# Ora: 31 point Door Gap
- Site: ora.ai
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: unknown
- Report: https://www.seconddoor.io/r/ora-2q2g6j
- Scanner version: 12
An AI assistant platform publishes machine-readable integration points but blocks training crawlers and withholds security contact details.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 94/100 |
| Agents | 63/100 |
| Composite | 79/100 |
| Door Gap | 31 points |
| Percentile | 99th |
The human score is the mean of the four human dimensions, the agent score the mean of the six agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The agent got through 12 of 13 requests, but could not find a contact route for machines.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- ok      find a published agent interface
- ok      find an agent plugin manifest
- ok      find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- ok      find a machine readable API spec
- ok      read the developer documentation
- ok      walk the way a visitor would, to a signup form or a product
## Top issues
1. **Training crawlers are blocked in robots.txt, preventing model weight updates from the site's content.** (machine_discoverability)
2. **No security.txt file is published, leaving no machine-readable contact path for vulnerability disclosure.** (machine_fetchable_trust)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/ora-2q2g6j
## Files generated from this scan
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/ora-2q2g6j
## The agent door
- **machine_discoverability** 59/100. Robots.txt blocks 2 training crawlers (ccbot, bytespider) while allowing search and agent crawlers including gptbot, claudebot and perplexitybot. A sitemap lists 1723 URLs, 16 schema.org types appear on the homepage, and llms.txt is.
- **programmatic_onboarding** null/100. Not scored: a blog is not measured on this.
- **pricing_legibility** null/100. Not scored: a blog is not measured on this.
- **agent_aware_instrumentation** 91/100. An MCP manifest is published at /.well-known/mcp.json, an ai-plugin.json is published, and Web Bot Auth signals are present with 1 key in the directory. A machine readable API spec is published at /openapi.json.
- **machine_fetchable_trust** 40/100. No security.txt is published at /.well-known/security.txt, so no security contact or vulnerability disclosure path is machine-readable. The homepage answers automated requests with structured data and schema.org markup.
- **commercial_rails** null/100. Not scored: a blog is not measured on this.
## The human door
- **steps_to_first_value** 95/100. The product is usable immediately without signup or account creation. No entry wall exists. A visitor reaches full functionality on the homepage with no steps required.
- **required_fields** 100/100. No form exists on the homepage and no account is required. Nothing is asked of a visitor before they can use the product.
- **verification_walls** 100/100. No account system exists, so no verification step stands between a visitor and the product. Access is immediate.
- **error_recovery** 80/100. No form is present on the homepage, so no validation errors can occur during signup. The absence of a form means error recovery cannot be measured, but the lack of friction is itself a strong signal.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
