Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanUnclassified/Scanned 8 Sept 2026, 20:03 UTC/1 browser pass
Hims blocks all automated access at the HTTP layer, preventing both AI agents and programmatic integrations from reading the site.
Severe. Your human funnel and your agent funnel are different products.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
1 piece of evidence and the recommended fix are recorded for this issue, with notes written from your own pages.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail behind every number above. Not measured is not zero.
Machine discoverability
No JSON-LD schema or microdata on the homepage. The sitemap is blocked from automated access, so its contents cannot be verified. A real browser's own request to the homepage is refused with an automated traffic challenge, which closes the.
4 observations recorded.
Programmatic onboarding
No API documentation is linked from the homepage. Automated access to all six standard OpenAPI paths was refused. The site offers no programmatic entry point that an agent or integration could discover or use.
3 observations recorded.
Pricing legibility
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
Agent-aware instrumentation
No MCP manifest.
4 observations recorded.
Machine-fetchable trust
The security.txt file at /.well-known/security.txt could not be checked because automated access was refused with HTTP 403. The homepage itself refuses all automated clients outright, blocking the ability to verify trust signals.
2 observations recorded.
Commercial rails
Could not verify: this scan did not reach the pages that would show it.
2 observations recorded.
Steps to first value
The signup page is 2 steps from the homepage, which is a short distance. However, a real browser's request to the signup page was refused with an automated traffic challenge, so the form itself could not be read.
1 observation recorded.
Required fields
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
Verification walls
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
Error recovery
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
It got through 3 of 14.
The site refused automated access at hims.com, so the agent could not reach the site at all.