# Prontezza IA di marriott.com

> Misurato sulla home page. Valutazione complessiva: Scarso.

Punteggio 37/100, voto Scarso. Misurato 2026-09-04T22:30:36.027+00:00, motore ax-audit@4.1.0.

## Controlli

### Contenuto — 46/100

#### Content Negotiation — 0/100

- **FAIL** Homepage does not serve Markdown via content negotiation
  Got text/html (HTTP 403) for "Accept: text/markdown"
  Serve a Markdown representation of your pages when agents request "Accept: text/markdown". Agents like Claude Code and Cursor ask for it, and Markdown cuts token usage by roughly 80% against HTML. Cloudflare ("Markdown for Agents") and Vercel can enable this without code changes.
  https://axrush.com/guides/content-negotiation#not-supported
- **WARN** No <link rel="alternate" type="text/markdown"> fallback found on the homepage
  If you cannot enable content negotiation, advertise a Markdown version with <link rel="alternate" type="text/markdown" href="/index.md"> so agents can discover it.
  https://axrush.com/guides/content-negotiation#no-alternate

#### Operabilità per agenti — 95/100

- **WARN** No lang attribute on <html>
  Agents route, translate and pick a voice from this. Add lang="en" or whichever applies.
  https://axrush.com/guides/agent-operability#no-lang
- **PASS** Method note: this reads markup, not a rendered accessibility tree
  Labels attached by script and roles computed at runtime are invisible here, so treat low proportions as a prompt to check the real tree rather than as a count. Every finding is also a plain accessibility defect.

#### Structured Data — 0/100

- **FAIL** No JSON-LD structured data found
  Add a <script type="application/ld+json"> block in your HTML <head> with schema.org structured data describing your site, organization, or person.
  https://axrush.com/guides/structured-data#not-found

#### HTML Rendering — 60/100

- **WARN** Sparse server-rendered content (16 words, 282 chars)
  Below thresholds: 80 words, 500 chars
  Render at least the main page content server-side. Many AI crawlers (GPTBot, ClaudeBot, CCBot) do not execute JavaScript and will see only the static HTML.
  https://axrush.com/guides/html-rendering#sparse-content
- **PASS** Text-to-markup ratio is healthy (77.9%)
- **WARN** No semantic HTML landmarks found
  Replace generic <div> structures with semantic tags: <main>, <article>, <header>, <nav>, <footer>. Agents use these to identify the primary content region.
  https://axrush.com/guides/html-rendering#no-landmarks
- **PASS** Single <h1> heading: "Access Denied"

#### SEO Basics — 40/100

- **WARN** <title> is too short (13 chars): "Access Denied"
  Lengthen the title to 20-70 characters with a clear topic indicator.
  https://axrush.com/guides/seo-basics#short-title
- **FAIL** <meta name="description"> is missing
  Add <meta name="description" content="..."> in <head> with a 70-160 character summary. Agents use this as the canonical short description.
  https://axrush.com/guides/seo-basics#no-description
- **WARN** No <link rel="canonical"> found
  Add <link rel="canonical" href="https://your-site.com/page"> so agents have an unambiguous URL to cite even when crawled via a redirect or query-string variant.
  https://axrush.com/guides/seo-basics#no-canonical
- **WARN** <html lang="..."> is missing
  Set the document language: <html lang="en">. Multilingual agents rely on this to pick the right summarization model and avoid mixed-language ranking.
  https://axrush.com/guides/seo-basics#no-lang
- **WARN** No UTF-8 charset declaration in HTML head
  Add <meta charset="utf-8"> as the first child of <head>. Without it, agents can mis-decode non-ASCII content.
  https://axrush.com/guides/seo-basics#no-charset
- **WARN** Missing or incomplete viewport meta tag
  Add <meta name="viewport" content="width=device-width, initial-scale=1">. Helps mobile agents render the page correctly.
  https://axrush.com/guides/seo-basics#no-viewport

### Accesso — 50/100

#### TLS / HTTPS — 87/100

- **PASS** Site is served over HTTPS
- **WARN** Could not verify HTTP→HTTPS redirect
  HTTP 403 on http://marriott.com/
  Test manually: a request to http://your-site.com should respond with 301 → https://your-site.com.
  https://axrush.com/guides/tls-https#redirect-unknown
- **WARN** HSTS max-age is short (86400s = ~1 days)
  Use at least max-age=15768000 (~6 months); preload list submission requires max-age=31536000 (1 year).
  https://axrush.com/guides/tls-https#hsts-short
- **PASS** HSTS includes subdomains
- **WARN** HSTS lacks the preload directive
  Add preload (and ensure max-age >= 31536000 + includeSubDomains) and submit the domain at https://hstspreload.org for browser-built-in HTTPS enforcement.
  https://axrush.com/guides/tls-https#hsts-no-preload

#### Agent Access — 0/100

- **FAIL** Baseline homepage request failed — cannot compare crawler access
  HTTP 403
  https://axrush.com/guides/agent-access#baseline-unavailable

#### Direttive IA — 100/100

- **PASS** Homepage is indexable
- **PASS** No directive restricts how AI assistants may use this page

#### Igiene HTTP — 85/100

- **WARN** A nonexistent path returns 403 rather than 404
  Answering unknown paths with 403 is a defensible hardening choice, but it stops a client distinguishing "missing" from "forbidden".
  https://axrush.com/guides/http-hygiene#not-found-403
- **PASS** Homepage answers without a redirect
- **WARN** No character encoding declared in the header or the document
  Without a charset, non-ASCII text is decoded by guesswork and quoted back with replacement characters. Add charset=utf-8.
  https://axrush.com/guides/http-hygiene#no-charset

#### Crawl Efficiency — 0/100

- **FAIL** Homepage request failed — cannot assess crawl efficiency
  HTTP 403
  https://axrush.com/guides/crawl-efficiency#fetch-failed

### Individuabilità — 15/100

#### LLMs.txt — 0/100

- **FAIL** /llms.txt not found
  HTTP 403
  Create a /llms.txt file at your site root following the llmstxt.org specification. It should be a Markdown file starting with "# Your Site Name" and include a description, sections, and links.
  https://axrush.com/guides/llms-txt#not-found

#### Robots.txt — 0/100

- **FAIL** /robots.txt not found
  Create a /robots.txt file at your site root. Add User-agent entries for AI crawlers (GPTBot, ClaudeBot, etc.) with Allow: / to grant access.
  https://axrush.com/guides/robots-txt#not-found

#### Meta Tags — 36/100

- **WARN** No AI meta tags (ai:*) found
  Add AI meta tags to your HTML <head>: <meta name="ai:summary" content="Brief description">, <meta name="ai:content_type" content="website">, <meta name="ai:author" content="Your Name">.
  https://axrush.com/guides/meta-tags#no-ai-meta
- **WARN** No rel="alternate" link to llms.txt in HTML
  Add to your <head>: <link rel="alternate" type="text/plain" href="/llms.txt" title="LLM-optimized content">
  https://axrush.com/guides/meta-tags#no-llms-alternate
- **WARN** No rel="alternate" link to the Agent Card in HTML
  Add to your <head>: <link rel="alternate" type="application/json" href="/.well-known/agent-card.json" title="Agent Card">
  https://axrush.com/guides/meta-tags#no-agent-alternate
- **WARN** No rel="me" identity links found
  Add rel="me" links to verify your identity across platforms: <link rel="me" href="https://github.com/yourname">, <link rel="me" href="https://twitter.com/yourname">.
  https://axrush.com/guides/meta-tags#no-rel-me
- **WARN** No OpenGraph meta tags found
  Add at minimum og:title, og:description, og:url, og:type, and og:image. Agents and link previews depend on these.
  https://axrush.com/guides/meta-tags#no-opengraph
- **WARN** No Twitter Card meta tags found
  Add twitter:card, twitter:title, twitter:description, and twitter:image so X / Threads / Bluesky / Discord agents render link previews correctly.
  https://axrush.com/guides/meta-tags#no-twitter

#### Sitemap — 0/100

- **FAIL** No sitemap found
  Tried robots.txt Sitemap: directive and /sitemap.xml
  Publish an XML sitemap at /sitemap.xml and reference it from robots.txt with: Sitemap: https://your-site.com/sitemap.xml
  https://axrush.com/guides/sitemap#not-found

#### HTTP Headers — 70/100

- **FAIL** Missing critical header: X-Content-Type-Options
  Add the X-Content-Type-Options response header to your server configuration. This is a critical security header.
  https://axrush.com/guides/http-headers#missing-critical-header
- **WARN** Only 1/7 security headers present
  Add security headers like Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy to your server response.
  https://axrush.com/guides/http-headers#low-security-headers
- **WARN** No Link header for AI discovery (llms.txt, Agent Card)
  Add a Link response header pointing to your AI discovery files: Link: </llms.txt>; rel="alternate"; type="text/plain", </.well-known/agent-card.json>; rel="alternate"; type="application/json"
  https://axrush.com/guides/http-headers#no-link-header
- **WARN** No machine-readable discovery relations beyond llms.txt and the Agent Card
  describedby — llms.txt v2 uses this relation to point a page at the llms.txt that covers it.
api-catalog — RFC 9727: the catalog of APIs this publisher offers.
service-desc — RFC 8631: a machine-readable API description.
service-doc — RFC 8631: human documentation for the API.
ai-catalog — Draft: the AI catalog listing agent cards and MCP server cards.
c2pa-manifest — C2PA 2.4: content provenance for media on the page.
license — RSL and other machine-readable licensing terms.
  Advertise what you publish with Link relations so agents stop guessing paths. Add the ones that apply, for example: Link: </llms.txt>; rel="describedby", </.well-known/api-catalog>; rel="api-catalog". Informational in 3.x: this does not affect your score.
  https://axrush.com/guides/http-headers#discovery-relations

### Protocolli — 0/100

#### Agent Card (A2A) — N/D

- **PASS** No agent-facing surface — an Agent Card does not apply to this site
  No API, MCP server or existing card was found. An Agent Card advertises capabilities another agent can invoke; a site that offers none has nothing to put in it. Run with --profile agent to audit as though it did.

#### OpenAPI Spec — N/D

- **PASS** No API surface — API discovery does not apply to this site
  No description, catalog, service-desc relation or developer area was found. Run with --profile api to audit as though the site offered one.

#### MCP (Model Context Protocol) — N/D

- **PASS** No MCP server — MCP discovery does not apply to this site
  A server card describes an MCP server so agents can find it. A site that runs none has nothing to advertise. Run with --profile mcp to audit as though it did.

#### Catalogo IA — 0/100 (informa, non assegna un punteggio)

- **WARN** No agent resource catalog found
  Checked robots.txt Agentmap: directive, Link header rel="ai-catalog", <link rel="ai-catalog">, well-known path and /.well-known/ai-catalog.json, /.well-known/ard.json. Both specifications are drafts.
  A catalog is one document listing everything an agent can call here — agent cards, MCP servers, APIs, skills — so a client stops probing four conventions to find out. Worth publishing once you have more than one of those. Informational: both ai-catalog.json and ard.json are still drafts, so this never affects your score.
  https://axrush.com/guides/ai-catalog#not-found

#### Competenze agente — N/D

- **PASS** No developer-facing surface — skills do not apply to this site
  No documentation links, llms.txt, or API description found. Skills describe procedures an agent follows; a site with no procedures to teach has nothing to publish.

#### WebMCP — N/D

- **PASS** No forms and no WebMCP code — nothing here for an agent to invoke as a tool

#### Scoperta commercio — 0/100 (informa, non assegna un punteggio)

- **FAIL** /.well-known/ucp requires authentication
  HTTP 403
  The UCP profile must be publicly accessible with no authentication. An agent reads it before it has any credentials.
  https://axrush.com/guides/commerce-discovery#profile-auth

#### Scoperta autenticazione — N/D

- **PASS** Nothing on this site requires authorization — auth discovery does not apply
  No API description, API catalog, MCP server card or commerce profile found.

### Criteri — 18/100

#### Security.txt — 0/100

- **FAIL** /.well-known/security.txt not found
  HTTP 403
  Create a /.well-known/security.txt file per RFC 9116. At minimum, include Contact: and Expires: fields. See https://securitytxt.org/ for a generator.
  https://axrush.com/guides/security-txt#not-found

#### RSL License — 0/100

- **FAIL** No RSL license discovery found
  Checked robots.txt License directive, Link header, and <link rel="license" type="application/rsl+xml">
  Declare machine-readable licensing terms for your content with Really Simple Licensing. Add to robots.txt: License: https://your-site.com/license.xml — then publish the RSL document. See https://rslstandard.org.
  https://axrush.com/guides/rsl#not-found

#### Politica d'uso — 40/100

- **WARN** No machine-readable usage policy declared
  Checked robots.txt Content-Signal and Content-Usage, the Content-Usage and content-signal response headers, an RSL licence, TDMRep, and the noai meta directive.
  State your terms where they can be read without a lawyer. The lowest-effort option is a Content-Signal line in robots.txt: Content-Signal: search=yes, ai-input=yes, ai-train=no. Absence is neutral, not permission — but it also gives you nothing to point at.
  https://axrush.com/guides/usage-policy#no-policy

---

Rappresentazione Markdown di https://axrush.com/report/marriott.com
