Can agents find your site and its capabilities?
Per llmstxt.org, group key pages under "## Section" headings as "[name](url)" links.
Fix: Add "## Docs" / "## Products" sections listing your key pages as markdown links.
Found https://americanas.com.br/llms.txt.
Found a "> summary" blockquote.
First line is a top-level "# Title" heading.
Crawled 12 of 12 discovered pages beyond the homepage.
Could not identify a known website platform (custom stack or unrecognised).
Can agents understand your content?
Homepage ignored Accept: text/markdown and returned HTML.
Fix: Serve a markdown version of high-value pages when the client asks for text/markdown. AI summarisers, chatbots and IDE agents prefer markdown — fewer tokens, no DOM noise.
Missing landmark elements: main, footer.
2 of 12 pages are missing <title> and/or <h1>: /mueller, /popcorners.
Fix: Make sure every page sets a unique <title> and exactly one <h1>. The title is how an AI agent confirms it landed on the right page after navigating.
Homepage server response contains 140 words of visible text — content is reachable without executing JavaScript.
Homepage contains ~507 elements.
1 headings, no level skips.
Language declared as "pt-BR".
47 of 47 <img> tags have alt attributes.
47/47 images set width and height — no layout shift.
45 internal links found.
Exactly one <h1> on the homepage.
All 12 pages return ≥80 words of visible text without JavaScript.
Can agents actually operate the page?
All 15 agent-critical accessibility audits passed — an agent can perceive and operate the page through its accessibility tree.
`[aria-*]` attributes match their roles passed.
Uses ARIA roles only on compatible elements passed.
`button`, `link`, and `menuitem` elements have accessible names passed.
`[aria-hidden="true"]` is not present on the document `<body>` passed.
`[aria-hidden="true"]` elements do not contain focusable descendents passed.
`[role]`s have all required `[aria-*]` attributes passed.
Elements with an ARIA `[role]` that require children to contain a specific `[role]` have all required children. passed.
`[role]`s are contained by their required parent element passed.
`[role]` values are valid passed.
`[aria-*]` attributes are valid and not misspelled passed.
`[aria-*]` attributes have valid values passed.
Buttons have an accessible name passed.
Document has a `<title>` element passed.
ARIA IDs are unique passed.
Links have a discernible name passed.
Lighthouse accessibility score: 94/100. Agents read the page through its accessibility tree, so this is a proxy for how navigable your site is to an AI agent.
4 of 4 visible interactive form fields have labels.
0.090 (field data from CrUX) — good.
310ms (field data from CrUX) — good.
No tool catalog was found at /.well-known/webmcp.json (or /.well-known/webmcp). The catalog is a community convention, not part of the WebMCP standard, so this does not affect WebMCP presence.
Fix: Consider also publishing a tool catalog at /.well-known/webmcp.json: a JSON document with a "spec" of "webmcp/0.1" and a "tools" array, where each tool declares a name and a clear description. It is a community convention (optional, not part of the WebMCP standard) that lets crawlers and agents discover your tools without executing JavaScript.
Can agents safely transact?
No Strict-Transport-Security header on the homepage.
Fix: Add `Strict-Transport-Security: max-age=15768000; includeSubDomains` so browsers and agents refuse to downgrade to http for at least six months.
/.well-known/oauth-authorization-server returned 404.
Fix: Publish /.well-known/oauth-authorization-server so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
/.well-known/oauth-protected-resource returned 404.
Fix: Publish /.well-known/oauth-protected-resource so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
No Web Bot Auth signature headers — sites can't verify agent identity.
Fix: Web Bot Auth (IETF HTTP Message Signatures over Signature / Signature-Input) lets you cryptographically verify which agent is hitting you. Several CDNs offer turn-key support; otherwise skip until vendor support matures.
No Content-Security-Policy header on the homepage.
Fix: Add a Content-Security-Policy. Even a strict default-src directive cuts XSS blast radius dramatically. Start in report-only mode to find violations.
No Referrer-Policy header on the homepage.
Fix: Add `Referrer-Policy: strict-origin-when-cross-origin` so outbound links don't leak full URLs (including query strings) to third parties.
No `X-Content-Type-Options: nosniff` header.
Fix: Add `X-Content-Type-Options: nosniff` to prevent browsers (and some agents) from re-interpreting your responses as a different content type.
No X-Frame-Options header and no CSP frame-ancestors directive.
Fix: Add `X-Frame-Options: SAMEORIGIN` (or a CSP frame-ancestors directive) to prevent your site being framed by a phishing host.
x-amz-cf-id: b43O5SL83udWqbPuxHJd0zbOfiDgpzA3a0s6qB9K (AWS CloudFront)
Homepage scheme is https:.
http://americanas.com.br → https://www.americanas.com.br/ (1 hop).
No stack-trace markers in the first 5KB.
Homepage HTML references no http:// resources.
Valid for 184 more days (Jan 21 18:10:54 2027 GMT, issuer: Go Daddy Secure Certificate Authority - G2).
Server / X-Powered-By headers don't leak product version.