Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanRetail storefront · Storefront property/Scanned 8 Sept 2026, 20:08 UTC/1 browser pass
A Shopify storefront with open product data but no account-free checkout path and no agent instrumentation.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
3 pieces of evidence and the recommended fix are recorded for this issue, with snippets/seconddoor-product-jsonld.liquid written from your own pages.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail. Not measured is not zero.
Machine discoverability
No AI crawler is blocked by robots.txt or user agent rules. The site publishes llms.txt, a sitemap with 81 URLs including product pages, and a /products.json feed listing 11 products with brand and identifier.
4 observations recorded.
Programmatic onboarding
No API documentation, OpenAPI spec, or MCP manifest exists at any standard path. The /products.json feed is readable but requires no authentication, so an agent can fetch product data without registration.
1 observation recorded.
Pricing legibility
Prices appear in raw HTML on the homepage (9 instances) and across 3 product pages checked (124 instances). Product structured data publishes price and currency on every offer. An agent can parse cost without JavaScript or scraping.
2 observations recorded.
Agent-aware instrumentation
No MCP manifest, OpenAPI spec, or Web Bot Auth signals exist. The /products.json catalogue feed is machine-readable with brand and identifier on each product.
4 observations recorded.
Machine-fetchable trust
No security.txt file exists at /.well-known/security.txt. The homepage and product pages are served to automated clients without blocking. The site publishes a robots.txt with 87 directives that explicitly allow major AI crawlers including.
2 observations recorded.
Commercial rails
Product markup carries price, currency, identifier, brand, aggregate rating (4.5 stars over 531 reviews) and a 30-day return policy in schema. The /products.json feed includes brand and handle on each of 11 products.
3 observations recorded.
Steps to first value
Could not verify: this scan did not reach the pages that would show it.
Required fields
Could not verify: this scan did not reach the pages that would show it.
Verification walls
Could not verify: this scan did not reach the pages that would show it.
Error recovery
Could not verify: this scan did not reach the pages that would show it.
It got through 8 of 14.
The agent got through 8 of 14 requests, but could not find a contact route for machines. It came up empty on 5 other checks too.