Menu

Agent readiness report

webseccorp.com

What an AI agent can and cannot do on this site, measured by an unauthenticated crawl and scored against the published rubric.

Scanned · rubric v1.0.1 · scored as a e-commerce site · re-scan (results are cached for seven days)

What to fix first

Ranked by impact first, then by how cheap the fix is — the same ordering the engine uses.

  1. 1C4

    Machine endpoints and agent manifests

    High impact · High effort

    No machine-readable endpoint of any kind. Most sites score zero here, which is exactly why it is the cheapest differentiation on this rubric: an agents.json is a static file, and a documented read-only API is usually a subset of something you already run.

  2. 2A4

    llms.txt present

    Medium impact · Low effort

    Publish an llms.txt at the root: an H1, a one-line summary, then described links to your most useful pages. It is a text file and it takes an hour — the cheapest points on this rubric.

  3. 3B4

    Meta and Open Graph

    Medium impact · Low effort

    Fix: 1 title(s) outside 15–70 characters; 5 description(s) outside 50–160 characters.

  4. 4D1

    Transport security

    Medium impact · Low effort

    Fix: no Strict-Transport-Security header; 1 insecure subresource reference(s).

  5. 5D2

    Verifiable identity

    Medium impact · Low effort

    Fix: Organization schema has no sameAs links. sameAs links to a company profile are how a model corroborates that you are who the page says you are.

Every check, with the evidence

No finding without evidence: each result shows what we actually captured during the crawl.

ADiscovery & access

  • A1Pass

    robots.txt exists and parses

    2/2
    What we captured
    {
      "groups": 1,
      "status": 200,
      "sitemaps": 0
    }
  • A2Pass

    Major AI crawlers allowed

    6/6
    What we captured
    {
      "of": 6,
      "allowed": 6,
      "blocked": []
    }
  • A3Partial

    XML sitemap valid and referenced

    2/3

    Fix: not referenced from robots.txt. A sitemap referenced from robots.txt is how a crawler discovers pages that are not linked from the homepage.

    What we captured
    {
      "exists": true,
      "urlCount": 32,
      "referencedInRobots": false
    }
  • A4Fail

    llms.txt present

    0/4

    Publish an llms.txt at the root: an H1, a one-line summary, then described links to your most useful pages. It is a text file and it takes an hour — the cheapest points on this rubric.

    What we captured
    {
      "status": 404,
      "present": false
    }
  • A5Pass

    Bot user-agent HTTP health

    3/3
    What we captured
    {
      "probes": [
        {
          "name": "GPTBot",
          "status": 200,
          "ttfbMs": 389
        },
        {
          "name": "ClaudeBot",
          "status": 200,
          "ttfbMs": 33
        },
        {
          "name": "PerplexityBot",
          "status": 200,
          "ttfbMs": 49
        }
      ],
      "medianTtfbMs": 49,
      "edgeBlockingDespiteRobots": false
    }
  • A6Fail

    No hard interstitial

    0/2

    Detected: CAPTCHA. An agent cannot dismiss a consent dialog or solve a challenge — whatever sits behind it is unreachable. Cookieless analytics removes the need for a banner entirely.

    What we captured
    {
      "markers": [
        "CAPTCHA"
      ]
    }
  • A7Pass

    Server-rendered content parity

    5/5
    What we captured
    {
      "ratio": 1,
      "rawTextLength": 4098,
      "renderedTextLength": 2958
    }

BUnderstanding

  • B1Pass

    JSON-LD present and valid

    5/5
    What we captured
    {
      "pagesCrawled": 6,
      "pagesWithValidJsonLd": 6,
      "homepageHasValidJsonLd": true,
      "pagesWithInvalidJsonLd": 0
    }
  • B2Pass

    Correct schema types for the site type

    5/5
    What we captured
    {
      "matched": [
        "Product",
        "Offer"
      ],
      "missing": [],
      "siteType": "ecommerce",
      "typesFound": [
        "BreadcrumbList",
        "EntryPoint",
        "ImageObject",
        "ListItem",
        "Offer",
        "Organization",
        "Product",
        "PropertyValueSpecification",
        "ReadAction",
        "SearchAction",
        "UnitPriceSpecification",
        "WebPage",
        "WebSite"
      ]
    }
  • B3Partial

    Semantic HTML structure

    3/4

    Headings and landmarks are how a machine builds an outline of the page. One h1, no skipped levels, and real main/nav/footer elements — all template-level fixes, applied once.

    What we captured
    {
      "problems": [
        "https://webseccorp.com: 0 h1 elements"
      ],
      "singleH1": 5,
      "allLandmarks": 6,
      "pagesCrawled": 6,
      "noSkippedLevels": 6
    }
  • B4Partial

    Meta and Open Graph

    1/3

    Fix: 1 title(s) outside 15–70 characters; 5 description(s) outside 50–160 characters.

    What we captured
    {
      "goodTitles": 5,
      "pagesCrawled": 6,
      "uniqueTitles": true,
      "goodDescriptions": 1,
      "completeOpenGraph": 6
    }
  • B5Partial

    Clean text ratio

    2/3

    Visible text is 5.7% of your markup. Deeply nested wrapper elements make a page expensive to parse and dilute the content an agent extracts. Script and style contents are already excluded from this measure, so this is markup weight, not framework overhead.

    What we captured
    {
      "perPage": [
        0.074,
        0.027,
        0.086,
        0.048,
        0.066,
        0.041
      ],
      "averageRatio": 0.057
    }
  • B6Pass

    Alt text coverage

    2/2
    What we captured
    {
      "withAlt": 76,
      "coverage": 1,
      "contentImages": 76
    }
  • B7Pass

    Canonical and duplication hygiene

    3/3
    What we captured
    {
      "hostVariants": [
        {
          "url": "https://www.webseccorp.com",
          "status": 301,
          "location": "https://webseccorp.com/"
        },
        {
          "url": "http://webseccorp.com",
          "status": 301,
          "location": "https://webseccorp.com/"
        }
      ],
      "pagesCrawled": 6,
      "selfConsistentCanonicals": 6
    }

CActionability

  • C1Pass

    Form usability

    5/5
    What we captured
    {
      "forms": 8,
      "inputs": 20,
      "realSubmit": true,
      "unlabelled": 0,
      "wrongTypes": 0
    }
  • C2Partial

    Navigable link graph

    3/4

    Fix: 13% of links use contextless text like "click here".

    What we captured
    {
      "anchors": 45,
      "genericLinks": 6,
      "genericRatio": 0.13,
      "hasBreadcrumb": true,
      "clickableNonAnchors": 0
    }
  • C3Pass

    Interactive element semantics

    4/4
    What we captured
    {
      "realButtons": 3,
      "positiveTabindex": 0,
      "clickableNonButtons": 0,
      "keyboardTrapsTested": false
    }
  • C4Fail

    Machine endpoints and agent manifests

    0/5

    No machine-readable endpoint of any kind. Most sites score zero here, which is exactly why it is the cheapest differentiation on this rubric: an agents.json is a static file, and a documented read-only API is usually a subset of something you already run.

    What we captured
    {
      "found": []
    }
  • C5Partial

    Commerce actionability

    1/4

    Fix: no Offer schema carrying price and availability; cart or checkout path did not return 200 without login; no guest or express checkout signal detected. Agentic commerce depends on an agent being able to read a price and reach a checkout without an account.

    What we captured
    {
      "offerSchema": false,
      "cartReachable": false,
      "expressCheckout": false,
      "productPageFound": true
    }
  • C6Partial

    On-site search

    2/3

    Search exists but posts rather than using a GET query parameter, so an agent cannot construct a results URL directly. Switching to GET is usually a one-line change, and advertising it via WebSite SearchAction schema makes it discoverable.

    What we captured
    {
      "usesGet": false,
      "searchForm": false,
      "searchAction": true
    }

DTrust & freshness

  • D1Partial

    Transport security

    2/4

    Fix: no Strict-Transport-Security header; 1 insecure subresource reference(s).

    What we captured
    {
      "hsts": false,
      "tlsValid": true,
      "mixedContentReferences": 1
    }
  • D2Partial

    Verifiable identity

    2/4

    Fix: Organization schema has no sameAs links. sameAs links to a company profile are how a model corroborates that you are who the page says you are.

    What we captured
    {
      "sameAsCount": 0,
      "contactDiscoverable": true,
      "hasOrganizationSchema": true
    }
  • D3Partial

    Policies discoverable

    2/4

    Fix: shipping and returns pages not both linked.

    What we captured
    {
      "hasTerms": false,
      "siteType": "ecommerce",
      "hasPrivacy": true,
      "hasReturns": false,
      "hasShipping": false
    }
  • D4Partial

    Freshness signals

    2/4

    Fix: only 0% of sitemap URLs modified in the last 90 days. Staleness is a ranking signal for models deciding what to cite.

    What we captured
    {
      "sitemapUrls": 32,
      "withLastmod": 32,
      "visibleDates": true,
      "modifiedLast90Days": 0
    }
  • D5Partial

    Identity consistency

    2/3

    Fix: no favicon declared. An unexplained name mismatch reads as a signal the site may not be what it claims.

    What we captured
    {
      "title": "IA & Security Solutions Provider | WebSec Corporation",
      "hasFavicon": false,
      "hasOgImage": true,
      "ogSiteName": "WebSec Corporation",
      "schemaName": "IA & Security Solutions Provider | WebSec Corporation"
    }
  • D6Fail

    security.txt

    0/2

    Publish /.well-known/security.txt with a Contact field and a future-dated Expires field. It is a five-line text file.

    What we captured
    {
      "status": 404,
      "present": false
    }
  • D7Partial

    Multi-page stability

    3/4

    Fix: navigation missing on some pages.

    What we captured
    {
      "nonOk": [],
      "slowPages": 0,
      "pagesCrawled": 6,
      "consistentTemplate": false
    }
67C
Discovery & access18/25
Understanding21/25
Actionability15/25
Trust & freshness13/25

Keep this report

Get the permanent link and the ranked fix list by email. One message, no list.

Want this fixed?

We audit in depth and implement the fixes — in your codebase or your CMS, scoped by architecture.

Own this site?

This report and its leaderboard entry come from a public crawl. Prove you own the domain with an email address on it, and you can hide the report or publish it again yourself, in minutes.

To block future scans instead, disallow AgentFriendlyRankBot in your robots.txt — see how our crawler works.

Scan your own site

Same rubric, same evidence standard, about a minute.

Run a free scan →

Compare webseccorp.com with another site →