Site report: 1 measured page. Overall grade: Fair.
Bring the findings to the people who can fix them. Copy a ready-to-send summary for Slack, Teams or your next planning meeting.
This is a public report. Your team can open it without an account.
Areas group the checks shown in this report. Their scores are weighted summaries, not individual pages.
Is there substance an agent can read?
Homepage does not serve Markdown via content negotiation
Serve a Markdown representation of your pages when agents request "Accept: text/markdown". Agents like Claude Code and Cursor ask for it, and Markdown cuts token usage by roughly 80% against HTML. Cloudflare ("Markdown for Agents") and Vercel can enable this without code changes.
No <link rel="alternate" type="text/markdown"> fallback found on the homepage
If you cannot enable content negotiation, advertise a Markdown version with <link rel="alternate" type="text/markdown" href="/index.md"> so agents can discover it.
No JSON-LD structured data found
Add a <script type="application/ld+json"> block in your HTML <head> with schema.org structured data describing your site, organization, or person.
<title> is too short (14 chars): "Example Domain"
Lengthen the title to 20-70 characters with a clear topic indicator.
<meta name="description"> is missing
Add <meta name="description" content="..."> in <head> with a 70-160 character summary. Agents use this as the canonical short description.
No <link rel="canonical"> found
Add <link rel="canonical" href="https://your-site.com/page"> so agents have an unambiguous URL to cite even when crawled via a redirect or query-string variant.
<html lang="en">
No UTF-8 charset declaration in HTML head
Add <meta charset="utf-8"> as the first child of <head>. Without it, agents can mis-decode non-ASCII content.
Viewport meta present: "width=device-width, initial-scale=1"
Sparse server-rendered content (21 words, 142 chars)
Render at least the main page content server-side. Many AI crawlers (GPTBot, ClaudeBot, CCBot) do not execute JavaScript and will see only the static HTML.
Text-to-markup ratio is healthy (64.8% of structural markup)
No semantic HTML landmarks found
Replace generic <div> structures with semantic tags: <main>, <article>, <header>, <nav>, <footer>. Agents use these to identify the primary content region.
Single <h1> heading: "Example Domain"
1/1 interactive elements have an accessible name
Method note: this reads markup, not a rendered accessibility tree
Can an agent retrieve it at all?
Site is served over HTTPS
HTTP request did not redirect to HTTPS
Configure your server to 301-redirect every http:// request to https://. Otherwise agents may cache the insecure variant.
No Strict-Transport-Security header
Add: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload. This locks browsers and many agents to HTTPS for 1 year.
Missing pages return 404
Homepage answers without a redirect
HEAD requests are supported
No character encoding declared in the header or the document
Without a charset, non-ASCII text is decoded by guesswork and quoted back with replacement characters. Add charset=utf-8.
All 10 core AI crawler user-agents receive the same page as a regular client
Response compressed with Brotli (br)
Cache validator present (Last-Modified)
Conditional request returns 304 Not Modified
Homepage size is reasonable (559 B decompressed)
Roughly 36 tokens of content in 140 tokens of response (74% markup)
Homepage responded in 50ms
Homepage is indexable
No directive restricts how AI assistants may use this page
Can an agent find what you publish?
/llms.txt not found
Create a /llms.txt file at your site root following the llmstxt.org specification. It should be a Markdown file starting with "# Your Site Name" and include a description, sections, and links.
/robots.txt not found
Create a /robots.txt file at your site root. Add User-agent entries for AI crawlers (GPTBot, ClaudeBot, etc.) with Allow: / to grant access.
No sitemap found
Publish an XML sitemap at /sitemap.xml and reference it from robots.txt with: Sitemap: https://your-site.com/sitemap.xml
Missing critical header: Strict-Transport-Security
Add the Strict-Transport-Security response header to your server configuration. This is a critical security header.
Missing critical header: X-Content-Type-Options
Add the X-Content-Type-Options response header to your server configuration. This is a critical security header.
Only 0/7 security headers present
Add security headers like Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy to your server response.
No Link header for AI discovery (llms.txt, Agent Card)
Add a Link response header pointing to your AI discovery files: Link: </llms.txt>; rel="alternate"; type="text/plain", </.well-known/agent-card.json>; rel="alternate"; type="application/json"
No machine-readable discovery relations beyond llms.txt and the Agent Card
Advertise what you publish with Link relations so agents stop guessing paths. Add the ones that apply, for example: Link: </llms.txt>; rel="describedby", </.well-known/api-catalog>; rel="api-catalog". Informational in 3.x: this does not affect your score.
What can an agent call?
No agent resource catalog found
A catalog is one document listing everything an agent can call here — agent cards, MCP servers, APIs, skills — so a client stops probing four conventions to find out. Worth publishing once you have more than one of those. Informational: both ai-catalog.json and ard.json are still drafts, so this never affects your score.
No agent-facing surface — an Agent Card does not apply to this site
No API surface — API discovery does not apply to this site
No MCP server — MCP discovery does not apply to this site
No developer-facing surface — skills do not apply to this site
No commerce surface — agentic-commerce discovery does not apply to this site
Nothing on this site requires authorization — auth discovery does not apply
No forms and no WebMCP code — nothing here for an agent to invoke as a tool
What usage rights are declared?
/.well-known/security.txt not found
Create a /.well-known/security.txt file per RFC 9116. At minimum, include Contact: and Expires: fields. See https://securitytxt.org/ for a generator.
No RSL license discovery found
Declare machine-readable licensing terms for your content with Really Simple Licensing. Add to robots.txt: License: https://your-site.com/license.xml — then publish the RSL document. See https://rslstandard.org.
No machine-readable usage policy declared
State your terms where they can be read without a lawyer. The lowest-effort option is a Content-Signal line in robots.txt: Content-Signal: search=yes, ai-input=yes, ai-train=no. Absence is neutral, not permission — but it also gives you nothing to point at.
Give your team full reports, prioritized fixes and monitoring, so improvements last beyond the next release.