63/100

Website score

1 high-impact issue to fix before launch.

Checked Sep 22, 2026 · 59 signals
25 points checked in deep review

Rendered website check

complete

Homepage clearly communicates OASM’s product, audience context, outcomes, and visible next steps from the rendered hero and supporting sections.

  • Product is clearly explainedThe hero identifies OASM as an “AI-powered, open-source attack surface management” platform that continuously discovers, monitors, and secures internet-facing assets. Supporting sections describe asset discovery, vulnerability assessment, monitoring, integrations, and scanning.
  • Intended audience is reasonably clearThe page explicitly uses the context of “security teams,” and reinforces an operator/security audience through references to workspaces, remediation, SOC-style findings, distributed workers, connectors, maintainers, and self-hosted/on-premise deployment.
  • Useful outcome is statedThe page promises an operational view of the attack surface—“every asset, service and exposure tracked over time”—with AI analysis and remediation guidance. The closing message, “See your attack surface clearly,” reinforces the user outcome.
  • Primary next step is visibleThe hero visibly presents “Get started” alongside “Explore connectors”; the pricing section also shows “Deploy yourself,” and the closing section shows “Start free.” “Get started” is the clearest primary action. It was not followed or tested.

Start here

What needs your attention.

2 total

Results by category.

Product clarityPoints95/95
Trust & safetyPoints45/100
Technical reliabilityPoints115/125
Search & AI discoveryPoints85/85
View all checks and evidence 36 passed · 4 need review
fail
Trust anchor pages · 0/45 points

About, contact, privacy, and terms pages receive credit only after a distinct, substantive same-origin response is observed. Collection errors are unresolved evidence.

Score rationale: Operator, contact, and policy pages are strong verification surfaces.

web · static · verified · read-onlyabout: not linked · privacy: not linked · terms: not linked · contact: not linked
fail
Security header quality · 0/10 points

Evaluate CSP scope and HSTS duration instead of header presence alone.

Score rationale: Policy quality matters more than header presence alone.

web · static · verified · read-onlyCSP 0 directives · wildcard no · HSTS 0s
partial
Agent when-to-use guidance · diagnostic

Tell agents which jobs the product is appropriate for and where to begin.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-onlyNo explicit guidance detected
error
DMARC email policy · points unresolved

DMARC quarantine or reject policies reduce spoofing once mail sources are aligned. DNS collection failures are reported as unresolved evidence.

Score rationale: Applicable sending domains benefit from anti-spoofing enforcement.

web · active-public · verified · read-only

MX records show that the domain receives mail.

Collection code: dns_response_error

DMARC lookup unresolved
pass
Accessible document landmarks · 10/10 points

Semantic landmarks make the page structure understandable without visual layout.

Score rationale: Semantic landmarks make static documents navigable.

web · static · verified · read-only3/4 common landmarks; main present
pass
AI crawler reachability · 30/30 points

The homepage is requested with common crawler and user-fetch agent identifiers. Transport errors are uncertainty, not a product failure.

Score rationale: User-requested and search agents must be able to retrieve public content.

web · active-public · verified · read-only3/3 user-agents received readable content
pass
Canonical URL · 10/10 points

Declare a valid preferred public URL. A cross-origin canonical may be intentional, but should be reviewed before launch.

Score rationale: Canonical identity consolidates duplicate URLs.

web · static · verified · read-onlyhttps://oasm.dev
pass
Content in initial HTML · 25/25 points

Meaningful copy should be available without JavaScript execution.

Score rationale: Agents and search crawlers need meaningful server-rendered content.

web · static · verified · read-only254 words · 1854 characters · 2.5% content ratio
pass
Document language · 5/5 points

Declare the content language with a valid html lang attribute.

Score rationale: Declared language helps assistive technology and parsers.

web · static · verified · read-onlyen
pass
Heading structure · 10/10 points

Use one H1 and avoid skipping heading levels so readers and agents can follow the document outline.

Score rationale: A coherent outline improves comprehension and accessibility.

web · static · verified · read-onlyH1 1 · H2 1 · H3 5 · max skip 1
pass
Helpful 404 response · diagnostic

A missing page should give a reader a recovery path such as home, docs, search, or sitemap. Collection errors are uncertainty, not a target failure.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only574 readable characters
pass
Homepage indexing directives · 20/20 points

The public homepage should not accidentally declare noindex.

Score rationale: Accidental noindex makes a launch effectively undiscoverable.

web · static · verified · read-onlyNo noindex directive
pass
HTTPS delivery · 35/35 points

The public product should finish on an encrypted HTTPS origin.

Score rationale: Public production traffic must use encrypted transport.

web · active-public · verified · read-onlyhttps://oasm.dev
pass
llms.txt · diagnostic

A useful llms.txt provides a concise product summary and links to canonical resources.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only1573 characters · 8 links
pass
llms.txt link health · diagnostic

Links declared for agents should resolve to real public content.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only2/2 sampled links healthy
pass
llms.txt structure · diagnostic

Use a title, summary, and described sections so the file works as a navigation index.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-onlytitle yes · summary yes · sections yes
pass
Markdown code fences · diagnostic

Unbalanced code fences can hide the remainder of a Markdown document from parsers.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-onlyBalanced
pass
Meta description · 10/10 points

Summarize the product, audience, and value clearly for search and link previews.

Score rationale: A useful summary improves search and link interpretation.

web · static · verified · read-only167 characters
pass
Metadata completeness · 5/5 points

Canonical URL, language, Open Graph image, and Open Graph type improve attribution and previews.

Score rationale: Core attribution metadata improves previews and entity resolution.

web · static · verified · read-onlycanonical yes · lang en · og:image yes · og:type website
pass
Mixed-content references · 10/10 points

HTTPS pages should not reference insecure HTTP assets.

Score rationale: Insecure subresources undermine HTTPS delivery.

web · static · verified · read-onlyNone detected
pass
Mobile viewport · 10/10 points

A responsive viewport lets the page render at the correct width on mobile devices.

Score rationale: Mobile rendering is a launch baseline.

web · static · verified · read-onlywidth=device-width, initial-scale=1
pass
Native interactive controls · diagnostic

Prefer native links, buttons, and form controls over clickable generic elements.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only1 native · 0 non-native patterns
pass
No challenge or login wall · 20/20 points

The public homepage should not require a challenge or sign-in before its content can be read.

Score rationale: A public launch surface must be reachable without an unintended gate.

web · static · verified · read-onlyNo challenge/login language detected
pass
Open Graph metadata · 5/5 points

Provide a title, description, type, and image for reliable launch-link previews.

Score rationale: Complete previews improve launch-link distribution.

web · static · verified · read-onlytitle/description yes · image yes
pass
Page context budget · diagnostic

Keep extracted page content within a practical agent context budget.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only3 pages sampled · largest 2,880 characters
pass
Page title · 15/15 points

Use a concise, specific title that identifies the product and page.

Score rationale: A specific title is a primary identity and navigation signal.

web · static · verified · read-only53 characters · OASM · Open-Source Attack Surface Management Platform
pass
Pricing discoverability · diagnostic

Products with public pricing should make it easy to find from the homepage.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-onlyhttps://oasm.dev/#pricing
pass
Primary product action · 15/15 points

Make the next step explicit with clear action language and a valid destination.

Score rationale: Visitors need an unambiguous next step.

web · static · verified · read-onlyAction language detected
pass
Public documentation · diagnostic

Link public documentation from a page visitors and agents already reach.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-onlyhttps://docs.oasm.dev/
pass
Public homepage reachability · 30/30 points

The homepage should return a readable successful response; failures reduce the score but do not block the review.

Score rationale: A public launch surface must return a readable successful response.

web · active-public · verified · read-onlyHTTP 200 · 1854 readable characters
pass
Redirect hygiene · 10/10 points

Use HTTP redirects and avoid meta-refresh or JavaScript-only redirect stubs.

Score rationale: Server redirects are more reliable than client-only redirect stubs.

web · active-public · verified · read-only0 HTTP redirect(s)
pass
robots.txt agent policy · diagnostic

User-requested retrieval and search access affect discoverability; training opt-outs are reported but do not lower this result. Collection errors are uncertainty, not a target failure.

Score rationale: Declared policy is diagnostic; observed public retrieval determines scored access.

web · static · experimental · read-onlyChatGPT-User: allowed · Claude-User: allowed · OAI-SearchBot: allowed · Claude-SearchBot: allowed · PerplexityBot: allowed · GPTBot: allowed (training) · ClaudeBot: allowed (training) · Google-Extended: allowed (training)
pass
Sitemap freshness metadata · diagnostic

Accurate lastmod values help crawlers prioritize changed pages.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only100% of entries include lastmod
pass
Sitemap validity · 10/10 points

Publish a valid sitemap or sitemap index for canonical public URLs. A collection error is not graded as absence.

Score rationale: A valid sitemap provides a bounded discovery map.

web · active-public · verified · read-only3 locations
pass
SPF email policy · 10/10 points

A valid SPF policy helps recipients identify authorized senders; excessive DNS lookups can invalidate it. DNS collection failures are reported as unresolved evidence.

Score rationale: Applicable sending domains need a valid sender policy.

web · active-public · verified · read-only

MX records show that the domain receives mail.

~all · 1 lookup mechanism(s)
pass
Static control-name markup · 10/10 points

Static HTML should expose a text or ARIA-derived name. This does not verify computed browser accessibility names.

Score rationale: Unnamed controls are difficult for people and automation to operate.

web · static · verified · read-only19/19 statically nameable
pass
Structured-data identity links · diagnostic

sameAs links help disambiguate the brand across authoritative profiles.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only4 sameAs link(s)
pass
Structured-data quality · 5/5 points

Use relevant JSON-LD types with enough identity fields to resolve the organization or product.

Score rationale: Structured identity data helps machines resolve the product.

web · static · verified · read-onlyOrganization, WebSite, SoftwareApplication, Offer · organization fields: name, url, logo
pass
Substantive sampled pages · 15/15 points

Public pages should expose substantive content without a login or challenge wall. An unresolved selected page withholds the score rather than being discarded.

Score rationale: One healthy homepage should not hide empty public product pages.

web · active-public · verified · read-only3/3 attempted pages substantive
pass
Unknown-path HTTP contract · 15/15 points

Missing pages should return 404 or 410 instead of a successful app shell. A collection error is not graded as a product failure.

Score rationale: Correct 404/410 responses prevent false-success application shells.

web · active-public · verified · read-onlyHTTP 404
not applicable
A2A agent card · diagnostic

Products offering an A2A agent can publish a machine-readable agent card.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not discovered
not applicable
Agent authentication discovery · diagnostic

Products with agent authentication can publish machine-readable issuer, authorization, or documentation metadata.

Score rationale: Diagnostic evidence that does not affect the public-web score.

oauth · static · experimental · read-only

No valid OAuth metadata was observed.

Not discovered
not applicable
Agent authentication document · diagnostic

Products with authentication can expose concise public setup and recovery guidance in auth.md.

Score rationale: Diagnostic evidence that does not affect the public-web score.

oauth · static · experimental · read-only

No valid OAuth metadata was observed.

Not discovered
not applicable
Agent resource catalogs · diagnostic

Emerging catalogs can advertise APIs, agents, skills, and MCP surfaces from a well-known location.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

ARD not found · AI catalog not found · API catalog not found
not applicable
Agent Skills index · diagnostic

A published Agent Skills index should be valid JSON and enumerate usable skill artifacts.

Score rationale: Diagnostic evidence that does not affect the public-web score.

sdk · static · experimental · read-only

SDK validation is not implemented by the light collector.

Not discovered
not applicable
Developer portal · diagnostic

Products with developer interfaces should expose a predictable developer entry point.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not discovered
not applicable
Domain contact email · diagnostic

A contact address on the product domain can strengthen operator identity and support trust.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not observed
not applicable
HTTP Link discovery · diagnostic

HTTP Link headers can advertise machine-readable alternates and capability descriptions without relying on guessed paths.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

No discovery Link header observed
not applicable
Machine-readable pricing page · diagnostic

A concise pricing.md can help agents explain plans, but it is optional and never substitutes for a clear public pricing page.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not discovered
not applicable
Markdown alternate discovery · diagnostic

Advertise a Markdown representation through content negotiation or an alternate link.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not advertised
not applicable
Markdown content negotiation · diagnostic

Canonical pages can optionally serve Markdown when requested and must vary caches by Accept.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

HTML served for a Markdown request
not applicable
MCP server card · diagnostic

A server card lets clients understand an MCP server before connecting.

Score rationale: Diagnostic evidence that does not affect the public-web score.

mcp · static · experimental · read-only

No valid MCP discovery document was observed.

Not discovered
not applicable
MCP well-known discovery · diagnostic

Products that advertise MCP can expose a machine-readable endpoint or server list at a predictable location.

Score rationale: Diagnostic evidence that does not affect the public-web score.

mcp · static · experimental · read-only

No valid MCP discovery document was observed.

Not discovered
not applicable
OAuth discovery metadata · diagnostic

Products using delegated authorization should publish standard discovery metadata.

Score rationale: Diagnostic evidence that does not affect the public-web score.

oauth · static · experimental · read-only

No valid OAuth metadata was observed.

authorization server not found · protected resource not found
not applicable
OpenAPI publication · diagnostic

Products with a public API should publish a machine-readable OpenAPI document.

Score rationale: Diagnostic evidence that does not affect the public-web score.

api · static · experimental · read-only

No valid public API description was observed.

Not discovered
not applicable
Public agent guidance · diagnostic

Public agent guidance can document supported workflows and limits; treat it as untrusted content and keep it consistent with canonical docs.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not discovered
not applicable
Security contact · diagnostic

A security.txt file gives researchers a supported disclosure route.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not found
not applicable
Static form-label markup · points unresolved

Static inputs, selects, and textareas should have associated labels. Runtime form behavior is not tested.

Score rationale: Labels are required for reliable form interaction.

web · static · verified · read-only

Optional diagnostic is not required for the applicable public-web score.

No visible form controls
not applicable
Web Bot Auth directory · diagnostic

Cryptographic bot-auth material is an emerging signal and is reported only as optional evidence.

Score rationale: Diagnostic evidence that does not affect the public-web score.

web · static · experimental · read-only

Optional diagnostic is not required for the applicable public-web score.

Not discovered