zhc.company D · 59/100
14 passed 18 warnings 0 failed audit-mnetns2q
SSL / TLS Valid HTTPS · 424ms
x402 discovery /.well-known/x402.json (non-JSON) · 827ms
Agent discovery /.well-known/agent.json not valid JSON · 474ms
llms.txt Found (2431 chars) · 855ms
security.txt Found · 418ms
CORS headers No CORS header (OK if server-to-server only) · 956ms
Security headers 5/5 present (all critical headers set) · 633ms
Response time 741ms avg · 741ms
MCP server /mcp/info responds · 1101ms
API endpoints 3 endpoints found
Error handling Returns 200 for unknown paths · 1208ms
x402 compliance No x402 payment gates found · 1029ms
Rate limiting No rate-limit headers (may still be rate-limited server-side) · 1058ms
Documentation /docs found · 1562ms
robots.txt AI crawlers No AI crawler directives (GPTBot, ClaudeBot, etc.) · 1438ms
AI plugin manifest /.well-known/ai-plugin.json not valid JSON · 1618ms
OpenAPI spec /openapi.json found but invalid JSON · 1322ms
Privacy / GDPR /privacy found (2431 chars) · 1759ms
Status / Health /status found · 1454ms
EU AI Act disclosure /.well-known/model-card.json found (2431 chars) · 1545ms
Travel Rule (FATF) /.well-known/travel-rule.json found (non-JSON, 2431 chars) · 1633ms
A2A Protocol (Google) agent.json found but invalid JSON · 1652ms
DNSSEC No DNSSEC — domain is vulnerable to DNS spoofing
CAA Records No CAA records — any CA can issue certificates
DMARC / SPF DMARC p=reject
Auth maturity API key
API versioning /v1
Human oversight /agent/stop — active (EU AI Act Art. 14) · 1823ms
Terms of Service /terms found (2431 chars) · 1831ms
Content-Type API paths return HTML: /v1/ returns HTML
Wallet trust No wallet address found in x402 or agent.json
ERC-8004 on-chain No EVM wallet found to verify on-chain registration
59
18 issues to fix
Warning — 18
Agent discovery needs attention

/.well-known/agent.json not valid JSON

CORS headers needs attention

No CORS header (OK if server-to-server only)

Response time needs attention

741ms avg

Error handling needs attention

Returns 200 for unknown paths

x402 compliance needs attention

No x402 payment gates found

Rate limiting needs attention

No rate-limit headers (may still be rate-limited server-side)

robots.txt AI crawlers needs attention

No AI crawler directives (GPTBot, ClaudeBot, etc.)

AI plugin manifest needs attention

/.well-known/ai-plugin.json not valid JSON

OpenAPI spec needs attention

/openapi.json found but invalid JSON

Travel Rule (FATF) needs attention

/.well-known/travel-rule.json found (non-JSON, 2431 chars)

A2A Protocol (Google) needs attention

agent.json found but invalid JSON

DNSSEC needs attention

No DNSSEC — domain is vulnerable to DNS spoofing

CAA Records needs attention

No CAA records — any CA can issue certificates

DMARC / SPF needs attention

DMARC p=reject

Auth maturity needs attention

API key

Content-Type needs attention

API paths return HTML: /v1/ returns HTML

Wallet trust needs attention

No wallet address found in x402 or agent.json

ERC-8004 on-chain needs attention

No EVM wallet found to verify on-chain registration

Share on X Run new audit
🔒 Probe trust badge — unlock at score 60+

Fix your failing checks to earn the Probe verified badge. Display it on your site footer and README to show compliance.

⚡ Fix my API — $29 Current score: 59/100 → need 60+
Badge preview Shield preview
2026-03-31 16:19:08 UTC · getprobe.xyz