Basic scanSoftware and storefront · Storefront property/Scanned 7 Sept 2026, 20:46 UTC/1 browser pass
seconddoor.io
A software and storefront hybrid with strong machine discoverability but no published path for agents to complete a purchase.
Narrow. Both audiences hit roughly the same walls.
The two issues worth fixing first
Ordered by what the evidence says is costing most. Written for whoever owns the site, not whoever builds it.
3 pieces of evidence and the recommended fix are recorded for this issue, with /shipping written from your own pages.
This is a basic scan, so it raises the three issues the deterministic evidence supports. A deep scan sends two agents over the site and raises up to ten, each with cited evidence and the screens to prove it.
Deep scans need an account. Accounts are free.
A deep scan walks the site with two agents, records cited evidence and screenshots, and keeps a mission timeline. It comes with the paid plans. Making an account costs nothing and gives you one basic scan a month.
Get full access
The score and the audit trail stay public. The evidence and the files open with an account.
For finding out where you stand.
- 1 basic scan a month
- 3 prioritised fixes, with evidence
- No watched domains
- Your latest report
For one site you care about.
- A deep scan every week, another when your site changes, and 3 on demand
- Every fix the scan finds, not three
- Fixes reopen when a release undoes them
- 1 watched domain, checked every day
- Competitor comparison, 2 per domain
- 12 months of history
For a portfolio and a release cadence.
- A deep scan every week, another when your site changes, and 10 on demand
- Every fix the scan finds, not three
- Fixes reopen when a release undoes them
- 5 watched domains, checked every day
- Competitor comparison, 5 per domain
- All history
What the agents checked
The audit trail behind every number above. Not measured is not zero.
Machine discoverability
Robots.txt names 14 AI crawlers and allows them all. A real browser is served the page normally. No user agent rule refuses declared crawler names.
4 observations recorded.
Programmatic onboarding
A machine readable API spec is published.
3 observations recorded.
Pricing legibility
Six prices are readable without JavaScript on the pricing page: $0, $29, $99, $249, $2,500, and one more. No tier is gated behind a demo or contact-sales wall. The page carries FAQ schema markup. Pricing is published and legible.
2 observations recorded.
Agent-aware instrumentation
An MCP manifest is published at /.well-known/mcp.json. An ai-plugin.json is published. Robots.txt names 14 AI crawlers and allows them. An OpenAPI spec is published. The site declares its intent for assistants across multiple standards.
4 observations recorded.
Machine-fetchable trust
Security.txt is published at /.well-known/security.txt with a contact route for machines. The returns policy reads as text at /refunds. The homepage answers automated requests.
3 observations recorded.
Commercial rails
Prices are published in raw HTML on the pricing page. A self-serve signup form is 2 steps from the homepage and asks for work email and password only. However, no UCP manifest, commerce platform, or payment processor is detected.
4 observations recorded.
Steps to first value
The primary call to action, 'Sign up for free', is 2 steps from the homepage and leads to a 2-field signup form. A visitor reaches the form quickly. What happens after submission was not observed in this scan.
1 observation recorded.
Required fields
The signup form has 2 fields, both required: work email and password. One sign-in option is offered: Google. Both inputs carry validation rules. The form asks for the minimum needed to create an account.
1 observation recorded.
Verification walls
No verification requirement appears on the signup page itself. Google sign-in avoids email verification entirely. Email verification after submission was not observed in this scan, so the full verification wall is unmeasured.
1 observation recorded.
Error recovery
Both of the 2 inputs on the signup form carry validation rules, so a visitor receives feedback if they enter invalid data. No inline error containers or live regions were detected, so error messaging detail is unmeasured.
1 observation recorded.
We sent a buying agent. 18 requests, in order
It got through 16 of 18.
The agent got through 16 of 18 requests, but could not find out whether verified agents are recognised. It came up empty on 1 other check too.