nutritionwarehouse.com.au
Audited 6 days ago· shopify
Agent-readiness across all five AI commerce surfaces.
Surfaces — click to filter
16 failing · 7 not checked · 23 shown
7 checks couldn't run on this store — each is listed below with the reason. Your score reflects only what we could verify.
Enforce HTTPS sitewide and ship a Strict-Transport-Security header with max-age ≥ 6 months
Why this matters: AI agents and payment flows refuse plain HTTP; weak HSTS is treated as effectively no HSTS by trust-and-safety scanners.
Findings (1)
Confirmed the homepage is HTTPS (status 200), probed http://nutritionwarehouse.com.au/ for redirect behaviour, and parsed the Strict-Transport-Security header (value: "max-age=7889238").
How: URL scheme + homepage status check, an http://host/ redirect probe through politeFetch, and a Strict-Transport-Security max-age parse (RFC 6797; ≥ 180-day threshold).
- HSTS max-age is below the 6-month minimumCRITICAL
/parsed max-age = 7889238s (need ≥ 15552000s = 180 days)
What we found
max-age=7889238What we expected
Strict-Transport-Security: max-age=31536000; includeSubDomainsBump
max-ageto at least 15552000 (180 days). 31536000 (1 year) is required for preload-list inclusion.
Remove the noindex directive from every PDP
Why this matters: A noindex on the PDP makes it invisible to Google and ineligible for the merchant listing program.
Findings (3)
Sampled 20 PDP(s); 3 returned a noindex directive.
How: For each sampled PDP, inspect the HTML for <meta name="robots" content="...noindex..."> and the response headers for X-Robots-Tag: ...noindex....
Coverage
17/20 · 85%
- PDP returns noindex (html)HIGH× 3
What we found
<meta name="robots" content="noindex,nofollow" />What we expected
<meta name="robots" content="index, follow">Remove the noindex directive from both the meta tag and the X-Robots-Tag header on this route.
Affected (3)
- /products/loaded-shaker-by-kamikazecontent: noindex,nofollow
- /products/kamikaze-energy-rtd-free-gift-by-athl…content: noindex,nofollow
- /products/let-the-gains-begin-shaker-free-gift-…content: noindex,nofollow
Emit a single Product JSON-LD node per PDP
Why this matters: Duplicate Product nodes on a single PDP cause Google's merchant scraper to drop the listing or pick the wrong variant.
Findings (16)
Sampled 20 PDP(s); 16 carried multiple Product JSON-LD nodes.
How: For each sampled PDP, count JSON-LD nodes whose @type is Product or whose @type array contains Product. Each PDP must expose at most one.
Coverage
4/20 · 20%
- PDP exposes 2 Product JSON-LD nodesHIGH× 16
Emit exactly one Product JSON-LD block per PDP; model variants via
hasVariantor multiple Offer children.Affected (16)
- /products/mad-gains-by-mad-science2 Product nodes detected
- /products/protein-water-by-nutra-naturals2 Product nodes detected
- /products/loaded-shaker-by-kamikaze2 Product nodes detected
- /products/everyday-hydration-salts-assorted-sac…2 Product nodes detected
- /products/kamikaze-energy-rtd-free-gift-by-athl…2 Product nodes detected
- /products/kn-12-live-well-by-kailo-nutrition2 Product nodes detected
- /products/vitamin-d3-k2-by-genetix-nutrition-es…2 Product nodes detected
- /products/tmg-by-genetix-nutrition-essentials2 Product nodes detected
- /products/tudca-by-anabolix-nutrition2 Product nodes detected
- /products/l-theanine-by-genetix-nutrition-essen…2 Product nodes detected
- …and 6 more
…and 6 more
Populate gtin on every branded Product node
Why this matters: GTINs let agents match your product to the same item elsewhere; without them you lose cross-catalog matching.
Findings (11)
Checked 20 sampled product pages for a GTIN in the Product JSON-LD (0 carry a valid GTIN, 0%).
How: Extract gtin / gtin8 / gtin12 / gtin13 / gtin14 from the first Product JSON-LD node on each PDP; validate digit length.
Coverage
0/20 · 0%
- No valid GTIN on this product pageHIGH× 10
Populate gtin/gtin8/gtin12/gtin13/gtin14 with the manufacturer's barcode.
Affected (10)
- /products/mad-gains-by-mad-science
- /products/protein-water-by-nutra-naturals
- /products/loaded-shaker-by-kamikaze
- /products/everyday-hydration-salts-assorted-sac…
- /products/free-noway-collagen-protein-water-whe…
- /products/kamikaze-energy-rtd-free-gift-by-athl…
- /products/kn-12-live-well-by-kailo-nutrition
- /products/vitamin-d3-k2-by-genetix-nutrition-es…
- /products/tmg-by-genetix-nutrition-essentials
- /products/tudca-by-anabolix-nutrition
…and 1 more
Emit shippingDetails (OfferShippingDetails) on Offer JSON-LD
Why this matters: Without shippingDetails, AI agents fall back to vague defaults — they can't quote your rates, destinations, or delivery windows in shopping cards.
Findings (11)
Inspected shippingDetails on Product/Offer JSON-LD across 20 sampled PDPs (0 present, 0%).
How: On each PDP, locate the Product JSON-LD node and check for shippingDetails (single object or array) at Product or Offer level. Pass band ≥ 85% coverage.
Coverage
0/20 · 0%
- Offer JSON-LD missing
shippingDetailsHIGH× 10Add OfferShippingDetails with shippingRate, shippingDestination, and deliveryTime.
Affected (10)
- /products/mad-gains-by-mad-science
- /products/protein-water-by-nutra-naturals
- /products/loaded-shaker-by-kamikaze
- /products/everyday-hydration-salts-assorted-sac…
- /products/free-noway-collagen-protein-water-whe…
- /products/kamikaze-energy-rtd-free-gift-by-athl…
- /products/kn-12-live-well-by-kailo-nutrition
- /products/vitamin-d3-k2-by-genetix-nutrition-es…
- /products/tmg-by-genetix-nutrition-essentials
- /products/tudca-by-anabolix-nutrition
…and 1 more
Add every required top-level key to the UCP profile
Why this matters: A profile missing one of the four required keys is treated as non-conformant — agent runtimes fall back to default behaviour and may skip the merchant.
Findings (1)
Profile is missing required key(s): signing_keys.
How: Read the profile root (or top-level ucp wrapper) and verify the presence of version, services, capabilities, and signing_keys keys.
- Required top-level key
signing_keysis missingHIGHWhat we expected
Add a top-level "signing_keys" field to the JSON document (empty array/object is fine).Set
signing_keysat the root of the JSON document.
Use a canonical Schema.org availability IRI on every Offer
Why this matters: Agents suppress out-of-stock or ambiguous items; a valid availability URL keeps you eligible.
Findings (4)
Checked Offer availability on 20 sampled product pages with an Offer (16 use a canonical Schema.org URL, 80%).
How: On each Offer, accept availability only if it matches one of the canonical Schema.org ItemAvailability IRIs (http or https, trailing slash optional).
Coverage
16/20 · 80%
- Offer
availabilityis missing or not a canonical Schema.org URLHIGH× 4Use https://schema.org/InStock (or OutOfStock / PreOrder / BackOrder).
Affected (4)
- /products/free-noway-collagen-protein-water-whe…value: InStock
- /products/free-creatine-shaker-when-you-buy-mas…value: InStock
- /products/free-gym-towel-creatine-when-you-buy-…value: InStock
- /products/free-creatine-shaker-when-you-buy-cle…value: InStock
Emit hasMerchantReturnPolicy on Product or Offer JSON-LD
Why this matters: Without the entry-point return-policy node, agents can't render or quote your return terms — they fall back to platform defaults or skip your store.
Findings (4)
Inspected hasMerchantReturnPolicy on Product/Offer JSON-LD across 20 sampled product pages (16 present, 80%).
How: On each PDP, locate the Product JSON-LD node and check for a hasMerchantReturnPolicy object/array at Product level OR Offer level. Pass band ≥ 85% coverage, partial ≥ 50%.
Coverage
16/20 · 80%
- Product JSON-LD missing
hasMerchantReturnPolicyHIGH× 4Add a MerchantReturnPolicy node to Product or Offer with category + applicableCountry (or merchantReturnLink).
Skipped — the runner did not surface transport metadata
Context: If your UCP profile says `no-cache`, agent runtimes re-fetch on every interaction — brittle at scale and prone to rate-limit failures.
Why this was skipped
Wanted to inspect the UCP profile's Cache-Control header, but the runner did not surface transport metadata.
How: Parse the Cache-Control header on the /.well-known/ucp response; require public, max-age ≥ 60, and no no-store/no-cache/private.
- Transport metadata not available — runner update pendingLOW
This check activates once the runner (Task I1) populates ctx.wellKnownUcp.cacheControl.
Skipped — Profile declares no signing_keys; JWK validation has no entries to evaluate.
Context: Malformed JWK entries are rejected silently by agents — signed payloads cannot be verified and the merchant loses trust signal.
Why this was skipped
Profile declares no signing_keys; JWK validation has no entries to evaluate.
How: Walk signing_keys[] and validate each entry per RFC 7517 §4.1 (kty required) + RFC 7518 §6 (kty-specific required parameters). kid is OPTIONAL per RFC 7517 §4.5 and not enforced here.
Add includeSubDomains to your Strict-Transport-Security header
Why this matters: Without includeSubDomains, an HTTP subdomain (staging, mail, …) can be used to attack the apex's cookies.
Findings (1)
Inspected the homepage Strict-Transport-Security header ("max-age=7889238") and the includeSubDomains directive is absent.
How: Parse the homepage Strict-Transport-Security header for the includeSubDomains directive (RFC 6797 §6.1.2).
- HSTS header is missing the includeSubDomains directiveMEDIUM
What we found
max-age=7889238What we expected
Strict-Transport-Security: max-age=31536000; includeSubDomainsAppend
; includeSubDomainsto your STS header once every subdomain you operate supports HTTPS.
Add an Organization (or OnlineStore) JSON-LD block to your homepage with a contactPoint
Why this matters: Organization markup with a contactPoint tells AI agents who you are and how a shopper can reach you for support.
Findings (1)
Parsed the homepage JSON-LD looking for an Organization/OnlineStore node with a contactPoint, but no Organization-class node is present.
How: Parse homepage <script type="application/ld+json"> blocks, flatten @graph, and look for an Organization/OnlineStore/Store node with a contactPoint carrying email or telephone.
- No Organization/OnlineStore JSON-LD on homepageMEDIUM
What we expected
<script type="application/ld+json">{"@context":"https://schema.org","@type":"OnlineStore","name":"Example Store","url":"https://example.com","contactPoint":[{"@type":"ContactPoint","contactType":"customer service","email":"support@example.com"}]}</script>Add an Organization (or OnlineStore) JSON-LD block in the homepage
<head>with a contactPoint.
Populate sku on every Product JSON-LD node
Why this matters: A stable SKU lets agents track and re-identify your product across catalogs.
Findings (4)
Read the sku field on Product JSON-LD across 20 sampled product pages (16 populated, 80%).
How: On each PDP with a Product node, accept sku if it is a non-empty trimmed string or a number.
Coverage
16/20 · 80%
- Product JSON-LD has no populated
skuMEDIUM× 4Fill in the SKU field in your product admin; the JSON-LD template typically binds to that field.
Skipped — No MerchantReturnPolicy node carried `applicableCountry`, so the ISO-code check has nothing to evaluate.
Context: A non-ISO country is dropped silently; the policy looks present but never reaches the merchant-listing rich result.
Why this was skipped
No MerchantReturnPolicy node carried applicableCountry, so the ISO-code check has nothing to evaluate.
How: On each MerchantReturnPolicy node where applicableCountry is set, extract every candidate string and require every one to match /^[A-Z]{2}$/i.
Skipped — No OfferShippingDetails node carried `shippingDestination`, so the DefinedRegion check has nothing to evaluate.
Context: Without a valid destination region, your shipping rate has no scope — Google can't decide whether to render it for a given shopper's country.
Why this was skipped
No OfferShippingDetails node carried shippingDestination, so the DefinedRegion check has nothing to evaluate.
How: On each OfferShippingDetails node where shippingDestination is set, require it to be a DefinedRegion (or array) and every entry to carry addressCountry matching /^[A-Z]{2}$/i.
Skipped — No OfferShippingDetails node carried `shippingRate`, so the MonetaryAmount check has nothing to evaluate.
Context: An invalid rate object is silently dropped; agents can't quote your shipping cost in shopping cards.
Why this was skipped
No OfferShippingDetails node carried shippingRate, so the MonetaryAmount check has nothing to evaluate.
How: On each OfferShippingDetails node where shippingRate is set, require an object with numeric value/maxValue (typed or numeric string) and a 3-letter ISO 4217 currency.
Skipped — Profile declares no capabilities; required-field checks have nothing to evaluate.
Context: Capabilities missing version/spec/schema can't be matched against agent support tables — agents skip them silently.
Why this was skipped
Profile declares no capabilities; required-field checks have nothing to evaluate.
How: For each capabilities[] entry, require non-empty string values for version, spec, and schema.
Use Schema.org enum values for returnFees / returnMethod / refundType
Why this matters: Invalid enrichment values are dropped silently, leaving merchants confused about why their rendered policy is missing fields they configured.
Findings (11)
Validated enrichment enums on 48 MerchantReturnPolicy nodes (0 all-valid, 0%).
How: On each MerchantReturnPolicy node, inspect returnFees/returnMethod/refundType if set; require the bare name or schema.org URL form of a value in the corresponding Schema.org enum.
Coverage
0/48 · 0%
- MerchantReturnPolicy enum field uses an invalid Schema.org valueLOW× 10
What we found
returnMethod="["https://schema.org/ReturnByMail","https://schema.org/ReturnInStore"]"Use the bare enum name or schema.org URL form from the documented enum.
Affected (10)
- /products/mad-gains-by-mad-science
- /products/mad-gains-by-mad-science
- /products/mad-gains-by-mad-science
- /products/mad-gains-by-mad-science
- /products/mad-gains-by-mad-science
- /products/mad-gains-by-mad-science
- /products/mad-gains-by-mad-science
- /products/mad-gains-by-mad-science
- /products/protein-water-by-nutra-naturals
- /products/protein-water-by-nutra-naturals
…and 1 more
Add preload to your Strict-Transport-Security header and submit to hstspreload.org
Why this matters: HSTS preload-list inclusion is the strongest downgrade protection available — first-time visits are protected too.
Findings (1)
Inspected the homepage Strict-Transport-Security header ("max-age=7889238") and the preload directive is absent.
How: Parse the homepage Strict-Transport-Security header for the preload directive (hstspreload.org vendor extension to RFC 6797).
- HSTS header is missing the preload directiveLOW
What we found
max-age=7889238What we expected
Strict-Transport-Security: max-age=31536000; includeSubDomains; preloadAppend
; preloadafterincludeSubDomainsand submit your domain at https://hstspreload.org/.
Add an AggregateRating to Product nodes when you have real reviews
Why this matters: Review ratings are a trust signal agents use to rank and filter products.
Findings (11)
Looked for a valid aggregateRating on Product JSON-LD across 20 sampled product pages (0 valid, 0%).
How: On each Product node, parse aggregateRating (or the first element if it's an array) and require ratingValue in [0,5] AND reviewCount or ratingCount ≥ 1.
Coverage
0/20 · 0%
- Product has no valid AggregateRating (ratingValue 0-5 + reviewCount/ratingCount ≥ 1)LOW× 10
Render
aggregateRatingfrom real review totals — never fabricate.Affected (10)
- /products/mad-gains-by-mad-science
- /products/protein-water-by-nutra-naturals
- /products/loaded-shaker-by-kamikaze
- /products/everyday-hydration-salts-assorted-sac…
- /products/free-noway-collagen-protein-water-whe…
- /products/kamikaze-energy-rtd-free-gift-by-athl…
- /products/kn-12-live-well-by-kailo-nutrition
- /products/vitamin-d3-k2-by-genetix-nutrition-es…
- /products/tmg-by-genetix-nutrition-essentials
- /products/tudca-by-anabolix-nutrition
…and 1 more
Skipped — No OfferShippingDetails node carried `deliveryTime`, so the ShippingDeliveryTime check has nothing to evaluate.
Context: Without populated handling/transit times, agents can't quote a delivery window in shopping cards.
Why this was skipped
No OfferShippingDetails node carried deliveryTime, so the ShippingDeliveryTime check has nothing to evaluate.
How: On each OfferShippingDetails node where deliveryTime is set, require an object with at least one of handlingTime / transitTime populated as a QuantitativeValue.
Enable Apple Pay through your payment processor (informational only)
Why this matters: Apple Pay is a checkout-quality signal for human shoppers — informational only, does not affect the agent-readiness score.
Findings (1)
Scanned the homepage and 20 sampled PDPs for Apple Pay markers; none matched.
How: Substring match on known Apple Pay SDK/markup signatures (ApplePaySession, apple-pay-button, /apple-developer-merchantid-domain-association) across the homepage and every sampled PDP HTML.
- No Apple Pay markers detected on the homepage or PDPsINFO
Enable Apple Pay in your payment processor's dashboard (Stripe / Adyen / Braintree). Informational only — does not affect the score.
Enable Google Pay through your payment processor (informational only)
Why this matters: Google Pay is a checkout-quality signal for human shoppers — informational only, does not affect the agent-readiness score.
Findings (1)
Scanned the homepage and 20 sampled PDPs for Google Pay markers; none matched.
How: Substring match on known Google Pay SDK/markup signatures (pay.google.com/gp/p/js/pay.js, google.payments.api, <google-pay-button) across the homepage and every sampled PDP HTML.
- No Google Pay markers detected on the homepage or PDPsINFO
Enable Google Pay in your payment processor's dashboard (Stripe / Adyen / Braintree). Informational only — does not affect the score.