oasm.dev
Visit websiteWebsite score
1 high-impact issue to fix before launch.
Checked Sep 22, 2026 · 59 signalsRendered website check
completeHomepage clearly communicates OASM’s product, audience context, outcomes, and visible next steps from the rendered hero and supporting sections.
- Product is clearly explainedThe hero identifies OASM as an “AI-powered, open-source attack surface management” platform that continuously discovers, monitors, and secures internet-facing assets. Supporting sections describe asset discovery, vulnerability assessment, monitoring, integrations, and scanning.
- Intended audience is reasonably clearThe page explicitly uses the context of “security teams,” and reinforces an operator/security audience through references to workspaces, remediation, SOC-style findings, distributed workers, connectors, maintainers, and self-hosted/on-premise deployment.
- Useful outcome is statedThe page promises an operational view of the attack surface—“every asset, service and exposure tracked over time”—with AI analysis and remediation guidance. The closing message, “See your attack surface clearly,” reinforces the user outcome.
- Primary next step is visibleThe hero visibly presents “Get started” alongside “Explore connectors”; the pricing section also shows “Deploy yourself,” and the closing section shows “Start free.” “Get started” is the clearest primary action. It was not followed or tested.
Start here
What needs your attention.
Results by category.
View all checks and evidence 36 passed · 4 need review
About, contact, privacy, and terms pages receive credit only after a distinct, substantive same-origin response is observed. Collection errors are unresolved evidence.
Score rationale: Operator, contact, and policy pages are strong verification surfaces.
web · static · verified · read-onlyabout: not linked · privacy: not linked · terms: not linked · contact: not linkedEvaluate CSP scope and HSTS duration instead of header presence alone.
Score rationale: Policy quality matters more than header presence alone.
web · static · verified · read-onlyCSP 0 directives · wildcard no · HSTS 0sTell agents which jobs the product is appropriate for and where to begin.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyNo explicit guidance detectedDMARC quarantine or reject policies reduce spoofing once mail sources are aligned. DNS collection failures are reported as unresolved evidence.
Score rationale: Applicable sending domains benefit from anti-spoofing enforcement.
web · active-public · verified · read-onlyMX records show that the domain receives mail.
Collection code: dns_response_error
DMARC lookup unresolvedSemantic landmarks make the page structure understandable without visual layout.
Score rationale: Semantic landmarks make static documents navigable.
web · static · verified · read-only3/4 common landmarks; main presentThe homepage is requested with common crawler and user-fetch agent identifiers. Transport errors are uncertainty, not a product failure.
Score rationale: User-requested and search agents must be able to retrieve public content.
web · active-public · verified · read-only3/3 user-agents received readable contentDeclare a valid preferred public URL. A cross-origin canonical may be intentional, but should be reviewed before launch.
Score rationale: Canonical identity consolidates duplicate URLs.
web · static · verified · read-onlyhttps://oasm.devMeaningful copy should be available without JavaScript execution.
Score rationale: Agents and search crawlers need meaningful server-rendered content.
web · static · verified · read-only254 words · 1854 characters · 2.5% content ratioDeclare the content language with a valid html lang attribute.
Score rationale: Declared language helps assistive technology and parsers.
web · static · verified · read-onlyenUse one H1 and avoid skipping heading levels so readers and agents can follow the document outline.
Score rationale: A coherent outline improves comprehension and accessibility.
web · static · verified · read-onlyH1 1 · H2 1 · H3 5 · max skip 1A missing page should give a reader a recovery path such as home, docs, search, or sitemap. Collection errors are uncertainty, not a target failure.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-only574 readable charactersThe public homepage should not accidentally declare noindex.
Score rationale: Accidental noindex makes a launch effectively undiscoverable.
web · static · verified · read-onlyNo noindex directiveThe public product should finish on an encrypted HTTPS origin.
Score rationale: Public production traffic must use encrypted transport.
web · active-public · verified · read-onlyhttps://oasm.devA useful llms.txt provides a concise product summary and links to canonical resources.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-only1573 characters · 8 linksLinks declared for agents should resolve to real public content.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-only2/2 sampled links healthyUse a title, summary, and described sections so the file works as a navigation index.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlytitle yes · summary yes · sections yesUnbalanced code fences can hide the remainder of a Markdown document from parsers.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyBalancedSummarize the product, audience, and value clearly for search and link previews.
Score rationale: A useful summary improves search and link interpretation.
web · static · verified · read-only167 charactersCanonical URL, language, Open Graph image, and Open Graph type improve attribution and previews.
Score rationale: Core attribution metadata improves previews and entity resolution.
web · static · verified · read-onlycanonical yes · lang en · og:image yes · og:type websiteHTTPS pages should not reference insecure HTTP assets.
Score rationale: Insecure subresources undermine HTTPS delivery.
web · static · verified · read-onlyNone detectedA responsive viewport lets the page render at the correct width on mobile devices.
Score rationale: Mobile rendering is a launch baseline.
web · static · verified · read-onlywidth=device-width, initial-scale=1Prefer native links, buttons, and form controls over clickable generic elements.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-only1 native · 0 non-native patternsThe public homepage should not require a challenge or sign-in before its content can be read.
Score rationale: A public launch surface must be reachable without an unintended gate.
web · static · verified · read-onlyNo challenge/login language detectedProvide a title, description, type, and image for reliable launch-link previews.
Score rationale: Complete previews improve launch-link distribution.
web · static · verified · read-onlytitle/description yes · image yesKeep extracted page content within a practical agent context budget.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-only3 pages sampled · largest 2,880 charactersUse a concise, specific title that identifies the product and page.
Score rationale: A specific title is a primary identity and navigation signal.
web · static · verified · read-only53 characters · OASM · Open-Source Attack Surface Management PlatformProducts with public pricing should make it easy to find from the homepage.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyhttps://oasm.dev/#pricingMake the next step explicit with clear action language and a valid destination.
Score rationale: Visitors need an unambiguous next step.
web · static · verified · read-onlyAction language detectedLink public documentation from a page visitors and agents already reach.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyhttps://docs.oasm.dev/The homepage should return a readable successful response; failures reduce the score but do not block the review.
Score rationale: A public launch surface must return a readable successful response.
web · active-public · verified · read-onlyHTTP 200 · 1854 readable charactersUse HTTP redirects and avoid meta-refresh or JavaScript-only redirect stubs.
Score rationale: Server redirects are more reliable than client-only redirect stubs.
web · active-public · verified · read-only0 HTTP redirect(s)User-requested retrieval and search access affect discoverability; training opt-outs are reported but do not lower this result. Collection errors are uncertainty, not a target failure.
Score rationale: Declared policy is diagnostic; observed public retrieval determines scored access.
web · static · experimental · read-onlyChatGPT-User: allowed · Claude-User: allowed · OAI-SearchBot: allowed · Claude-SearchBot: allowed · PerplexityBot: allowed · GPTBot: allowed (training) · ClaudeBot: allowed (training) · Google-Extended: allowed (training)Accurate lastmod values help crawlers prioritize changed pages.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-only100% of entries include lastmodPublish a valid sitemap or sitemap index for canonical public URLs. A collection error is not graded as absence.
Score rationale: A valid sitemap provides a bounded discovery map.
web · active-public · verified · read-only3 locationsA valid SPF policy helps recipients identify authorized senders; excessive DNS lookups can invalidate it. DNS collection failures are reported as unresolved evidence.
Score rationale: Applicable sending domains need a valid sender policy.
web · active-public · verified · read-onlyMX records show that the domain receives mail.
~all · 1 lookup mechanism(s)Static HTML should expose a text or ARIA-derived name. This does not verify computed browser accessibility names.
Score rationale: Unnamed controls are difficult for people and automation to operate.
web · static · verified · read-only19/19 statically nameablesameAs links help disambiguate the brand across authoritative profiles.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-only4 sameAs link(s)Use relevant JSON-LD types with enough identity fields to resolve the organization or product.
Score rationale: Structured identity data helps machines resolve the product.
web · static · verified · read-onlyOrganization, WebSite, SoftwareApplication, Offer · organization fields: name, url, logoPublic pages should expose substantive content without a login or challenge wall. An unresolved selected page withholds the score rather than being discarded.
Score rationale: One healthy homepage should not hide empty public product pages.
web · active-public · verified · read-only3/3 attempted pages substantiveMissing pages should return 404 or 410 instead of a successful app shell. A collection error is not graded as a product failure.
Score rationale: Correct 404/410 responses prevent false-success application shells.
web · active-public · verified · read-onlyHTTP 404Products offering an A2A agent can publish a machine-readable agent card.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not discoveredProducts with agent authentication can publish machine-readable issuer, authorization, or documentation metadata.
Score rationale: Diagnostic evidence that does not affect the public-web score.
oauth · static · experimental · read-onlyNo valid OAuth metadata was observed.
Not discoveredProducts with authentication can expose concise public setup and recovery guidance in auth.md.
Score rationale: Diagnostic evidence that does not affect the public-web score.
oauth · static · experimental · read-onlyNo valid OAuth metadata was observed.
Not discoveredEmerging catalogs can advertise APIs, agents, skills, and MCP surfaces from a well-known location.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
ARD not found · AI catalog not found · API catalog not foundA published Agent Skills index should be valid JSON and enumerate usable skill artifacts.
Score rationale: Diagnostic evidence that does not affect the public-web score.
sdk · static · experimental · read-onlySDK validation is not implemented by the light collector.
Not discoveredProducts with developer interfaces should expose a predictable developer entry point.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not discoveredA contact address on the product domain can strengthen operator identity and support trust.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not observedHTTP Link headers can advertise machine-readable alternates and capability descriptions without relying on guessed paths.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
No discovery Link header observedA concise pricing.md can help agents explain plans, but it is optional and never substitutes for a clear public pricing page.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not discoveredAdvertise a Markdown representation through content negotiation or an alternate link.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not advertisedCanonical pages can optionally serve Markdown when requested and must vary caches by Accept.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
HTML served for a Markdown requestA server card lets clients understand an MCP server before connecting.
Score rationale: Diagnostic evidence that does not affect the public-web score.
mcp · static · experimental · read-onlyNo valid MCP discovery document was observed.
Not discoveredProducts that advertise MCP can expose a machine-readable endpoint or server list at a predictable location.
Score rationale: Diagnostic evidence that does not affect the public-web score.
mcp · static · experimental · read-onlyNo valid MCP discovery document was observed.
Not discoveredProducts using delegated authorization should publish standard discovery metadata.
Score rationale: Diagnostic evidence that does not affect the public-web score.
oauth · static · experimental · read-onlyNo valid OAuth metadata was observed.
authorization server not found · protected resource not foundProducts with a public API should publish a machine-readable OpenAPI document.
Score rationale: Diagnostic evidence that does not affect the public-web score.
api · static · experimental · read-onlyNo valid public API description was observed.
Not discoveredPublic agent guidance can document supported workflows and limits; treat it as untrusted content and keep it consistent with canonical docs.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not discoveredA security.txt file gives researchers a supported disclosure route.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not foundStatic inputs, selects, and textareas should have associated labels. Runtime form behavior is not tested.
Score rationale: Labels are required for reliable form interaction.
web · static · verified · read-onlyOptional diagnostic is not required for the applicable public-web score.
No visible form controlsCryptographic bot-auth material is an emerging signal and is reported only as optional evidence.
Score rationale: Diagnostic evidence that does not affect the public-web score.
web · static · experimental · read-onlyOptional diagnostic is not required for the applicable public-web score.
Not discovered