AX Rush

AI readiness of graza.co

Site report: 1 measured page. Overall grade: Poor.

Site score · graza.co

Blended across the origin and 1 measured page. The report below details the origin page alone.

graza.co

Poor · 24 passing checks, 20 warnings, 13 failures · 12.3s

Share this report with your technical team

Bring the findings to the people who can fix them. Copy a ready-to-send summary for Slack, Teams or your next planning meeting.

Email

This is a public report. Your team can open it without an account.

Content

49/100

Is there substance an agent can read?

  • Homepage does not serve Markdown via content negotiation

    Serve a Markdown representation of your pages when agents request "Accept: text/markdown". Agents like Claude Code and Cursor ask for it, and Markdown cuts token usage by roughly 80% against HTML. Cloudflare ("Markdown for Agents") and Vercel can enable this without code changes.

  • No <link rel="alternate" type="text/markdown"> fallback found on the homepage

    If you cannot enable content negotiation, advertise a Markdown version with <link rel="alternate" type="text/markdown" href="/index.md"> so agents can discover it.

  • No JSON-LD structured data found

    Add a <script type="application/ld+json"> block in your HTML <head> with schema.org structured data describing your site, organization, or person.

  • Sparse server-rendered content (13 words, 88 chars)

    Render at least the main page content server-side. Many AI crawlers (GPTBot, ClaudeBot, CCBot) do not execute JavaScript and will see only the static HTML.

  • Text-to-markup ratio is healthy (17.0% of structural markup)

  • No semantic HTML landmarks found

    Replace generic <div> structures with semantic tags: <main>, <article>, <header>, <nav>, <footer>. Agents use these to identify the primary content region.

  • Single <h1> heading: "Your connection needs to be verified before you can proceed"

  • <title> length 28 chars: "Verifying your connection..."

  • <meta name="description"> is missing

    Add <meta name="description" content="..."> in <head> with a 70-160 character summary. Agents use this as the canonical short description.

  • No <link rel="canonical"> found

    Add <link rel="canonical" href="https://your-site.com/page"> so agents have an unambiguous URL to cite even when crawled via a redirect or query-string variant.

  • <html lang="en">

  • UTF-8 charset declared

  • Viewport meta present: "width=device-width, initial-scale=1.0"

  • 1 obstacle(s) on the entry page

    A CAPTCHA or a meta refresh on the landing page stops an agent before it reaches any content. If bot protection is needed, apply it to the actions that need it, not to reading a page.

  • Method note: this reads markup, not a rendered accessibility tree

Access

45/100

Can an agent retrieve it at all?

  • Baseline homepage request failed — cannot compare crawler access

  • A missing page redirects (301) instead of returning 404

    A redirect on a nonexistent path hides the error. Return 404 or 410 so a client can tell the difference.

  • Homepage answers after 1 redirect

  • Rate limited with no Retry-After header

    A 429 without Retry-After tells a well-behaved crawler nothing about when to return, so it either gives up or keeps hammering. Always send the header.

  • Content-Type: text/html with charset

  • Site is served over HTTPS

  • Could not verify HTTP→HTTPS redirect

    Test manually: a request to http://your-site.com should respond with 301 → https://your-site.com.

  • No Strict-Transport-Security header

    Add: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload. This locks browsers and many agents to HTTPS for 1 year.

  • Homepage is indexable

  • No directive restricts how AI assistants may use this page

Discovery

16/100

Can an agent find what you publish?

  • /llms.txt not found

    Create a /llms.txt file at your site root following the llmstxt.org specification. It should be a Markdown file starting with "# Your Site Name" and include a description, sections, and links.

  • /robots.txt not found

    Create a /robots.txt file at your site root. Add User-agent entries for AI crawlers (GPTBot, ClaudeBot, etc.) with Allow: / to grant access.

  • No sitemap found

    Publish an XML sitemap at /sitemap.xml and reference it from robots.txt with: Sitemap: https://your-site.com/sitemap.xml

  • No AI meta tags (ai:*) found

    Add AI meta tags to your HTML <head>: <meta name="ai:summary" content="Brief description">, <meta name="ai:content_type" content="website">, <meta name="ai:author" content="Your Name">.

  • No rel="alternate" link to llms.txt in HTML

    Add to your <head>: <link rel="alternate" type="text/plain" href="/llms.txt" title="LLM-optimized content">

  • No rel="alternate" link to the Agent Card in HTML

    Add to your <head>: <link rel="alternate" type="application/json" href="/.well-known/agent-card.json" title="Agent Card">

  • No rel="me" identity links found

    Add rel="me" links to verify your identity across platforms: <link rel="me" href="https://github.com/yourname">, <link rel="me" href="https://twitter.com/yourname">.

  • No OpenGraph meta tags found

    Add at minimum og:title, og:description, og:url, og:type, and og:image. Agents and link previews depend on these.

  • No Twitter Card meta tags found

    Add twitter:card, twitter:title, twitter:description, and twitter:image so X / Threads / Bluesky / Discord agents render link previews correctly.

  • Missing critical header: Strict-Transport-Security

    Add the Strict-Transport-Security response header to your server configuration. This is a critical security header.

  • 5/7 security headers present

  • No Link header for AI discovery (llms.txt, Agent Card)

    Add a Link response header pointing to your AI discovery files: Link: </llms.txt>; rel="alternate"; type="text/plain", </.well-known/agent-card.json>; rel="alternate"; type="application/json"

  • No machine-readable discovery relations beyond llms.txt and the Agent Card

    Advertise what you publish with Link relations so agents stop guessing paths. Add the ones that apply, for example: Link: </llms.txt>; rel="describedby", </.well-known/api-catalog>; rel="api-catalog". Informational in 3.x: this does not affect your score.

Protocols

70/100

What can an agent call?

  • No agent resource catalog found

    A catalog is one document listing everything an agent can call here — agent cards, MCP servers, APIs, skills — so a client stops probing four conventions to find out. Worth publishing once you have more than one of those. Informational: both ai-catalog.json and ard.json are still drafts, so this never affects your score.

  • Protected-resource metadata published (RFC 9728)

  • 2 authorization server(s) named

  • Authorization server https://account.graza.co publishes no discovery metadata

    The chain stops here: an agent knows which server to ask but not which endpoints it has. Publish RFC 8414 or OpenID discovery metadata.

  • UCP profile published at /.well-known/ucp

  • UCP version 2026-08-25

  • 1 commerce service(s) declared: dev.ucp.shopping

  • 2 declared schema URL(s) resolve

  • UCP profile declares no payment handlers

    Without a payment handler an agent can read your catalog but cannot complete a purchase. Declare the handlers you accept.

  • UCP profile declares no signing keys

    Publish the public keys an agent uses to verify your responses. Money is moving; identity should not rest on DNS alone.

  • No agent-facing surface — an Agent Card does not apply to this site

  • No API surface — API discovery does not apply to this site

  • No MCP server — MCP discovery does not apply to this site

  • No developer-facing surface — skills do not apply to this site

  • No forms and no WebMCP code — nothing here for an agent to invoke as a tool

Policy

18/100

What usage rights are declared?

  • /.well-known/security.txt not found

    Create a /.well-known/security.txt file per RFC 9116. At minimum, include Contact: and Expires: fields. See https://securitytxt.org/ for a generator.

  • No RSL license discovery found

    Declare machine-readable licensing terms for your content with Really Simple Licensing. Add to robots.txt: License: https://your-site.com/license.xml — then publish the RSL document. See https://rslstandard.org.

  • No machine-readable usage policy declared

    State your terms where they can be read without a lawyer. The lowest-effort option is a Content-Signal line in robots.txt: Content-Signal: search=yes, ai-input=yes, ai-train=no. Absence is neutral, not permission — but it also gives you nothing to point at.

Technical details

Engine
axrush-engine@6.0.0
Scanned
Sep 10, 2026, 7:02:35 PM UTC
Duration
12,322 ms
Checks run
26

Turn this report into ongoing improvements

Give your team full reports, prioritized fixes and monitoring, so improvements last beyond the next release.

Read this report via the API or the MCP server