SSL / TLS
Valid HTTPS · 143ms
x402 discovery
No x402 discovery found
Agent discovery
No agent.json found
llms.txt
Found (347959 chars) · 1017ms
security.txt
Found · 186ms
CORS headers
No CORS header (OK if server-to-server only) · 474ms
Security headers
5/5 present (all critical headers set) · 528ms
Response time
415ms avg · 415ms
MCP server
/mcp/info responds · 367ms
API endpoints
No standard endpoints
Error handling
Could not test · 828ms
x402 compliance
No x402 payment gates found · 409ms
Rate limiting
No rate-limit headers (may still be rate-limited server-side) · 478ms
Documentation
/docs found · 461ms
robots.txt AI crawlers
robots.txt exists but no AI crawler rules · 469ms
AI plugin manifest
No ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec
No OpenAPI/Swagger spec found
Privacy / GDPR
/privacy found (853649 chars) · 880ms
Status / Health
No status or health endpoint
EU AI Act disclosure
No AI model card or disclosure endpoint
Travel Rule (FATF)
No Travel Rule endpoint or VASP disclosure
A2A Protocol (Google)
No agent.json for A2A discovery
DNSSEC
DNSSEC check failed
CAA Records
3 CAA record(s) found on vercel.com
DMARC / SPF
DMARC p=quarantine · SPF ~all (softfail)
Auth maturity
No authentication detected — open API or check failed
API versioning
No versioned paths or version headers found
Human oversight
/agent/stop — active (EU AI Act Art. 14) · 704ms
Terms of Service
/terms found (829367 chars) · 989ms
Content-Type
No application/json responses (1 paths tested)
OASF Classification
No OASF or agent service classification found
MCP Transport Security
No MCP endpoint found
Wallet trust
No wallet address found in x402 or agent.json
ERC-8004 on-chain
No EVM wallet found to verify on-chain registration
Critical — 2x402 discovery failedNo x402 discovery found
Agent discovery failedNo agent.json found
Warning — 21CORS headers needs attentionNo CORS header (OK if server-to-server only)
API endpoints needs attentionNo standard endpoints
Error handling needs attentionCould not test
x402 compliance needs attentionNo x402 payment gates found
Rate limiting needs attentionNo rate-limit headers (may still be rate-limited server-side)
robots.txt AI crawlers needs attentionrobots.txt exists but no AI crawler rules
AI plugin manifest needs attentionNo ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec needs attentionNo OpenAPI/Swagger spec found
Status / Health needs attentionNo status or health endpoint
EU AI Act disclosure needs attentionNo AI model card or disclosure endpoint
Travel Rule (FATF) needs attentionNo Travel Rule endpoint or VASP disclosure
A2A Protocol (Google) needs attentionNo agent.json for A2A discovery
DNSSEC needs attentionDNSSEC check failed
DMARC / SPF needs attentionDMARC p=quarantine · SPF ~all (softfail)
Auth maturity needs attentionNo authentication detected — open API or check failed
API versioning needs attentionNo versioned paths or version headers found
Content-Type needs attentionNo application/json responses (1 paths tested)
OASF Classification needs attentionNo OASF or agent service classification found
MCP Transport Security needs attentionNo MCP endpoint found
Wallet trust needs attentionNo wallet address found in x402 or agent.json
ERC-8004 on-chain needs attentionNo EVM wallet found to verify on-chain registration