# Gainful: agent door 53, human door not measured
- Site: gainful.com
- Scanned: 2026-09-11
- Scan type: Basic scan
- Business type: ecommerce
- Report: https://www.seconddoor.io/r/gainful-n5br8r
- Scanner version: 54
- Scanner release: 2cdef4a
- Scoring methodology: 1
- Evidence schema: 1
0 human and 4 agent dimensions measured from the pages checked; remaining dimensions are not scored.
## Scores
| Measure | Score |
| --- | --- |
| Humans | not measured |
| Agents | 53/100 (4/6 dimensions) |
| Composite | 53/100 |
Agent door only. The human door could not be measured on this scan. A Door Gap needs both doors, so this scan does not report one.
## What the machine actually did
The scanner recorded successful observations for 7 of 17 checks, but could not find a contact route for machines. It came up empty on 9 other checks too. 1 check could not be measured; see the report limitations.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find an MCP manifest at the standard paths checked
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- missing read the homepage as data rather than as a page
- missing find a machine readable API spec
- missing read the developer documentation
- ok      read the product catalogue as data
- missing read a product page as data
- missing read the returns and shipping terms
- ok      discover storefront agent checkout rails
- missing walk the way a visitor would, to a signup form or a product
## Top issues
1. **No valid security.txt was identified at /.well-known/security.txt.** (machine_fetchable_trust)
   - Evidence: /.well-known/security.txt: not found (404)
   - Evidence: Checked URL: https://www.gainful.com/.well-known/security.txt
   - Fix: Publish /.well-known/security.txt with a contact route.
The full report is at https://www.seconddoor.io/r/gainful-n5br8r
## Files generated from this scan
- **Complete the merchant fields in product markup** at `snippets/seconddoor-product-jsonld.liquid`, 30 minutes, developer. Verify: The next scan reads priceValidUntil and the available owner-reviewed return and shipping fields alongside price, currency and availability in the Product markup it samples.
- **Variants missing a GTIN or a brand** at `catalog-identifiers.csv`, 5 minutes, no developer needed. Verify: The next scan reads the catalogue feed and finds a valid GTIN on at least nine in ten variants and a brand on at least nine in ten products.
- **Organization structured data** at `homepage`, 15 minutes, developer. Verify: The next scan reads Organization and WebSite nodes in the homepage JSON-LD and the structured data check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/gainful-n5br8r
## The agent door
- **machine_discoverability** 79/100. Robots.txt explicitly names 7 AI crawler tokens; policies differ by token. On its first visit, our browser read the homepage. No user agent rule refused the tested retrieval crawler names. A sitemap listing 37 URLs.
- **programmatic_onboarding** 30/100. No general API documentation or OpenAPI specification was identified through the paths checked. A storefront MCP endpoint answered the tested tools/list discovery request; authentication and use were not tested.
- **pricing_legibility** not measured. Not measured: our scanner could not identify the required evidence on the pages checked.
- **agent_aware_instrumentation** 61/100. No MCP manifest was identified at the discovery paths checked. Robots.txt explicitly names 7 AI crawler tokens; policies differ by token. A Universal Commerce Protocol manifest is published.
- **machine_fetchable_trust** 40/100. No security.txt was identified at the checked path. The homepage answers automated requests.
- **commercial_rails** not measured. Not measured: our scanner could not identify the required evidence on the pages checked.
## The human door
- **steps_to_first_value** not measured. Not measured: our scanner could not identify the required evidence on the pages checked.
- **required_fields** not measured. Not measured: this scan did not reach the page or action needed to verify it.
- **verification_walls** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
- **error_recovery** not measured. Not measured: this read-only scan did not submit the form or perform the action needed to test this behavior.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
