A

sestogrado.it

Audited 5 days ago· woocommerce

58
Grade D

Agent-readiness across all five AI commerce surfaces.

Surfaces — click to filter

25 failing · 28 not checked · 53 shown

28 checks couldn't run on this store — each is listed below with the reason. Your score reflects only what we could verify.

FAILCRITICAL
Offer price + priceCurrency validoffer-price-currency-validMerchantSchema.org

Set price as a number and priceCurrency as an ISO 4217 code

Why this matters: Agents need a price with a currency to show and compare your product.

Findings (11)

Parsed Offer price and priceCurrency on Product JSON-LD across 19 sampled product pages (0 valid, 0%).

How: Parse Offer price (or AggregateOffer lowPrice) as a parseable numeric price ≥ 0; require priceCurrency to match /^[A-Z]{3}$/i.

Coverage

0/19 · 0%

…and 1 more

How to fix · 2 steps · create a free account to viewCreate a free account →
HALFCRITICAL
HTTPS enforced sitewide + HSTS (≥ 6-month max-age)https-and-hsts-enforcedHSTS

Enforce HTTPS sitewide and ship a Strict-Transport-Security header with max-age ≥ 6 months

Why this matters: AI agents and payment flows refuse plain HTTP; weak HSTS is treated as effectively no HSTS by trust-and-safety scanners.

Findings (1)

Confirmed the homepage is HTTPS (status 200), probed http://sestogrado.it/ for redirect behaviour, and parsed the Strict-Transport-Security header (absent).

How: URL scheme + homepage status check, an http://host/ redirect probe through politeFetch, and a Strict-Transport-Security max-age parse (RFC 6797; ≥ 180-day threshold).

  • No Strict-Transport-Security header on the homepage responseCRITICAL

    /

    Add Strict-Transport-Security: max-age=31536000; includeSubDomains to every HTTPS response.

How to fix · 3 steps · create a free account to viewCreate a free account →
FAILHIGH
Product `image` populatedproduct-image-populatedSchema.orgMerchant

Add a resolvable image URL to every Product node

Why this matters: Agents show your product image in shopping cards; a missing image weakens or drops the listing.

Findings (11)

Read the image field on Product JSON-LD across 19 sampled product pages (6 resolve at least one URL, 32%).

How: Resolve image on each Product node into a list of URL strings (string, array, or ImageObject.url/contentUrl); require at least one non-empty URL.

Coverage

6/19 · 32%

…and 1 more

How to fix · 3 steps · create a free account to viewCreate a free account →
FAILHIGH
Each PDP carries at most one Product JSON-LD nodepdp-single-product-pageMerchant

Emit a single Product JSON-LD node per PDP

Why this matters: Duplicate Product nodes on a single PDP cause Google's merchant scraper to drop the listing or pick the wrong variant.

Findings (5)

Sampled 20 PDP(s); 5 carried multiple Product JSON-LD nodes.

How: For each sampled PDP, count JSON-LD nodes whose @type is Product or whose @type array contains Product. Each PDP must expose at most one.

Coverage

15/20 · 75%

How to fix · 2 steps · create a free account to viewCreate a free account →
FAILHIGH
Terms of service page reachableterms-of-service-page-reachableMerchant

Publish a terms of service page and link it from your site nav/footer

Why this matters: A published ToS is a baseline trust signal AI agents and ad networks use to decide whether to surface or accept a merchant.

Findings (1)

Probed 5 candidate ToS paths (nav-discovered + platform-conventional) and none returned a 2xx body.

How: Discover candidate URLs by scoring homepage nav/footer anchors for terms/tos/legal/conditions keywords, then append platform-conventional paths; probe each with politeFetch and pass on the first 2xx with ≥200 stripped-body chars.

  • No terms-of-service page reachable at any candidate URLHIGH

    statuses: /terms/=404, /terms-conditions/=404, /terms=404, /terms-of-service=404, /policies/terms-of-service=404

    Publish a ToS page at /terms (or your platform's standard slug) with ≥200 chars of body text.

How to fix · 2 steps · create a free account to viewCreate a free account →
FAILHIGH
MerchantReturnPolicy node present on Product or Offermerchant-return-policy-presentReturnsSchema.org

Emit hasMerchantReturnPolicy on Product or Offer JSON-LD

Why this matters: Without the entry-point return-policy node, agents can't render or quote your return terms — they fall back to platform defaults or skip your store.

Findings (11)

Inspected hasMerchantReturnPolicy on Product/Offer JSON-LD across 19 sampled product pages (0 present, 0%).

How: On each PDP, locate the Product JSON-LD node and check for a hasMerchantReturnPolicy object/array at Product level OR Offer level. Pass band ≥ 85% coverage, partial ≥ 50%.

Coverage

0/19 · 0%

…and 1 more

How to fix · 2 steps · create a free account to viewCreate a free account →
FAILHIGH
Offer JSON-LD carries shippingDetails (OfferShippingDetails)offer-shipping-details-presentSchema.orgShipping

Emit shippingDetails (OfferShippingDetails) on Offer JSON-LD

Why this matters: Without shippingDetails, AI agents fall back to vague defaults — they can't quote your rates, destinations, or delivery windows in shopping cards.

Findings (11)

Inspected shippingDetails on Product/Offer JSON-LD across 19 sampled PDPs (0 present, 0%).

How: On each PDP, locate the Product JSON-LD node and check for shippingDetails (single object or array) at Product or Offer level. Pass band ≥ 85% coverage.

Coverage

0/19 · 0%

…and 1 more

How to fix · 2 steps · create a free account to viewCreate a free account →
FAILHIGH
/.well-known/ucp profile is present with a `version` fielducp-profile-presentUCPUCP Profile

Publish /.well-known/ucp with at minimum a version field

Why this matters: Without `/.well-known/ucp`, Google's AI Mode can't identify your storefront as a UCP-conformant merchant.

Findings (1)

Inspected /.well-known/ucp for a parseable JSON document with a top-level version string.

How: Confirm ctx.wellKnownUcp is non-null and carries a non-empty version string (the only universally-required UCP profile field).

  • /.well-known/ucp is not reachable or not parseable as JSONHIGH

    /.well-known/ucp

    Serve a JSON document at /.well-known/ucp with a top-level version string (e.g., "2026-04-08").

How to fix · 2 steps · create a free account to viewCreate a free account →
FAILHIGH
UCP profile carries all four required top-level keysucp-profile-required-keysUCP

Add every required top-level key to the UCP profile

Why this matters: A profile missing one of the four required keys is treated as non-conformant — agent runtimes fall back to default behaviour and may skip the merchant.

Findings (1)

Wanted to inspect UCP root keys, but no profile was found.

How: Read the profile root (or top-level ucp wrapper) and verify the presence of version, services, capabilities, and signing_keys keys.

  • No /.well-known/ucp profile presentHIGH

    /.well-known/ucp

    Publish /.well-known/ucp first (see ucp-profile-present).

How to fix · 2 steps · create a free account to viewCreate a free account →
FAILHIGH
UCP profile declares a valid shopping service entryucp-shopping-service-validUCPUCP Profile

Declare a shopping service entry with a recognised transport and an HTTPS endpoint

Why this matters: Without a valid shopping service entry, agents can recognise you as a UCP merchant but have no way to fetch your catalog.

Findings (1)

Wanted to walk the UCP profile's services[] for a valid shopping entry, but no profile was found.

How: List every services[] entry whose namespace is shopping (or contains shopping) and require at least one with transport ∈ {rest,mcp,a2a,embedded} AND a syntactically valid https:// endpoint.

  • No /.well-known/ucp profile presentHIGH

    /.well-known/ucp

    Publish /.well-known/ucp first (see ucp-profile-present), then declare the shopping service.

How to fix · 2 steps · create a free account to viewCreate a free account →
FAILHIGH
Every signing_keys[] entry is a valid JWKucp-signing-keys-validJWKS

Make every signing_keys[] entry a JWK with kty + kty-specific params

Why this matters: Malformed JWK entries are rejected silently by agents — signed payloads cannot be verified and the merchant loses trust signal.

Findings (1)

Wanted to validate signing_keys[], but no UCP profile was found.

How: Walk signing_keys[] and validate each entry per RFC 7517 §4.1 (kty required) + RFC 7518 §6 (kty-specific required parameters). kid is OPTIONAL per RFC 7517 §4.5 and not enforced here.

  • No /.well-known/ucp profile presentHIGH

    /.well-known/ucp

How to fix · 3 steps · create a free account to viewCreate a free account →
HALFHIGH
Offer `availability` is a Schema.org URLoffer-availability-schema-urlSchema.org

Use a canonical Schema.org availability IRI on every Offer

Why this matters: Agents suppress out-of-stock or ambiguous items; a valid availability URL keeps you eligible.

Findings (6)

Checked Offer availability on 19 sampled product pages with an Offer (13 use a canonical Schema.org URL, 68%).

How: On each Offer, accept availability only if it matches one of the canonical Schema.org ItemAvailability IRIs (http or https, trailing slash optional).

Coverage

13/19 · 68%

How to fix · 2 steps · create a free account to viewCreate a free account →
HALFHIGH
Contact page exposes email or phonecontact-with-email-or-phoneMerchant

Add a mailto: email link or tel: phone link to your contact page

Why this matters: Without an email or phone on your contact page, ChatGPT and Perplexity have no escalation path to surface for shoppers.

Findings (1)

Reached the contact page at https://sestogrado.it/pages/contact but found neither a mailto link, tel link, plain email, nor a phone-shaped number.

How: URL probe of contact paths; the first 2xx body is scanned for mailto: / tel: hrefs, plain emails (placeholder hosts excluded), and phone-shaped numbers.

  • Contact page reachable but exposes no email, phone, mailto, or tel linkHIGH

    /pages/contact

    Add a mailto: link or a tel: link to the page body.

How to fix · 3 steps · create a free account to viewCreate a free account →
HALFHIGH
GTIN coverage on PDPsproduct-gtin-populatedSchema.orgMerchant

Populate gtin on every branded Product node

Why this matters: GTINs let agents match your product to the same item elsewhere; without them you lose cross-catalog matching.

Findings (7)

Checked 20 sampled product pages for a GTIN in the Product JSON-LD (13 carry a valid GTIN, 65%).

How: Extract gtin / gtin8 / gtin12 / gtin13 / gtin14 from the first Product JSON-LD node on each PDP; validate digit length.

Coverage

13/20 · 65%

How to fix · 2 steps · create a free account to viewCreate a free account →
NAHIGH
MerchantReturnPolicy finite-window has positive merchantReturnDaysmerchant-return-policy-finite-daysReturns

Skipped — No MerchantReturnPolicy node used the MerchantReturnFiniteReturnWindow category, so the `merchantReturnDays` check has nothing to evaluate.

Context: AI agents quote your concrete return window in shopping cards. Without `merchantReturnDays`, your policy renders as 'has a return policy' without the headline number.

Why this was skipped

No MerchantReturnPolicy node used the MerchantReturnFiniteReturnWindow category, so the merchantReturnDays check has nothing to evaluate.

How: For each MerchantReturnPolicy node whose returnPolicyCategory normalizes to MerchantReturnFiniteReturnWindow, require merchantReturnDays to be a positive number (or a numeric string > 0).

NAHIGH
MerchantReturnPolicy satisfies Option A (country+category) or B (returnLink)merchant-return-policy-option-a-or-bReturnsSchema.org

Skipped — No PDP carried a `hasMerchantReturnPolicy` node, so Option A/B shape cannot be evaluated.

Context: A policy node missing both shapes is invisible to agents — they can't render it, link to it, or quote your return terms.

Why this was skipped

No PDP carried a hasMerchantReturnPolicy node, so Option A/B shape cannot be evaluated.

How: For each PDP, walk every hasMerchantReturnPolicy node (Product or Offer level) and require either (applicableCountry + returnPolicyCategory) OR a syntactically-valid merchantReturnLink URL.

NAHIGH
UCP profile Cache-Control is shared-cacheable with max-age ≥ 60sucp-cache-headers-validUCP

Skipped — No UCP profile present; Cache-Control policy is not evaluable.

Context: If your UCP profile says `no-cache`, agent runtimes re-fetch on every interaction — brittle at scale and prone to rate-limit failures.

Why this was skipped

No UCP profile present; Cache-Control policy is not evaluable.

How: Parse the Cache-Control header on the /.well-known/ucp response; require public, max-age ≥ 60, and no no-store/no-cache/private.

NAHIGH
/.well-known/ucp response Content-Type is application/jsonucp-profile-content-type-jsonUCP

Skipped — No UCP profile present; Content-Type is not evaluable.

Context: Agent runtimes that gate parsing on Content-Type will skip your profile if it's served as HTML or plain text.

Why this was skipped

No UCP profile present; Content-Type is not evaluable.

How: Check that the Content-Type header on /.well-known/ucp starts with application/json (optionally with a charset parameter).

NAHIGH
/.well-known/ucp is publicly fetchable with no authucp-profile-no-auth-requiredUCP ProfileUCP

Skipped — No UCP profile reachable; public-fetch evaluation deferred to ucp-profile-present.

Context: Agents fetch `/.well-known/ucp` without credentials — a 401 or 403 means they never see the profile.

Why this was skipped

No UCP profile reachable; public-fetch evaluation deferred to ucp-profile-present.

How: Confirm an unauthenticated GET to /.well-known/ucp returns a 2xx status.

NAHIGH
/.well-known/ucp returns 200 directly with no redirectsucp-profile-no-redirectsUCP

Skipped — No UCP profile present; redirect behaviour is not evaluable.

Context: Lightweight agent clients fetch `/.well-known/ucp` without following redirects — a 301/302 means they never see your profile.

Why this was skipped

No UCP profile present; redirect behaviour is not evaluable.

How: Inspect the final HTTP status of GET /.well-known/ucp and whether any 3xx redirect was followed to reach it.

NAHIGH
Each service satisfies the transport-conditional field requirementsucp-service-transport-conditional-fieldsUCP

Skipped — No UCP profile present.

Context: A service declared with the right transport but missing endpoint/schema is unreachable — agents can't negotiate or connect.

Why this was skipped

No UCP profile present.

How: For each services[] entry with a recognised transport, require the transport-conditional fields: rest/mcp → endpoint+schema; a2a → endpoint; embedded → schema.

NAHIGH
Each service `transport` is rest, mcp, a2a, or embeddeducp-service-transport-enumUCP

Skipped — No UCP profile present.

Context: An unrecognised transport leaves agents with no handler to dispatch — your service appears absent.

Why this was skipped

No UCP profile present.

How: For each services[] entry, require transport to be one of: rest, mcp, a2a, embedded.

FAILMEDIUM
Product `sku` populatedproduct-sku-populatedSchema.orgMerchant

Populate sku on every Product JSON-LD node

Why this matters: A stable SKU lets agents track and re-identify your product across catalogs.

Findings (11)

Read the sku field on Product JSON-LD across 19 sampled product pages (0 populated, 0%).

How: On each PDP with a Product node, accept sku if it is a non-empty trimmed string or a number.

Coverage

0/19 · 0%

…and 1 more

How to fix · 2 steps · create a free account to viewCreate a free account →
FAILMEDIUM
Organization/OnlineStore JSON-LD with contactPoint on homepageorganization-jsonld-with-contactSchema.org

Add an Organization (or OnlineStore) JSON-LD block to your homepage with a contactPoint

Why this matters: Organization markup with a contactPoint tells AI agents who you are and how a shopper can reach you for support.

Findings (1)

Found a homepage Organization node but its contactPoint is missing both email and telephone.

How: Parse homepage <script type="application/ld+json"> blocks, flatten @graph, and look for an Organization/OnlineStore/Store node with a contactPoint carrying email or telephone.

  • Homepage Organization node has no contactPoint with email or telephoneMEDIUM

    /

    What we expected

    "contactPoint": [{"@type":"ContactPoint","contactType":"customer service","email":"support@example.com","telephone":"+1-555-123-4567"}]

    Add a contactPoint object with at least one of email or telephone.

How to fix · 3 steps · create a free account to viewCreate a free account →
FAILMEDIUM
Third-party review-platform integration detectedreview-app-detectedSchema.org

Install a third-party review platform so agents see syndicated reviews on your storefront

Why this matters: Third-party review widgets feed the ratings AI agents trust when ranking merchants.

Findings (1)

Scanned the homepage and 20 sampled PDPs for 8 review-platform asset fingerprints; none matched.

How: Substring scan of homepage and sampled PDP HTML for known review-platform asset fingerprints (judge.me, yotpo, stamped.io, reviews.io, okendo, loox, trustpilot, bazaarvoice).

  • No third-party review-platform integration detectedMEDIUM

    none of 8 fingerprints matched across 21 sources

    Install a Judge.me / Yotpo / Loox / Okendo / Stamped / Reviews.io / Trustpilot / Bazaarvoice widget on your storefront.

How to fix · 3 steps · create a free account to viewCreate a free account →
FAILMEDIUM
Sitemap resolvable and includes at least one product URLsitemap-resolvable-with-productsSitemap

Publish a sitemap containing product URLs

Why this matters: A sitemap that omits product URLs forces every crawler into slower, less complete frontier discovery.

Findings (1)

Tried to resolve an XML sitemap from robots.txt (Sitemap: directives) or /sitemap.xml. No entries were returned.

How: Parse <loc> entries from the resolved sitemap (or sitemap index) and classify each against product-URL patterns (/products/..., /product/..., /p/<id>, etc.).

  • No XML sitemap was reachable, or it contained no <loc> entriesMEDIUM

    /sitemap.xml0 entries parsed

    Publish a sitemap at /sitemap.xml that includes one <loc> entry per product.

How to fix · 3 steps · create a free account to viewCreate a free account →
FAILMEDIUM
Returns/refund policy page reachablereturns-policy-page-reachableMerchant

Publish a returns policy page and link it from your site nav/footer

Why this matters: AI agents quote return terms to shoppers; missing returns pages are a baseline trust failure that suppresses you from agentic shopping cards.

Findings (1)

Probed 7 candidate returns-policy paths (nav-discovered + platform-conventional) and none returned a 2xx body.

How: Discover candidate URLs by scoring homepage nav/footer anchors for return/refund/exchange keywords, then append platform-conventional paths; probe each with politeFetch and pass on the first 2xx with ≥200 stripped-body chars.

  • No returns/refund policy page reachable at any candidate URLMEDIUM

    statuses: /refund_returns/=404, /returns/=404, /refund-policy/=404, /returns=404, /refund-policy=404, /return-policy=404, /policies/refund-policy=404

    Publish a returns/refund policy page at /returns (or your platform's standard slug) with ≥200 chars of body text.

How to fix · 2 steps · create a free account to viewCreate a free account →
FAILMEDIUM
Shipping policy page reachableshipping-policy-page-reachableMerchant

Publish a shipping policy page and link it from your site nav/footer

Why this matters: Agents quote shipping terms to shoppers; without a reachable shipping policy they fall back to vague defaults or skip your store.

Findings (1)

Probed 6 candidate shipping-policy paths (nav-discovered + platform-conventional) and none returned a 2xx body.

How: Discover candidate URLs by scoring homepage nav/footer anchors for shipping/delivery/dispatch keywords, then append platform-conventional paths; probe each with politeFetch and pass on the first 2xx with ≥200 stripped-body chars.

  • No shipping policy page reachable at any candidate URLMEDIUM

    statuses: /shipping-policy/=404, /shipping/=404, /shipping=404, /shipping-policy=404, /policies/shipping-policy=404, /pages/shipping=404

    Publish a shipping policy page at /shipping-policy (or your platform's standard slug) with ≥200 chars of body text and link it from your footer.

How to fix · 2 steps · create a free account to viewCreate a free account →
HALFMEDIUM
Sitemap declared in robots.txtsitemap-declared-in-robotsSitemap

Add a Sitemap: line to robots.txt

Why this matters: Declaring the sitemap in robots.txt is the simplest way to point every crawler at your full product list.

Findings (1)

Read robots.txt and looked for a Sitemap: directive; none were declared.

How: Read parsed Sitemap: directives from robots.txt (sitemaps.org / RFC 9309 implementation note).

  • robots.txt has no Sitemap: directiveMEDIUM

    /robots.txt0 Sitemap: lines parsed

    What we expected

    Sitemap: https://yourdomain.com/sitemap.xml

    Add a top-level Sitemap: line pointing at your XML sitemap (or sitemap index).

How to fix · 2 steps · create a free account to viewCreate a free account →
NAMEDIUM
HSTS policy carries the includeSubDomains directivehsts-include-subdomainsHSTS

Skipped — HSTS itself is not enabled

Context: Without includeSubDomains, an HTTP subdomain (staging, mail, …) can be used to attack the apex's cookies.

Why this was skipped

Looked for includeSubDomains in the Strict-Transport-Security header, but HSTS itself is not enabled.

How: Parse the homepage Strict-Transport-Security header for the includeSubDomains directive (RFC 6797 §6.1.2).

  • HSTS not enabled; check https-and-hsts-enforced first.MEDIUM

    /

    Fix https-and-hsts-enforced first — once HSTS ships, re-run this check.

NAMEDIUM
MerchantReturnPolicy merchantReturnLink URL is reachablemerchant-return-link-reachableReturns

Skipped — No MerchantReturnPolicy node carried a `merchantReturnLink` URL, so reachability has nothing to evaluate.

Context: A broken return-link makes Option B policies invisible — agents can't render or follow the link.

Why this was skipped

No MerchantReturnPolicy node carried a merchantReturnLink URL, so reachability has nothing to evaluate.

How: Collect every unique merchantReturnLink URL across all MerchantReturnPolicy nodes; probe each once via politeFetch (failSoft). 2xx counts as reachable.

NAMEDIUM
MerchantReturnPolicy applicableCountry uses ISO 3166-1 alpha-2 codesmerchant-return-policy-applicable-country-isoReturns

Skipped — No MerchantReturnPolicy node carried `applicableCountry`, so the ISO-code check has nothing to evaluate.

Context: A non-ISO country is dropped silently; the policy looks present but never reaches the merchant-listing rich result.

Why this was skipped

No MerchantReturnPolicy node carried applicableCountry, so the ISO-code check has nothing to evaluate.

How: On each MerchantReturnPolicy node where applicableCountry is set, extract every candidate string and require every one to match /^[A-Z]{2}$/i.

NAMEDIUM
MerchantReturnPolicy returnPolicyCategory uses valid Schema.org enummerchant-return-policy-category-enumReturns

Skipped — No MerchantReturnPolicy node carried `returnPolicyCategory`, so the enum check has nothing to evaluate.

Context: An invalid category is silently dropped — your policy looks present in the source but never renders in Google's return-policy rich result.

Why this was skipped

No MerchantReturnPolicy node carried returnPolicyCategory, so the enum check has nothing to evaluate.

How: On each MerchantReturnPolicy node where returnPolicyCategory is set, accept the bare enum name or the schema.org URL form; reject any other string.

NAMEDIUM
OfferShippingDetails shippingDestination is a valid DefinedRegionoffer-shipping-destination-validShipping

Skipped — No OfferShippingDetails node carried `shippingDestination`, so the DefinedRegion check has nothing to evaluate.

Context: Without a valid destination region, your shipping rate has no scope — Google can't decide whether to render it for a given shopper's country.

Why this was skipped

No OfferShippingDetails node carried shippingDestination, so the DefinedRegion check has nothing to evaluate.

How: On each OfferShippingDetails node where shippingDestination is set, require it to be a DefinedRegion (or array) and every entry to carry addressCountry matching /^[A-Z]{2}$/i.

NAMEDIUM
OfferShippingDetails shippingRate is a valid MonetaryAmountoffer-shipping-rate-validShipping

Skipped — No OfferShippingDetails node carried `shippingRate`, so the MonetaryAmount check has nothing to evaluate.

Context: An invalid rate object is silently dropped; agents can't quote your shipping cost in shopping cards.

Why this was skipped

No OfferShippingDetails node carried shippingRate, so the MonetaryAmount check has nothing to evaluate.

How: On each OfferShippingDetails node where shippingRate is set, require an object with numeric value/maxValue (typed or numeric string) and a 3-letter ISO 4217 currency.

NAMEDIUM
Sitemap <loc> entries are entity-escapedsitemap-entries-escapedSitemap

Skipped — the runner did not surface any sitemap resources

Context: Unescaped `&` is the single most common cause of sitemap parse errors that drop product URLs silently.

Why this was skipped

Wanted to inspect sampled <loc> entries for entity escaping, but the runner did not surface any sitemap resources.

How: Sample the first 100 <loc> entries per sitemap document and check for raw &, <, or > (sitemaps.org entity escaping rules).

  • Transport metadata not available — runner update pendingLOW

    /sitemap.xml

NAMEDIUM
Sitemap entries share the host of the containing sitemapsitemap-same-hostSitemap

Skipped — the runner did not surface any sitemap resources

Context: Cross-host sitemap entries are silently dropped, so the off-host product URLs effectively don't exist for the crawler.

Why this was skipped

Wanted to compare sitemap entry hosts against the containing sitemap, but the runner did not surface any sitemap resources.

How: For each resolved sitemap resource, parse the sitemap URL's host and compare it against every parsed <loc> URL's host.

  • Transport metadata not available — runner update pendingLOW

    /sitemap.xml

NAMEDIUM
Sitemap root declares the sitemaps.org 0.9 namespacesitemap-urlset-namespaceSitemap

Skipped — the runner did not surface any sitemap resources

Context: Schema-validating crawlers reject sitemaps with a missing or wrong namespace.

Why this was skipped

Wanted to check the xmlns declaration on every resolved sitemap document, but the runner did not surface any sitemap resources.

How: Substring-match xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" against the raw XML of every resolved sitemap document.

  • Transport metadata not available — runner update pendingLOW

    /sitemap.xml

NAMEDIUM
Each capability has version + spec + schemaucp-capability-required-fieldsUCP

Skipped — No UCP profile present.

Context: Capabilities missing version/spec/schema can't be matched against agent support tables — agents skip them silently.

Why this was skipped

No UCP profile present.

How: For each capabilities[] entry, require non-empty string values for version, spec, and schema.

NAMEDIUM
Each service's `spec` URL origin matches its namespace authorityucp-service-spec-url-origin-matchesUCP

Skipped — No UCP profile present.

Context: A spec URL on an unrelated authority signals the service was copy-pasted from stale documentation — agents can't trust the conformance claim.

Why this was skipped

No UCP profile present.

How: For each service with a spec URL, require the URL origin to be a canonical UCP authority OR the host/path to include the namespace token.

NAMEDIUM
Every service `version` matches YYYY-MM-DDucp-service-version-date-formatUCP

Skipped — No UCP profile present; service version formats are not evaluable.

Context: Free-form version labels like `1.0` or `latest` defeat the version-pinning agents rely on, leaving them unable to negotiate the correct spec generation.

Why this was skipped

No UCP profile present; service version formats are not evaluable.

How: For each services[] entry, require version to be a string matching /^\d{4}-\d{2}-\d{2}$/.

FAILLOW
Product `aggregateRating` presentproduct-aggregate-rating-presentSchema.org

Add an AggregateRating to Product nodes when you have real reviews

Why this matters: Review ratings are a trust signal agents use to rank and filter products.

Findings (11)

Looked for a valid aggregateRating on Product JSON-LD across 19 sampled product pages (1 valid, 5%).

How: On each Product node, parse aggregateRating (or the first element if it's an array) and require ratingValue in [0,5] AND reviewCount or ratingCount ≥ 1.

Coverage

1/19 · 5%

…and 1 more

How to fix · 2 steps · create a free account to viewCreate a free account →
FAILLOW
About page reachable with substantive copyabout-page-reachableMerchant

Publish a substantive About page at a standard URL

Why this matters: Perplexity and ChatGPT use About-page text to summarise your brand to shoppers in answer responses.

Findings (1)

Probed 5 candidate About-page paths and none returned a 2xx body.

How: URL probe of platform-specific about-page paths via politeFetch; the first 2xx response whose HTML-stripped body length is ≥ 200 chars counts as a pass.

  • No About page reachable at any standard URLLOW

    statuses: /about/=404, /about-us/=404, /about=404, /about-us=404, /pages/about=404

    Publish an About page at /about (or your platform's standard path) with ≥ 200 chars of body text.

How to fix · 3 steps · create a free account to viewCreate a free account →
NALOW
HSTS policy carries the preload directivehsts-preload-directiveHSTS

Skipped — HSTS itself is not enabled

Context: HSTS preload-list inclusion is the strongest downgrade protection available — first-time visits are protected too.

Why this was skipped

Looked for the preload directive in the Strict-Transport-Security header, but HSTS itself is not enabled.

How: Parse the homepage Strict-Transport-Security header for the preload directive (hstspreload.org vendor extension to RFC 6797).

  • HSTS not enabled; check https-and-hsts-enforced first.LOW

    /

    Fix https-and-hsts-enforced first — once HSTS ships, re-run this check.

NALOW
MerchantReturnPolicy enrichment enums use valid Schema.org valuesmerchant-return-policy-enums-validReturns

Skipped — No MerchantReturnPolicy node carried returnFees, returnMethod, or refundType, so the enum check has nothing to evaluate.

Context: Invalid enrichment values are dropped silently, leaving merchants confused about why their rendered policy is missing fields they configured.

Why this was skipped

No MerchantReturnPolicy node carried returnFees, returnMethod, or refundType, so the enum check has nothing to evaluate.

How: On each MerchantReturnPolicy node, inspect returnFees/returnMethod/refundType if set; require the bare name or schema.org URL form of a value in the corresponding Schema.org enum.

NALOW
OfferShippingDetails deliveryTime is a valid ShippingDeliveryTimeoffer-shipping-delivery-time-validShipping

Skipped — No OfferShippingDetails node carried `deliveryTime`, so the ShippingDeliveryTime check has nothing to evaluate.

Context: Without populated handling/transit times, agents can't quote a delivery window in shopping cards.

Why this was skipped

No OfferShippingDetails node carried deliveryTime, so the ShippingDeliveryTime check has nothing to evaluate.

How: On each OfferShippingDetails node where deliveryTime is set, require an object with at least one of handlingTime / transitTime populated as a QuantitativeValue.

NALOW
Every sitemap <loc> URL is under 2048 characterssitemap-loc-under-2048Sitemap

Skipped — the runner did not surface any sitemap resources

Context: Strict crawlers drop over-cap URLs without surfacing the error, so over-cap product entries effectively vanish.

Why this was skipped

Wanted to check <loc> URL lengths across every resolved sitemap document, but the runner did not surface any sitemap resources.

How: Iterate every parsed <loc> URL across all resolved sitemap resources and check length against the 2,048-character cap.

  • Transport metadata not available — runner update pendingLOW

    /sitemap.xml

NALOW
Sitemap respects 50 MiB / 50,000-URL caps per documentsitemap-size-limitsSitemap

Skipped — the runner did not surface any sitemap resources

Context: Over-cap sitemaps are silently dropped — neither byte overflow nor entry overflow surfaces a crawler error.

Why this was skipped

Wanted to verify each sitemap's byte size and entry count against sitemaps.org caps, but the runner did not surface any sitemap resources.

How: Check raw byte size (≤ 52,428,800 B) and entry count (≤ 50,000) for every resolved sitemap resource.

  • Transport metadata not available — runner update pendingLOW

    /sitemap.xml

NALOW
Sitemap is served as UTF-8sitemap-utf8Sitemap

Skipped — the runner did not surface any sitemap resources with transport metadata

Context: Non-UTF-8 sitemaps are silently dropped by Search Console and trip default XML parsers used by other crawlers.

Why this was skipped

Wanted to check the encoding of every resolved sitemap document, but the runner did not surface any sitemap resources with transport metadata.

How: Inspect every resolved sitemap document's raw byte stream for UTF-8 decodability (sitemaps.org encoding requirement).

  • Transport metadata not available — runner update pendingLOW

    /sitemap.xml

    This check activates once the runner (Task I1) populates ctx.sitemapResources with raw bytes + headers.

NALOW
UCP MCP-transport entries have valid HTTPS endpointsucp-mcp-transport-validUCP

Skipped — No UCP profile found; MCP transport validity is not evaluable.

Context: If you advertise MCP transport, agents will try to connect — broken or non-HTTPS endpoints fail silently and lose the integration.

Why this was skipped

No UCP profile found; MCP transport validity is not evaluable.

How: Filter services[] to entries where transport=mcp and validate that endpoint is an absolute https:// URL.

FAILINFO
Apple Pay markers detected (informational)apple-pay-detectedSchema.org

Enable Apple Pay through your payment processor (informational only)

Why this matters: Apple Pay is a checkout-quality signal for human shoppers — informational only, does not affect the agent-readiness score.

Findings (1)

Scanned the homepage and 20 sampled PDPs for Apple Pay markers; none matched.

How: Substring match on known Apple Pay SDK/markup signatures (ApplePaySession, apple-pay-button, /apple-developer-merchantid-domain-association) across the homepage and every sampled PDP HTML.

  • No Apple Pay markers detected on the homepage or PDPsINFO

    /

    Enable Apple Pay in your payment processor's dashboard (Stripe / Adyen / Braintree). Informational only — does not affect the score.

How to fix · 3 steps · create a free account to viewCreate a free account →
FAILINFO
Google Pay markers detected (informational)google-pay-detectedSchema.org

Enable Google Pay through your payment processor (informational only)

Why this matters: Google Pay is a checkout-quality signal for human shoppers — informational only, does not affect the agent-readiness score.

Findings (1)

Scanned the homepage and 20 sampled PDPs for Google Pay markers; none matched.

How: Substring match on known Google Pay SDK/markup signatures (pay.google.com/gp/p/js/pay.js, google.payments.api, <google-pay-button) across the homepage and every sampled PDP HTML.

  • No Google Pay markers detected on the homepage or PDPsINFO

    /

    Enable Google Pay in your payment processor's dashboard (Stripe / Adyen / Braintree). Informational only — does not affect the score.

How to fix · 3 steps · create a free account to viewCreate a free account →
NAINFO
llms.txt present (informational)llms-txt-presentllms.txt

Skipped — Looked for /llms.txt at the site root; the fetcher returned no file.

Context: An /llms.txt manifest points agents at your feed and key pages without them having to guess.

Why this was skipped

Looked for /llms.txt at the site root; the fetcher returned no file.

How: Check whether the fetcher reached an /llms.txt at the site root. Informational only — no failure path per llmstxt.org being a voluntary community convention.

Engine 2.0.0 · ACP 2026-04-17 · UCP 2026-04-08

Get notified when this score drops.

Paid plans auto-rescan your store weekly and email you when anything changes — incl. when ACP/UCP ships a new spec.

See plans · from $29/mo →