# AI readiness of paypal.com

> Measured on the home page. Overall grade: Poor.

Score 48/100, grade Poor. Measured 2026-09-04T15:10:38.769+00:00, engine ax-audit@3.6.0.

## Checks

### LLMs.txt — 90/100

- **PASS** /llms.txt exists
- **PASS** /llms.txt Content-Type OK (text/plain)
- **PASS** H1 heading: "PayPal"
- **WARN** No blockquote description found ("> ...")
  Add a blockquote description after the H1 heading, e.g.: > A brief summary of your site for AI agents.
  https://lucioduran.com/projects/ax-audit/guides/llms-txt#missing-blockquote
- **PASS** 7 section heading(s) found
- **PASS** 151 link(s) found
- **WARN** /llms-full.txt not found (optional but recommended)
  Create a /llms-full.txt with expanded content — full documentation, API details, and comprehensive site information for AI agents.
  https://lucioduran.com/projects/ax-audit/guides/llms-txt#missing-full

### Robots.txt — 60/100

- **PASS** /robots.txt exists
- **FAIL** No core AI crawlers explicitly configured
  Expected: GPTBot, ClaudeBot, ChatGPT-User, Claude-SearchBot, Google-Extended, PerplexityBot, OAI-SearchBot, CCBot
  Add User-agent entries for core AI crawlers in your robots.txt. For each crawler, add: User-agent: <name> followed by Allow: / on the next line.
  https://lucioduran.com/projects/ax-audit/guides/robots-txt#no-core-crawlers
- **PASS** Sitemap directive present
- **WARN** No Content-Signal directive found (optional)
  Declare how crawlers may use your content after access with the Content Signals Policy, e.g.: Content-Signal: search=yes, ai-train=no. Known signals: search, ai-input, ai-train. Generate yours at contentsignals.org.
  https://lucioduran.com/projects/ax-audit/guides/robots-txt#missing-content-signals
- **WARN** 0/48 known AI crawlers have explicit rules
  Add explicit User-agent entries for more AI crawlers to maximize discoverability.
  https://lucioduran.com/projects/ax-audit/guides/robots-txt#low-coverage

### Agent Card (A2A) — 0/100

- **FAIL** /.well-known/agent.json not found
  HTTP 404
  Create a /.well-known/agent.json file following the A2A (Agent-to-Agent) protocol. It should include name, description, url, and skills fields describing your site's capabilities.
  https://lucioduran.com/projects/ax-audit/guides/agent-json#not-found

### Security.txt — 75/100

- **PASS** /.well-known/security.txt exists
- **PASS** Required field "Contact" present
- **FAIL** Required field "Expires" missing (RFC 9116)
  Add "Expires:" to your security.txt. Use an ISO 8601 date, e.g., Expires: 2026-12-31T23:59:59.000Z
  https://lucioduran.com/projects/ax-audit/guides/security-txt#missing-field
- **PASS** 3/5 optional fields present

### Meta Tags — 51/100

- **WARN** No AI meta tags (ai:*) found
  Add AI meta tags to your HTML <head>: <meta name="ai:summary" content="Brief description">, <meta name="ai:content_type" content="website">, <meta name="ai:author" content="Your Name">.
  https://lucioduran.com/projects/ax-audit/guides/meta-tags#no-ai-meta
- **WARN** No rel="alternate" link to llms.txt in HTML
  Add to your <head>: <link rel="alternate" type="text/plain" href="/llms.txt" title="LLM-optimized content">
  https://lucioduran.com/projects/ax-audit/guides/meta-tags#no-llms-alternate
- **WARN** No rel="alternate" link to agent.json in HTML
  Add to your <head>: <link rel="alternate" type="application/json" href="/.well-known/agent.json" title="Agent Card">
  https://lucioduran.com/projects/ax-audit/guides/meta-tags#no-agent-alternate
- **WARN** No rel="me" identity links found
  Add rel="me" links to verify your identity across platforms: <link rel="me" href="https://github.com/yourname">, <link rel="me" href="https://twitter.com/yourname">.
  https://lucioduran.com/projects/ax-audit/guides/meta-tags#no-rel-me
- **PASS** OpenGraph required tags present (og:title, og:description, og:url, og:type)
- **WARN** OpenGraph recommended tags missing: og:site_name
  Add these for richer previews: og:site_name.
  https://lucioduran.com/projects/ax-audit/guides/meta-tags#og-recommended-missing
- **PASS** Twitter Card required tags present (twitter:card, twitter:title, twitter:description)

### OpenAPI Spec — 0/100

- **FAIL** /.well-known/openapi.json not found
  HTTP 404
  Create a /.well-known/openapi.json file with your API specification following the OpenAPI 3.x standard. See https://swagger.io/specification/ for the spec.
  https://lucioduran.com/projects/ax-audit/guides/openapi#not-found

### MCP (Model Context Protocol) — 0/100

- **FAIL** /.well-known/mcp.json not found
  HTTP 404
  Create a /.well-known/mcp.json file describing your MCP server configuration. Include name, description, tools, and version fields. See https://modelcontextprotocol.io for the spec.
  https://lucioduran.com/projects/ax-audit/guides/mcp#not-found

### Sitemap — 100/100

- **PASS** Sitemap located: https://www.paypal.com/paypal-sitemap-index.xml
- **PASS** Content-Type is XML (text/xml)
- **PASS** Sitemap-index references 1213 child sitemap(s)
- **PASS** 3/3 sample child sitemap(s) reachable
- **PASS** Sample yielded 1768 URL(s) across 3 child(ren)

### TLS / HTTPS — 100/100

- **PASS** Site is served over HTTPS
- **PASS** HTTP requests redirect to HTTPS
- **PASS** HSTS max-age=31536000
- **PASS** HSTS includes subdomains
- **PASS** HSTS preload-eligible

### AI Well-Known — 0/100

- **WARN** 0/5 emerging AI discovery files published
- **WARN** ai.txt not found
  Tried: /.well-known/ai.txt
  Publish /.well-known/ai.txt declaring opt-in/opt-out signals for AI training. See https://site.spawning.ai/spawning-ai-txt for the format.
  https://lucioduran.com/projects/ax-audit/guides/well-known-ai#ai-txt
- **WARN** genai.txt not found
  Tried: /.well-known/genai.txt
  Publish /.well-known/genai.txt declaring your generative-AI usage policy.
  https://lucioduran.com/projects/ax-audit/guides/well-known-ai#genai-txt
- **WARN** ai-plugin.json not found
  Tried: /.well-known/ai-plugin.json, /ai-plugin.json
  Publish /ai-plugin.json (legacy ChatGPT plugin manifest). Schema: name_for_model, description_for_model, api.url. Still consumed by some agents.
  https://lucioduran.com/projects/ax-audit/guides/well-known-ai#ai-plugin
- **WARN** agents.json not found
  Tried: /agents.json, /.well-known/agents.json
  Publish /agents.json describing your site as a callable agent (OpenAgents / Wildcard emerging spec). Includes name, description, and operations[].
  https://lucioduran.com/projects/ax-audit/guides/well-known-ai#agents-json
- **WARN** nlweb.json not found
  Tried: /.well-known/nlweb.json, /nlweb.json
  Publish /.well-known/nlweb.json (Microsoft NLWeb) so agents can interact with the site through a natural-language interface.
  https://lucioduran.com/projects/ax-audit/guides/well-known-ai#nlweb

### Content Negotiation — 0/100 (reports, does not score)

- **FAIL** Homepage does not serve Markdown via content negotiation
  Got text/html (HTTP 200) for "Accept: text/markdown"
  Serve a Markdown representation of your pages when agents request "Accept: text/markdown". Agents like Claude Code and Cursor ask for it, and Markdown cuts token usage by ~80% vs HTML. Cloudflare ("Markdown for Agents") and Vercel can enable this without code changes.
  https://lucioduran.com/projects/ax-audit/guides/content-negotiation#not-supported
- **WARN** No <link rel="alternate" type="text/markdown"> fallback found on the homepage
  If you cannot enable content negotiation, advertise a Markdown version with <link rel="alternate" type="text/markdown" href="/index.md"> so agents can discover it.
  https://lucioduran.com/projects/ax-audit/guides/content-negotiation#no-alternate

### RSL License — 0/100 (reports, does not score)

- **FAIL** No RSL license discovery found
  Checked robots.txt License directive, Link header, and <link rel="license" type="application/rsl+xml">
  Declare machine-readable licensing terms for your content with Really Simple Licensing. Add to robots.txt: License: https://your-site.com/license.xml — then publish the RSL document. See https://rslstandard.org.
  https://lucioduran.com/projects/ax-audit/guides/rsl#not-found

### Agent Access — 81/100 (reports, does not score)

- **WARN** PerplexityBot receives reduced content (1725 vs 10505 chars of visible text)
  The server returns 200 but serves this crawler substantially less content than a regular client — often an interstitial, a challenge page, or conditional rendering. Agents index what they receive.
  https://lucioduran.com/projects/ax-audit/guides/agent-access#reduced-content
- **WARN** OAI-SearchBot receives reduced content (1723 vs 10505 chars of visible text)
  The server returns 200 but serves this crawler substantially less content than a regular client — often an interstitial, a challenge page, or conditional rendering. Agents index what they receive.
  https://lucioduran.com/projects/ax-audit/guides/agent-access#reduced-content
- **WARN** CCBot receives reduced content (1721 vs 10505 chars of visible text)
  The server returns 200 but serves this crawler substantially less content than a regular client — often an interstitial, a challenge page, or conditional rendering. Agents index what they receive.
  https://lucioduran.com/projects/ax-audit/guides/agent-access#reduced-content

### Structured Data — 0/100

- **FAIL** No JSON-LD structured data found
  Add a <script type="application/ld+json"> block in your HTML <head> with schema.org structured data describing your site, organization, or person.
  https://lucioduran.com/projects/ax-audit/guides/structured-data#not-found

### HTTP Headers — 85/100

- **PASS** 5/7 security headers present
- **WARN** No Link header for AI discovery (llms.txt, agent.json)
  Add a Link response header pointing to your AI discovery files: Link: </llms.txt>; rel="alternate"; type="text/plain", </.well-known/agent.json>; rel="alternate"; type="application/json"
  https://lucioduran.com/projects/ax-audit/guides/http-headers#no-link-header

### HTML Rendering — 60/100

- **WARN** Sparse server-rendered content (29 words, 1778 chars)
  Below thresholds: 80 words, 500 chars
  Render at least the main page content server-side. Many AI crawlers (GPTBot, ClaudeBot, CCBot) do not execute JavaScript and will see only the static HTML.
  https://lucioduran.com/projects/ax-audit/guides/html-rendering#sparse-content
- **PASS** Text-to-markup ratio is healthy (37.2%)
- **WARN** Only 1 semantic landmark(s) found
  Found: header. Missing: main, article, section, footer, nav
  Use semantic HTML tags so AI agents can understand page structure: <header>, <nav>, <main>, <article>, <section>, <footer>.
  https://lucioduran.com/projects/ax-audit/guides/html-rendering#few-landmarks
- **WARN** 2 <h1> headings found (recommend exactly 1)
  Use a single <h1> per page to clearly mark the primary topic. Demote secondary headings to <h2>+.
  https://lucioduran.com/projects/ax-audit/guides/html-rendering#multiple-h1

### SEO Basics — 25/100

- **FAIL** <title> is missing or empty
  Add a <title> in <head> describing the page in 20-70 characters. Agents quote it as the document name.
  https://lucioduran.com/projects/ax-audit/guides/seo-basics#no-title
- **FAIL** <meta name="description"> is missing
  Add <meta name="description" content="..."> in <head> with a 70-160 character summary. Agents use this as the canonical short description.
  https://lucioduran.com/projects/ax-audit/guides/seo-basics#no-description
- **WARN** No <link rel="canonical"> found
  Add <link rel="canonical" href="https://your-site.com/page"> so agents have an unambiguous URL to cite even when crawled via a redirect or query-string variant.
  https://lucioduran.com/projects/ax-audit/guides/seo-basics#no-canonical
- **WARN** <html lang="..."> is missing
  Set the document language: <html lang="en">. Multilingual agents rely on this to pick the right summarization model and avoid mixed-language ranking.
  https://lucioduran.com/projects/ax-audit/guides/seo-basics#no-lang
- **WARN** No UTF-8 charset declaration in HTML head
  Add <meta charset="utf-8"> as the first child of <head>. Without it, agents can mis-decode non-ASCII content.
  https://lucioduran.com/projects/ax-audit/guides/seo-basics#no-charset
- **WARN** Missing or incomplete viewport meta tag
  Add <meta name="viewport" content="width=device-width, initial-scale=1">. Helps mobile agents render the page correctly.
  https://lucioduran.com/projects/ax-audit/guides/seo-basics#no-viewport

### Crawl Efficiency — 85/100 (reports, does not score)

- **PASS** Response compressed with Brotli (br)
- **PASS** Cache validator present (ETag)
- **WARN** Conditional request returned 200 instead of 304 Not Modified
  Re-requested with If-None-Match
  The server advertises a cache validator but does not honor If-None-Match / If-Modified-Since. Configure it to return 304 when the validator matches, so crawlers avoid re-downloading unchanged pages.
  https://lucioduran.com/projects/ax-audit/guides/crawl-efficiency#no-304
- **PASS** Homepage size is reasonable (4.7 KB decompressed)

---

Markdown representation of https://axrush.com/report/paypal.com
