Some cookies are necessary for SecondDoor to work. Others are optional, and tell us how the site and the product are used. Accept all, or decline all optional ones. Without a selection, nothing optional is set. More in our cookie policy.
Basic scanUnclassified/Scanned 8 Sept 2026, 13:53 UTC/1 browser pass
A major retailer blocks automated access entirely, serving stripped pages to browsers and refusing API discovery.
Older scan
This report was produced by an earlier version of the scanner. Some findings may not match how the site is measured now.
Severe. Your human funnel and your agent funnel are different products.
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
1 piece of evidence and the recommended fix are recorded for this issue.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
The score and the audit trail stay public. The evidence and the files open with an account.
The audit trail behind every number above. Not measured is not zero.
Machine discoverability
No sitemap, no schema.org markup, and a real browser receives a stripped page of 97 characters instead of full content. AI crawlers are not explicitly blocked but get nothing useful to read.
4 observations recorded.
Programmatic onboarding
No API documentation is linked from the homepage in raw HTML or rendered form. No OpenAPI spec exists at any of the 6 standard paths. The product requires no account, so there is nothing to onboard into programmatically.
3 observations recorded.
Pricing legibility
Could not verify: this scan did not reach the pages that would show it.
1 observation recorded.
Agent-aware instrumentation
No MCP manifest published at any of the 3 standard paths. No ai-plugin.json, no llms.txt, and no Web Bot Auth signals. The site makes no attempt to declare itself to agent frameworks.
4 observations recorded.
Machine-fetchable trust
No security.txt published at /.well-known/security.txt. No robots.txt exists to declare crawl policy. No trust signals are machine-readable.
2 observations recorded.
Commercial rails
.
2 observations recorded.
Steps to first value
The product is usable immediately with no signup, no account, and no form. A visitor can browse and act on the site without any prerequisite steps. The only friction is that a browser receives a stripped page.
1 observation recorded.
Required fields
No form exists on the homepage and no account is required. Nothing is asked of a visitor before they can use the site.
1 observation recorded.
Verification walls
No account system exists, so there is nothing to verify. A visitor reaches the product with no verification step of any kind.
1 observation recorded.
Error recovery
No form means no validation errors to recover from. The only error observed is the stripped page served to browsers, which is a rendering issue rather than a recoverable user error.
1 observation recorded.
It got through 4 of 14.
The agent got through 4 of 14 requests, but could not find out whether machines are welcome. It came up empty on 9 other checks too. That is enough missing for a machine to give up before it reaches a purchase.