SSL / TLS
Valid HTTPS · 316ms
x402 discovery
/.well-known/x402 found · v2 · 739ms
Agent discovery
No agent.json found
llms.txt
Found (2450 chars) · 332ms
security.txt
Not found · 321ms
CORS headers
No CORS header (OK if server-to-server only) · 466ms
Security headers
0/5 — missing critical: x-content-type-options, strict-transport-security, content-security-policy · 477ms
Response time
553ms avg · 553ms
MCP server
No MCP endpoint found
API endpoints
2 endpoints found
Error handling
404 returned · 589ms
x402 compliance
No x402 payment gates found · 629ms
Rate limiting
No rate-limit headers (may still be rate-limited server-side) · 655ms
Documentation
/docs found · 630ms
robots.txt AI crawlers
8 AI crawlers configured: GPTBot, ClaudeBot, Claude-Web, ChatGPT-User, Anthropic, Google-Extended, PerplexityBot, Bytespider · 699ms
AI plugin manifest
No ai-plugin.json (optional for ChatGPT/LLM integration)
OpenAPI spec
/openapi.json — 3.1.0, 16 paths, servers defined · 795ms
Privacy / GDPR
/privacy found (60915 chars) · 779ms
Status / Health
No status or health endpoint
EU AI Act disclosure
No AI model card or disclosure endpoint
Travel Rule (FATF)
No Travel Rule endpoint or VASP disclosure
A2A Protocol (Google)
No agent.json for A2A discovery
DNSSEC
DNSSEC check failed
CAA Records
No CAA records — any CA can issue certificates
DMARC / SPF
No DMARC or SPF records found
Auth maturity
No authentication detected — open API or check failed
API versioning
No versioned paths or version headers found
Human oversight
No human oversight / kill switch endpoint (EU AI Act Art. 14)
Terms of Service
/terms found (37039 chars) · 959ms
Content-Type
API paths return HTML: /v1/ returns HTML
Wallet trust
No wallet address found in x402 or agent.json
ERC-8004 on-chain
No EVM wallet found to verify on-chain registration
Critical — 1Agent discovery failedNo agent.json found
Warning — 21security.txt needs attentionNot found
CORS headers needs attentionNo CORS header (OK if server-to-server only)
Security headers needs attention0/5 — missing critical: x-content-type-options, strict-transport-security, content-security-policy
Response time needs attention553ms avg
MCP server needs attentionNo MCP endpoint found
x402 compliance needs attentionNo x402 payment gates found
Rate limiting needs attentionNo rate-limit headers (may still be rate-limited server-side)
AI plugin manifest needs attentionNo ai-plugin.json (optional for ChatGPT/LLM integration)
Status / Health needs attentionNo status or health endpoint
EU AI Act disclosure needs attentionNo AI model card or disclosure endpoint
Travel Rule (FATF) needs attentionNo Travel Rule endpoint or VASP disclosure
A2A Protocol (Google) needs attentionNo agent.json for A2A discovery
DNSSEC needs attentionDNSSEC check failed
CAA Records needs attentionNo CAA records — any CA can issue certificates
DMARC / SPF needs attentionNo DMARC or SPF records found
Auth maturity needs attentionNo authentication detected — open API or check failed
API versioning needs attentionNo versioned paths or version headers found
Human oversight needs attentionNo human oversight / kill switch endpoint (EU AI Act Art. 14)
Content-Type needs attentionAPI paths return HTML: /v1/ returns HTML
Wallet trust needs attentionNo wallet address found in x402 or agent.json
ERC-8004 on-chain needs attentionNo EVM wallet found to verify on-chain registration