Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanUnclassified · Blog property/Scanned 8 Sept 2026, 14:52 UTC/1 browser pass
An AI assistant platform publishes machine-readable integration points but blocks training crawlers and withholds security contact details.
Older scan
This report was produced by an earlier version of the scanner. Some findings may not match how the site is measured now.
Wide. Agents are dropping out well before humans do.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
3 pieces of evidence and the recommended fix are recorded for this issue.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail behind every number above. Not measured is not zero.
Machine discoverability
Robots.txt blocks 2 training crawlers (ccbot, bytespider) while allowing search and agent crawlers including gptbot, claudebot and perplexitybot. A sitemap lists 1723 URLs, 16 schema.org types appear on the homepage, and llms.txt is.
4 observations recorded.
Programmatic onboarding
Not scored: a blog is not measured on this.
Pricing legibility
Not scored: a blog is not measured on this.
Agent-aware instrumentation
An MCP manifest is published at /.well-known/mcp.json, an ai-plugin.json is published, and Web Bot Auth signals are present with 1 key in the directory. A machine readable API spec is published at /openapi.json.
4 observations recorded.
Machine-fetchable trust
No security.txt is published at /.well-known/security.txt, so no security contact or vulnerability disclosure path is machine-readable. The homepage answers automated requests with structured data and schema.org markup.
2 observations recorded.
Commercial rails
Not scored: a blog is not measured on this.
Steps to first value
The product is usable immediately without signup or account creation. No entry wall exists. A visitor reaches full functionality on the homepage with no steps required.
1 observation recorded.
Required fields
No form exists on the homepage and no account is required. Nothing is asked of a visitor before they can use the product.
1 observation recorded.
Verification walls
No account system exists, so no verification step stands between a visitor and the product. Access is immediate.
1 observation recorded.
Error recovery
No form is present on the homepage, so no validation errors can occur during signup. The absence of a form means error recovery cannot be measured, but the lack of friction is itself a strong signal.
1 observation recorded.
It got through 12 of 13.
The agent got through 12 of 13 requests, but could not find a contact route for machines.