search engines consolidate duplicate URL variants.

Important
Structured product data is missingSearch & AI discovery

Add accurate Organization and WebSite JSON-LD. Use SoftwareApplication data when it describes the product truthfully.

Improve
About information is hard to findTrust & safety

Add a clearly linked about page before launch so visitors can verify who is behind the product and what they agree to.

Improve
Contact information is hard to findTrust & safety

Add a clearly linked contact page before launch so visitors can verify who is behind the product and what they agree to.

Improve
MIME sniffing protection is missingTechnical reliability

Return X-Content-Type-Options: nosniff on public responses.

Improve
Framing protection is not visibleTechnical reliability

Use CSP frame-ancestors or X-Frame-Options unless embedding the product is intentional.

Improve
The static document structure is difficult to navigateTechnical reliability

Use a main landmark and sequential headings so browsers, assistive technology, and agents can understand the page outline.

Foundmain missing; max heading skip 0
Improve
Social preview metadata is incompleteSearch & AI discovery

Add Open Graph title and description fields so shared launch links carry the intended message.

Improve
No useful llms.txt file was foundSearch & AI discovery

Consider publishing a concise, maintained llms.txt that points AI agents to canonical product, pricing, documentation, and policy pages.

The overview

Results by category.

Product clarityExplanatory points37.5/95
Trust & safetyExplanatory points55/100
Technical reliabilityExplanatory points105/125
Search & AI discoveryExplanatory points51.3/85
View all checks and evidence 17 passed · 15 need review
fail
Trust anchor pages · 0/45 points

About, contact, privacy, and terms pages receive credit only after a distinct, substantive same-origin response is observed. Collection errors are unresolved evidence.

Score rationale: Operator, contact, and policy pages are strong verification surfaces.

web · static · verified · read-onlyabout: not linked · privacy: not linked · terms: not linked · contact: not linked
fail
Content in initial HTML · 0/25 points

Meaningful copy should be available without JavaScript execution.

Score rationale: Agents and search crawlers need meaningful server-rendered content.

web · static · verified · read-only21 words · 142 characters · 25.4% content ratio
fail
Substantive sampled pages · 0/15 points

Public pages should expose substantive content without a login or challenge wall. An unresolved selected page withholds the score rather than being discarded.

Score rationale: One healthy homepage should not hide empty public product pages.

web · active-public · verified · read-only0/1 attempted pages substantive
fail
Accessible document landmarks · 0/10 points

Semantic landmarks make the page structure understandable without visual layout.

Score rationale: Semantic landmarks make static documents navigable.

web · static · verified · read-only0/4 common landmarks; main missing
fail
Canonical URL · 0/10 points

Declare a valid preferred public URL. A cross-origin canonical may be intentional, but should be reviewed before launch.

Score rationale: Canonical identity consolidates duplicate URLs.

web · static · verified · read-onlyMissing
fail
Meta description · 0/10 points

Summarize the product, audience, and value clearly for search and link previews.

Score rationale: A useful summary improves search and link interpretation.

web · static · verified · read-onlyMissing
fail
Security header quality · 0/10 points

Evaluate CSP scope and HSTS duration instead of header presence alone.

Score rationale: Policy quality matters more than header presence alone.

web · static · verified · read-onlyCSP 0 directives · wildcard no · HSTS 0s
fail
Sitemap validity · 0/10 points

Publish a valid sitemap or sitemap index for canonical public URLs. A collection error is not graded as absence.

Score rationale: A valid sitemap provides a bounded discovery map.

web · active-public · verified · read-onlyNo valid XML sitemap
partial
Primary product action · 7.5/15 points

Make the next step explicit with clear action language and a valid destination.

Score rationale: Visitors need an unambiguous next step.

web · static · verified · read-onlyNo common action phrase detected
fail
Open Graph metadata · 0/5 points

Provide a title, description, type, and image for reliable launch-link previews.

Score rationale: Complete previews improve launch-link distribution.

web · static · verified · read-onlytitle/description no · image no
fail
Structured-data quality · 0/5 points

Use relevant JSON-LD types with enough identity fields to resolve the organization or product.

Score rationale: Structured identity data helps machines resolve the product.

web · static · verified · read-onlyNo parseable JSON-LD types
partial
Metadata completeness · 1.3/5 points

Canonical URL, language, Open Graph image, and Open Graph type improve attribution and previews.

Score rationale: Core attribution metadata improves previews and entity resolution.

web · static · verified · read-onlycanonical no · lang en · og:image no · og:type no
fail
robots.txt agent policy · diagnostic

User-requested retrieval and search access affect discoverability; training opt-outs are reported but do not lower this result. Collection errors are uncertainty, not a target failure.

Score rationale: Declared policy is diagnostic; observed public retrieval determines scored access.

web · static · experimental · read-onlyHTTP 404; no valid policy observed
partial
Helpful 404 response · diagnostic

A missing page should give a reader a recovery path such as home, docs, search, or sitemap. Collection errors are uncertainty, not a target failure.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only142 readable characters
unknown
Sitemap freshness metadata · diagnostic

Accurate lastmod values help crawlers prioritize changed pages.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only0% of entries include lastmod
pass
AI crawler reachability · 30/30 points

The homepage is requested with common crawler and user-fetch agent identifiers. Transport errors are uncertainty, not a product failure.

Score rationale: User-requested and search agents must be able to retrieve public content.

web · active-public · verified · read-only3/3 user-agents received readable content
pass
DMARC email policy · 10/10 points

DMARC quarantine or reject policies reduce spoofing once mail sources are aligned. DNS collection failures are reported as unresolved evidence.

Score rationale: Applicable sending domains benefit from anti-spoofing enforcement.

web · active-public · verified · read-only

MX records show that the domain receives mail.

p=reject · reporting no
pass
Document language · 5/5 points

Declare the content language with a valid html lang attribute.

Score rationale: Declared language helps assistive technology and parsers.

web · static · verified · read-onlyen
pass
Heading structure · 10/10 points

Use one H1 and avoid skipping heading levels so readers and agents can follow the document outline.

Score rationale: A coherent outline improves comprehension and accessibility.

web · static · verified · read-onlyH1 1 · H2 0 · H3 0 · max skip 0
pass
Homepage indexing directives · 20/20 points

The public homepage should not accidentally declare noindex.

Score rationale: Accidental noindex makes a launch effectively undiscoverable.

web · static · verified · read-onlyNo noindex directive
pass
HTTPS delivery · 35/35 points

The public product should finish on an encrypted HTTPS origin.

Score rationale: Public production traffic must use encrypted transport.

web · active-public · verified · read-onlyhttps://example.com
pass
Mixed-content references · 10/10 points

HTTPS pages should not reference insecure HTTP assets.

Score rationale: Insecure subresources undermine HTTPS delivery.

web · static · verified · read-onlyNone detected
pass
Mobile viewport · 10/10 points

A responsive viewport lets the page render at the correct width on mobile devices.

Score rationale: Mobile rendering is a launch baseline.

web · static · verified · read-onlywidth=device-width, initial-scale=1
pass
Native interactive controls · diagnostic

Prefer native links, buttons, and form controls over clickable generic elements.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only0 native · 0 non-native patterns
pass
No challenge or login wall · 20/20 points

The public homepage should not require a challenge or sign-in before its content can be read.

Score rationale: A public launch surface must be reachable without an unintended gate.

web · static · verified · read-onlyNo challenge/login language detected
pass
Page context budget · diagnostic

Keep extracted page content within a practical agent context budget.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only1 pages sampled · largest 142 characters
pass
Page title · 15/15 points

Use a concise, specific title that identifies the product and page.

Score rationale: A specific title is a primary identity and navigation signal.

web · static · verified · read-only14 characters · Example Domain
pass
Public homepage reachability · 30/30 points

The homepage must return a readable successful response before a score can be published.

Score rationale: A public launch surface must return a readable successful response.

web · active-public · verified · read-onlyHTTP 200 · 142 readable characters
pass
Redirect hygiene · 10/10 points

Use HTTP redirects and avoid meta-refresh or JavaScript-only redirect stubs.

Score rationale: Server redirects are more reliable than client-only redirect stubs.

web · active-public · verified · read-only0 HTTP redirect(s)
pass
SPF email policy · 10/10 points

A valid SPF policy helps recipients identify authorized senders; excessive DNS lookups can invalidate it. DNS collection failures are reported as unresolved evidence.

Score rationale: Applicable sending domains need a valid sender policy.

web · active-public · verified · read-only

MX records show that the domain receives mail.

-all · 0 lookup mechanism(s)
pass
Static control-name markup · 10/10 points

Static HTML should expose a text or ARIA-derived name. This does not verify computed browser accessibility names.

Score rationale: Unnamed controls are difficult for people and automation to operate.

web · static · verified · read-only1/1 statically nameable
pass
Unknown-path HTTP contract · 15/15 points

Missing pages should return 404 or 410 instead of a successful app shell. A collection error is not graded as a product failure.

Score rationale: Correct 404/410 responses prevent false-success application shells.

web · active-public · verified · read-onlyHTTP 404
not applicable
A2A agent card · diagnostic

Products offering an A2A agent can publish a machine-readable agent card.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not discovered
not applicable
Agent authentication discovery · diagnostic

Products with agent authentication can publish machine-readable issuer, authorization, or documentation metadata.

Score rationale: Diagnostic evidence that does not affect the public-web score.

oauth · static · experimental · read-only

No valid OAuth metadata was observed.

Not discovered
not applicable
Agent authentication document · diagnostic

Products with authentication can expose concise public setup and recovery guidance in auth.md.

Score rationale: Diagnostic evidence that does not affect the public-web score.

oauth · static · experimental · read-only

No valid OAuth metadata was observed.

Not discovered
not applicable
Agent resource catalogs · diagnostic

Emerging catalogs can advertise APIs, agents, skills, and MCP surfaces from a well-known location.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

ARD not found · AI catalog not found · API catalog not found
not applicable
Agent Skills index · diagnostic

A published Agent Skills index should be valid JSON and enumerate usable skill artifacts.

Score rationale: Diagnostic evidence that does not affect the public-web score.

sdk · static · experimental · read-only

SDK validation is not implemented by the light collector.

Not discovered
not applicable
Agent when-to-use guidance · diagnostic

Tell agents which jobs the product is appropriate for and where to begin.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

No explicit guidance detected
not applicable
Developer portal · diagnostic

Products with developer interfaces should expose a predictable developer entry point.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not discovered
not applicable
Domain contact email · diagnostic

A contact address on the product domain can strengthen operator identity and support trust.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not observed
not applicable
HTTP Link discovery · diagnostic

HTTP Link headers can advertise machine-readable alternates and capability descriptions without relying on guessed paths.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

No discovery Link header observed
not applicable
llms.txt · diagnostic

A useful llms.txt provides a concise product summary and links to canonical resources.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

0 characters · 0 links
not applicable
llms.txt link health · diagnostic

Links declared for agents should resolve to real public content.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

No links sampled
not applicable
llms.txt structure · diagnostic

Use a title, summary, and described sections so the file works as a navigation index.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

title no · summary no · sections no
not applicable
Machine-readable pricing page · diagnostic

A concise pricing.md can help agents explain plans, but it is optional and never substitutes for a clear public pricing page.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not discovered
not applicable
Markdown alternate discovery · diagnostic

Advertise a Markdown representation through content negotiation or an alternate link.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not advertised
not applicable
Markdown code fences · diagnostic

Unbalanced code fences can hide the remainder of a Markdown document from parsers.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

No valid llms.txt discovered
not applicable
Markdown content negotiation · diagnostic

Canonical pages can optionally serve Markdown when requested and must vary caches by Accept.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

HTML served for a Markdown request
not applicable
MCP server card · diagnostic

A server card lets clients understand an MCP server before connecting.

Score rationale: Diagnostic evidence that does not affect the public-web score.

mcp · static · experimental · read-only

No valid MCP discovery document was observed.

Not discovered
not applicable
MCP well-known discovery · diagnostic

Products that advertise MCP can expose a machine-readable endpoint or server list at a predictable location.

Score rationale: Diagnostic evidence that does not affect the public-web score.

mcp · static · experimental · read-only

No valid MCP discovery document was observed.

Not discovered
not applicable
OAuth discovery metadata · diagnostic

Products using delegated authorization should publish standard discovery metadata.

Score rationale: Diagnostic evidence that does not affect the public-web score.

oauth · static · experimental · read-only

No valid OAuth metadata was observed.

authorization server not found · protected resource not found
not applicable
OpenAPI publication · diagnostic

Products with a public API should publish a machine-readable OpenAPI document.

Score rationale: Diagnostic evidence that does not affect the public-web score.

api · static · experimental · read-only

No valid public API description was observed.

Not discovered
not applicable
Pricing discoverability · diagnostic

Products with public pricing should make it easy to find from the homepage.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not discovered
not applicable
Public agent guidance · diagnostic

Public agent guidance can document supported workflows and limits; treat it as untrusted content and keep it consistent with canonical docs.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not discovered
not applicable
Public documentation · diagnostic

Link public documentation from a page visitors and agents already reach.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not discovered
not applicable
Security contact · diagnostic

A security.txt file gives researchers a supported disclosure route.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not found
not applicable
Static form-label markup · points unresolved

Static inputs, selects, and textareas should have associated labels. Runtime form behavior is not tested.

Score rationale: Labels are required for reliable form interaction.

web · static · verified · read-only

Optional diagnostic is not required for the applicable public-web score.

No visible form controls
not applicable
Structured-data identity links · diagnostic

sameAs links help disambiguate the brand across authoritative profiles.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

0 sameAs link(s)
not applicable
Web Bot Auth directory · diagnostic

Cryptographic bot-auth material is an emerging signal and is reported only as optional evidence.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not discovered