SSL / TLS
Valid HTTPS · 222ms
x402 discovery
No x402 discovery found
Agent discovery
No agent.json found
llms.txt
HTTP 404 · 187ms
security.txt
Not found · 379ms
CORS headers
origin: https://partner.visa.com (restricted) · 356ms
Security headers
3/5 — missing: content-security-policy · 365ms
Response time
635ms avg · 635ms
MCP server
No MCP endpoint found
API endpoints
2 endpoints found
Error handling
404 JSON response · 901ms
x402 compliance
No x402 payment gates found · 564ms
Rate limiting
No rate-limit headers (may still be rate-limited server-side) · 576ms
Documentation
/docs found · 584ms
robots.txt AI crawlers
HTTP 404 · 927ms
AI plugin manifest
No ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec
/openapi.yaml found but invalid JSON · 380ms
Privacy / GDPR
/privacy found (1269 chars) · 1137ms
Status / Health
No status or health endpoint
EU AI Act disclosure
No AI model card or disclosure endpoint
Travel Rule (FATF)
No Travel Rule endpoint or VASP disclosure
A2A Protocol (Google)
No agent.json for A2A discovery
DNSSEC
No DNSSEC — domain is vulnerable to DNS spoofing
CAA Records
1 CAA record(s) found
DMARC / SPF
DMARC p=reject
Auth maturity
No authentication detected — open API or check failed
API versioning
No versioned paths or version headers found
Human oversight
No human oversight / kill switch endpoint (EU AI Act Art. 14)
Terms of Service
/terms found (142678 chars) · 1101ms
Content-Type
No application/json responses (1 paths tested)
Wallet trust
No wallet address found in x402 or agent.json
ERC-8004 on-chain
No EVM wallet found to verify on-chain registration
Critical — 3x402 discovery failedNo x402 discovery found
Agent discovery failedNo agent.json found
Warning — 21security.txt needs attentionNot found
Security headers needs attention3/5 — missing: content-security-policy
Response time needs attention635ms avg
MCP server needs attentionNo MCP endpoint found
x402 compliance needs attentionNo x402 payment gates found
Rate limiting needs attentionNo rate-limit headers (may still be rate-limited server-side)
robots.txt AI crawlers needs attentionHTTP 404
AI plugin manifest needs attentionNo ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec needs attention/openapi.yaml found but invalid JSON
Status / Health needs attentionNo status or health endpoint
EU AI Act disclosure needs attentionNo AI model card or disclosure endpoint
Travel Rule (FATF) needs attentionNo Travel Rule endpoint or VASP disclosure
A2A Protocol (Google) needs attentionNo agent.json for A2A discovery
DNSSEC needs attentionNo DNSSEC — domain is vulnerable to DNS spoofing
DMARC / SPF needs attentionDMARC p=reject
Auth maturity needs attentionNo authentication detected — open API or check failed
API versioning needs attentionNo versioned paths or version headers found
Human oversight needs attentionNo human oversight / kill switch endpoint (EU AI Act Art. 14)
Content-Type needs attentionNo application/json responses (1 paths tested)
Wallet trust needs attentionNo wallet address found in x402 or agent.json
ERC-8004 on-chain needs attentionNo EVM wallet found to verify on-chain registration