SSL / TLS
Valid HTTPS · 165ms
x402 discovery
No x402 discovery found
Agent discovery
No agent.json found
llms.txt
HTTP 404 · 329ms
security.txt
Not found · 365ms
CORS headers
No CORS header (OK if server-to-server only) · 204ms
Security headers
3/5 — missing: content-security-policy · 239ms
Response time
327ms avg · 327ms
MCP server
/mcp/info responds · 422ms
API endpoints
4 endpoints found
Error handling
Returns 200 for unknown paths · 538ms
x402 compliance
No x402 payment gates found · 400ms
Rate limiting
No rate-limit headers (may still be rate-limited server-side) · 402ms
Documentation
/docs found · 538ms
robots.txt AI crawlers
No AI crawler directives (GPTBot, ClaudeBot, etc.) · 499ms
AI plugin manifest
No ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec
No OpenAPI/Swagger spec found
Privacy / GDPR
/privacy found (1635 chars) · 628ms
Status / Health
/status found · 645ms
EU AI Act disclosure
/ai-disclosure found (1635 chars) · 173ms
Travel Rule (FATF)
/travel-rule found (non-JSON, 1635 chars) · 337ms
A2A Protocol (Google)
No agent.json for A2A discovery
DNSSEC
No DNSSEC — domain is vulnerable to DNS spoofing
CAA Records
No CAA records — any CA can issue certificates
DMARC / SPF
DMARC p=quarantine
Auth maturity
No authentication detected — open API or check failed
Wallet trust
No wallet address found in x402 or agent.json
ERC-8004 on-chain
No EVM wallet found to verify on-chain registration
Critical — 3x402 discovery failedNo x402 discovery found
Agent discovery failedNo agent.json found
Warning — 17security.txt needs attentionNot found
CORS headers needs attentionNo CORS header (OK if server-to-server only)
Security headers needs attention3/5 — missing: content-security-policy
Error handling needs attentionReturns 200 for unknown paths
x402 compliance needs attentionNo x402 payment gates found
Rate limiting needs attentionNo rate-limit headers (may still be rate-limited server-side)
robots.txt AI crawlers needs attentionNo AI crawler directives (GPTBot, ClaudeBot, etc.)
AI plugin manifest needs attentionNo ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec needs attentionNo OpenAPI/Swagger spec found
Travel Rule (FATF) needs attention/travel-rule found (non-JSON, 1635 chars)
A2A Protocol (Google) needs attentionNo agent.json for A2A discovery
DNSSEC needs attentionNo DNSSEC — domain is vulnerable to DNS spoofing
CAA Records needs attentionNo CAA records — any CA can issue certificates
DMARC / SPF needs attentionDMARC p=quarantine
Auth maturity needs attentionNo authentication detected — open API or check failed
Wallet trust needs attentionNo wallet address found in x402 or agent.json
ERC-8004 on-chain needs attentionNo EVM wallet found to verify on-chain registration