Can agents find your site and its capabilities?
The page registers no tools via the WebMCP browser API (navigator.modelContext).
Fix: Expose your actions to AI agents with the WebMCP browser API: register tools via navigator.modelContext.registerTool. Optionally also publish a /.well-known/webmcp.json tool catalog as a discovery signpost.
Crawled 1 of 12 discovered pages beyond the homepage.
Lighthouse Agentic Browsing audits ran.
Could not identify a known website platform (custom stack or unrecognised).
Can agents understand your content?
Only 8 of 11 images have alt attributes (73%).
Fix: Add alt text to every <img>. Screen readers and AI vision models both rely on it to caption images.
No semantic landmark elements (main, header, footer, nav) detected on the homepage.
Fix: Wrap your page structure in semantic landmarks. AI structural extractors rely on them to separate navigation from content from boilerplate.
No <h1> tag found on the homepage.
Fix: Add exactly one <h1> that names the page. AI summarisers use it as the document title.
Homepage ignored Accept: text/markdown and returned HTML.
Fix: Serve a markdown version of high-value pages when the client asks for text/markdown. AI summarisers, chatbots and IDE agents prefer markdown — fewer tokens, no DOM noise.
Only 3/11 images have width+height — large CLS risk.
Fix: Set width and height on every <img> so the browser reserves space before the image loads. A layout that shifts while loading makes an AI agent mis-click the element it targeted.
1 of 1 pages are missing <title> and/or <h1>: /sitemap.ashx.
Fix: Make sure every page sets a unique <title> and exactly one <h1>. The title is how an AI agent confirms it landed on the right page after navigating.
Homepage server response contains 254 words of visible text — content is reachable without executing JavaScript.
Detected 1 cookie-banner element but none look agent-hostile (small, dismissible, or offer a reject option).
Homepage contains ~478 elements.
7 headings, no level skips.
Language declared as "nl".
10 internal links found.
All 1 pages return ≥80 words of visible text without JavaScript.
Can agents actually operate the page?
A well-formed [accessibility tree](http://goo.gle/lighthouse-agentic-a11y) helps AI agents to navigate and interact with the page.
2.05s (field data from CrUX) — poor.
Fix: Every request an AI agent makes pays this server latency, and agents make many requests per task. Reduce TTFB with edge caching, a CDN, and shipping less server-side work per request.
The page registers no tools via the navigator.modelContext browser API, so an AI agent has no structured way to operate it.
Fix: Expose your site’s actions to AI agents with the WebMCP browser API: call navigator.modelContext.registerTool({ name, description, inputSchema, execute }) from your page so an agent can invoke them. Implement it directly, or with a library like the @mcp-b polyfill (https://mcp-b.ai). Spec: https://github.com/webmachinelearning/webmcp.
No autocomplete attributes on any data-collecting form field.
Fix: Add autocomplete hints (email, tel, name, etc.) so form-filling agents and browsers can populate fields without guessing.
0/1 data-collecting forms expose errors via ARIA attributes.
Fix: Wire inputs to their error containers with `aria-describedby` and toggle `aria-invalid` on validation failure. Agents that can't see styled error text rely on these attributes.
0.173
All 15 agent-critical accessibility audits passed — an agent can perceive and operate the page through its accessibility tree.
`[aria-*]` attributes match their roles passed.
Uses ARIA roles only on compatible elements passed.
`[aria-hidden="true"]` is not present on the document `<body>` passed.
`[aria-hidden="true"]` elements do not contain focusable descendents passed.
`[role]`s have all required `[aria-*]` attributes passed.
Elements with an ARIA `[role]` that require children to contain a specific `[role]` have all required children. passed.
`[role]`s are contained by their required parent element passed.
`[role]` values are valid passed.
ARIA toggle fields have accessible names passed.
`[aria-*]` attributes are valid and not misspelled passed.
`[aria-*]` attributes have valid values passed.
Buttons have an accessible name passed.
Document has a `<title>` element passed.
Input buttons have discernible text. passed.
Links have a discernible name passed.
Lighthouse accessibility score: 97/100. Agents read the page through its accessibility tree, so this is a proxy for how navigable your site is to an AI agent.
15 of 15 visible interactive form fields have labels.
1/1 data-collecting forms mark required fields.
All 1 data-collecting forms include pattern/min/max constraints.
0.010 (field data from CrUX) — good.
6 forms missing annotations
Lists the [WebMCP tools](http://goo.gle/webmcp-docs) registered at the time of analysis.
No tool catalog was found at /.well-known/webmcp.json (or /.well-known/webmcp). The catalog is a community convention, not part of the WebMCP standard, so this does not affect WebMCP presence.
Fix: Consider also publishing a tool catalog at /.well-known/webmcp.json: a JSON document with a "spec" of "webmcp/0.1" and a "tools" array, where each tool declares a name and a clear description. It is a community convention (optional, not part of the WebMCP standard) that lets crawlers and agents discover your tools without executing JavaScript.
Can agents safely transact?
Found 1 http:// reference in the homepage HTML — browsers will block these resources.
Fix: Update every http:// resource URL to https:// (or use protocol-relative `//`). Common offenders: image CDNs and legacy embed snippets.
/.well-known/oauth-authorization-server returned 404.
Fix: Publish /.well-known/oauth-authorization-server so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
/.well-known/oauth-protected-resource returned 404.
Fix: Publish /.well-known/oauth-protected-resource so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
No Web Bot Auth signature headers — sites can't verify agent identity.
Fix: Web Bot Auth (IETF HTTP Message Signatures over Signature / Signature-Input) lets you cryptographically verify which agent is hitting you. Several CDNs offer turn-key support; otherwise skip until vendor support matures.
No Content-Security-Policy header on the homepage.
Fix: Add a Content-Security-Policy. Even a strict default-src directive cuts XSS blast radius dramatically. Start in report-only mode to find violations.
HSTS max-age=15552000 is below six months.
Fix: Raise max-age to at least 15768000 (six months). The HSTS preload list requires 31536000 (one year).
No `X-Content-Type-Options: nosniff` header.
Fix: Add `X-Content-Type-Options: nosniff` to prevent browsers (and some agents) from re-interpreting your responses as a different content type.
x-akamai-transformed: 9l - 0 pmb=mRUM,2 (Akamai)
Homepage scheme is https:.
http://aa.com → https://www.american-airlines.nl/intl/nl/index.jsp (5 hops).
No stack-trace markers in the first 5KB.
Referrer-Policy: strict-origin-when-cross-origin.
Valid for 96 more days (Oct 25 23:59:59 2026 GMT, issuer: Entrust OV TLS Issuing ECC CA 2).
Server / X-Powered-By headers don't leak product version.
X-Frame-Options: SAMEORIGIN.