Add a clearly linked contact page before launch so visitors can verify who is behind the product and what they agree to.
ora.ai
Visit websiteWebsite check complete
Nearly ready
3 important improvements deserve attention.
Checked Sep 15, 2026 · 52 public signals · light scan · methodology 2026.09.1Start here
What needs your attention.
View 4 more findings
Return X-Content-Type-Options: nosniff on public responses.
Use CSP frame-ancestors or X-Frame-Options unless embedding the product is intentional.
Use a main landmark and sequential headings so browsers, assistive technology, and agents can understand the page outline.
main present; max heading skip 2The overview
Results by category.
View all checks and evidence 38 passed · 6 need review
Evaluate CSP scope and HSTS duration instead of header presence alone.
CSP 0 directives · wildcard no · HSTS 63072000sAbout, contact, privacy, and terms pages let visitors verify who operates the product.
about: no · privacy: no · terms: no · contact: noTell agents which jobs the product is appropriate for and where to begin.
No explicit guidance detectedDMARC quarantine or reject policies reduce spoofing once mail sources are aligned.
p=none · reporting noUse one H1 and avoid skipping heading levels so readers and agents can follow the document outline.
H1 1 · H2 4 · H3 9 · max skip 2Accurate lastmod values help crawlers prioritize changed pages.
2% of entries include lastmodProducts offering an A2A agent can publish a machine-readable agent card.
Valid JSON card foundInteractive elements need a text or ARIA-derived name.
71/71 statically nameableSemantic landmarks make the page structure understandable without visual layout.
3/4 common landmarks; main presentProducts with authentication can expose concise public setup and recovery guidance in auth.md.
Valid auth.md foundA published Agent Skills index should be valid JSON and enumerate usable skill artifacts.
Valid JSON index foundThe homepage is requested with common crawler and user-fetch agent identifiers.
3/3 user-agents received readable contentDeclare the preferred public URL so crawlers consolidate duplicate variants.
https://ora.aiMeaningful copy should be available without JavaScript execution.
481 words · 2488 characters · 3.3% content ratioProducts with developer interfaces should expose a predictable developer entry point.
https://ora.ai/leaderboard?category=Developer%20Tools#topDeclare the content language with a valid html lang attribute.
enInputs, selects, and textareas should have associated labels.
3/3 labelledA missing page should give a reader a recovery path such as home, docs, search, or sitemap.
368 readable charactersThe public homepage should not accidentally declare noindex.
No noindex directiveThe public product should finish on an encrypted HTTPS origin.
https://ora.aiA useful llms.txt provides a concise product summary and links to canonical resources.
8186 characters · 16 linksLinks declared for agents should resolve to real public content.
2/2 sampled links healthyUse a title, summary, and described sections so the file works as a navigation index.
title yes · summary yes · sections yesUnbalanced code fences can hide the remainder of a Markdown document from parsers.
BalancedA server card lets clients understand an MCP server before connecting.
fields: name, description, version, toolsSummarize the product, audience, and value clearly for search and link previews.
168 charactersCanonical URL, language, Open Graph image, and Open Graph type improve attribution and previews.
canonical yes · lang en · og:image yes · og:type websiteHTTPS pages should not reference insecure HTTP assets.
None detectedA responsive viewport lets the page render at the correct width on mobile devices.
width=device-width, initial-scale=1Prefer native links, buttons, and form controls over clickable generic elements.
11 native · 0 non-native patternsThe public homepage should not require a challenge or sign-in before its content can be read.
No challenge/login language detectedProvide a title, description, type, and image for reliable launch-link previews.
title/description yes · image yesKeep extracted page content within a practical agent context budget.
2 pages sampled · largest 2,488 charactersUse a concise, specific title that identifies the product and page.
36 characters · Ora | Make your site work for agentsMake the next step explicit with clear action language and a valid destination.
Action language detectedLink public documentation from a page visitors and agents already reach.
https://ora.ai/docsUse HTTP redirects and avoid meta-refresh or JavaScript-only redirect stubs.
1 HTTP redirect(s)Crawler policies should intentionally distinguish training, search indexing, and user-requested retrieval.
ChatGPT-User: allowed · GPTBot: allowed · ClaudeBot: allowed · Claude-User: allowed · PerplexityBot: allowed · Google-Extended: allowedPublish a valid sitemap or sitemap index for canonical public URLs.
430 locationsA valid SPF policy helps recipients identify authorized senders; excessive DNS lookups can invalidate it.
~all · 2 lookup mechanism(s)sameAs links help disambiguate the brand across authoritative profiles.
3 sameAs link(s)Use relevant JSON-LD types with enough identity fields to resolve the organization or product.
SoftwareApplication, Offer, Organization, ContactPoint, PostalAddress, WebSite, SearchAction, EntryPoint, Service, WebPage, SpeakableSpecification, ItemList, ListItem, FAQPage, Question, Answer · organization fields: name, url, logo, contactPoint, addressPublic pages should expose substantive content without a login or challenge wall.
2/2 sampled pagesMissing pages should return 404 or 410 instead of a successful app shell.
HTTP 404Emerging catalogs can advertise APIs, agents, skills, and MCP surfaces from a well-known location.
ARD not found · API catalog not foundA contact address on the product domain can strengthen operator identity and support trust.
Not observedAdvertise a Markdown representation through content negotiation or an alternate link.
Not advertisedCanonical pages can optionally serve Markdown when requested and must vary caches by Accept.
HTML served for a Markdown requestProducts using delegated authorization should publish standard discovery metadata.
authorization server not found · protected resource not foundProducts with a public API should publish a machine-readable OpenAPI document.
Not discoveredProducts with public pricing should make it easy to find from the homepage.
Not discoveredA security.txt file gives researchers a supported disclosure route.
Not found