Result summary
Readiness profiles
Methodology 2026-08-29Measured stable-core coverage
73/100
Methodology grade
B
37 core checkpoints assessed
26
Passed
1
Partial
10
Failed
12
Skipped
Strongest category
AI Search Signals
Weakest category
Security & Trust
Action plan
Priority actions
Highest-impact implementation details
3 prioritized actions
Prioritized by exact impact on the overall stable-core score.
Failed
HSTS header
+5 overall pts
Strict-Transport-Security header is not set. Note: sites on the HSTS preload list may not send this header but are still protected via browser preloading.
HSTS header
HIGHHSTS prevents protocol downgrade attacks by telling browsers to always use HTTPS. AI agents that follow redirects benefit from HSTS as it eliminates insecure initial connections.
Add the Strict-Transport-Security header with max-age=31536000 (1 year) and includeSubDomains. If your site is on the HSTS preload list (hstspreload.org), the header is still recommended for first-visit protection.
# Nginx
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
# Apache (.htaccess)
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
Failed
Content-Security-Policy
+4 overall pts
Content-Security-Policy header is not set.
Content-Security-Policy
HIGHContent-Security-Policy prevents XSS and injection attacks. For AI agents that interact with your site, CSP ensures the page content hasn't been tampered with by malicious scripts.
Add a Content-Security-Policy header with directives like default-src, script-src, and style-src.
# Nginx
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self'" always;
# Apache (.htaccess)
Header always set Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self'"
Failed
Link response headers
+4 overall pts
Link header present but no agent-useful rel values found. Detected rels: api.w.org, alternate, shortlink.
Link response headers
HIGHLink response headers (RFC 8288) tell agents about machine-readable resources at request time. Cloudflare's isitagentready.com and other scanners explicitly look for `api-catalog`, `service-desc`, `service-doc`, and `sitemap` rels to enable agent discovery without parsing HTML.
Add Link headers with rels from the IANA registry that help agents: api-catalog, service-desc (OpenAPI), service-doc, sitemap, describedby.
# Nginx
add_header Link '</.well-known/api-catalog>; rel="api-catalog", </openapi.json>; rel="service-desc", </sitemap.xml>; rel="sitemap"' always;
# Phoenix / Plug
plug :put_link_headers
defp put_link_headers(conn, _opts) do
put_resp_header(
conn,
"link",
"</.well-known/api-catalog>; rel=\"api-catalog\", " <>
"</openapi.json>; rel=\"service-desc\", " <>
"</sitemap.xml>; rel=\"sitemap\""
)
end
# Test: curl -I https://racing.nl/ | grep -i '^link:'
Detailed results
Agent Protocols
Weight 15%
Not assessed
No score-impacting checkpoints
5 bonus opportunities and 3 informational findings; do not affect the core score
Core score
0/100
No score-impacting checkpoints
5 bonus opportunities and 3 informational findings; do not affect the core score
AI Content Discovery
Weight 30%
Needs attention
1 failed, 1 partial score-impacting checkpoints
5 bonus opportunities; do not affect the core score
Core score
85/100
1 failed, 1 partial score-impacting checkpoints
5 bonus opportunities; do not affect the core score
Security & Trust
Weight 15%
Needs attention
5 failed score-impacting checkpoints
Core score
27/100
5 failed score-impacting checkpoints
Content & Semantics
Weight 20%
Needs attention
3 failed score-impacting checkpoints
Core score
76/100
3 failed score-impacting checkpoints
AI Search Signals
Weight 20%
Needs attention
1 failed score-impacting checkpoint
Core score
89/100
1 failed score-impacting checkpoint
AI visitor test
We let an AI try common visitor tasks to show what works and where it gets stuck.
Can an AI understand this website?
UnavailableThis check is temporarily unavailable.
Can an AI find a useful action to take?
UnavailableThis check is temporarily unavailable.
AI Training Exposure
Supplemental
Does not affect the readiness score
Does not affect the readiness score
No AI training protections detected. Your content may be freely used for AI model training.
Could not determine the latest Common Crawl index.
No training crawlers are blocked in robots.txt. All known AI training bots can access your content.
No TDMRep file found at /.well-known/tdmrep.json. The TDM Reservation Protocol (W3C) lets you declare whether you reserve text and data mining rights. See w3.org/community/reports/tdmrep/CG-FINAL-tdmrep-20240510 for the specification.
No ai.txt file found. ai.txt lets you declare AI usage preferences for your content.
No Web Bot Auth signature key directory found. Bots cannot prove their identity to origins via signed HTTP requests.
Scan and fix from your editor
Install our MCP server to scan any website from your terminal. Pair it with AI agent skills to fix failing checks automatically.
- Scan any website directly from your terminal
- Fix failing checks with AI agent skills
- Re-scan to verify improvements
claude mcp add isagentready-mcp -- npx -y isagentready-mcp
/plugin marketplace add bartwaardenburg/isagentready-skills
Request a detailed report Optional follow-up with a personalized PDF report
Get your detailed report
Receive a personalized report with actionable insights for improving your website's AI agent readiness.
- Detailed score breakdown per category
- Prioritized improvement recommendations
- Step-by-step implementation guide