Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanPublisher · Storefront property/Scanned 8 Sept 2026, 14:18 UTC/1 browser pass
A dermatology content publisher blocks programmatic access to its product while allowing human readers to browse freely.
Older scan
This report was produced by an earlier version of the scanner. Some findings may not match how the site is measured now.
Severe. Your human funnel and your agent funnel are different products.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
3 pieces of evidence and the recommended fix are recorded for this issue, with /.well-known/security.txt written from your own pages.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail behind every number above. Not measured is not zero.
Machine discoverability
No AI crawler is blocked by robots.txt, a real browser is served the page normally, and the sitemap lists 1168 URLs with 5 schema.org types published on the homepage. Agents can find and index the content.
4 observations recorded.
Programmatic onboarding
No API documentation, OpenAPI spec, or developer surface exists. The product itself requires no account, so there is no programmatic path to onboard. Agents cannot integrate with the service.
3 observations recorded.
Pricing legibility
Not scored: a business of this kind is not measured on this.
Agent-aware instrumentation
No MCP manifest is published at any of the 3 standard paths checked. Agents cannot discover structured capabilities or invoke the product through standard protocols.
4 observations recorded.
Machine-fetchable trust
No security.txt or Web Bot Auth signals are published. The homepage answers automated requests, but no trust metadata is available for agents to verify the site's identity or security posture.
2 observations recorded.
Commercial rails
Not scored: a business of this kind is not measured on this.
Steps to first value
The product is a quiz that begins immediately at https://quiz.curology.com/sign-up/start/face with no account required. A visitor reaches the content in 2 steps from the homepage CTA.
1 observation recorded.
Required fields
No form exists on the entry path. The quiz begins without asking for any information, so nothing stands between a visitor and the product.
1 observation recorded.
Verification walls
No account system exists. There is no email verification, phone verification, or identity check. A visitor proceeds directly to the quiz.
1 observation recorded.
Error recovery
No form fields mean no validation errors to recover from. The quiz interface itself was not walked, so error handling within the product cannot be scored.
1 observation recorded.
It got through 6 of 13.
The agent got through 6 of 13 requests, but could not read the site's own guide for language models. It came up empty on 6 other checks too. That is enough missing for a machine to give up before it reaches a purchase.