Can agents find your site and its capabilities?
The page registers no tools via the WebMCP browser API (navigator.modelContext).
Fix: Expose your actions to AI agents with the WebMCP browser API: register tools via navigator.modelContext.registerTool. Optionally also publish a /.well-known/webmcp.json tool catalog as a discovery signpost.
Crawled 1 of 12 discovered pages beyond the homepage.
Could not identify a known website platform (custom stack or unrecognised).
Can agents understand your content?
Homepage returned 403 — couldn't analyse structure.
Homepage returned 403 for Accept: text/markdown.
Homepage returned 403.
All 1 reachable key pages have both a <title> and <h1>.
All 1 pages return ≥80 words of visible text without JavaScript.
Can agents actually operate the page?
Lighthouse flagged this audit — agents may be unable to perceive or operate the affected elements.
Fix: Remove ARIA attributes that aren't allowed on the element's role.
Lighthouse flagged this audit — agents may be unable to perceive or operate the affected elements.
Fix: Don't place focusable/interactive elements inside aria-hidden="true" containers.
The page registers no tools via the navigator.modelContext browser API, so an AI agent has no structured way to operate it.
Fix: Expose your site’s actions to AI agents with the WebMCP browser API: call navigator.modelContext.registerTool({ name, description, inputSchema, execute }) from your page so an agent can invoke them. Implement it directly, or with a library like the @mcp-b polyfill (https://mcp-b.ai). Spec: https://github.com/webmachinelearning/webmcp.
2 of 13 agent-critical accessibility audits failed (`[aria-*]` attributes do not match their roles, `[aria-hidden="true"]` elements contain focusable descendents) — an agent may be unable to identify or operate the affected elements.
Fix: Fix the failing agent-accessibility audits listed below (accessible names on controls, valid ARIA roles/relationships, nothing interactive hidden from the tree).
Lighthouse accessibility score: 82/100. Agents read the page through its accessibility tree, so this is a proxy for how navigable your site is to an AI agent.
Fix: Resolve the failing accessibility audits below — each one removes an element or relationship an agent would otherwise be blind to.
`button`, `link`, and `menuitem` elements have accessible names passed.
`[aria-hidden="true"]` is not present on the document `<body>` passed.
`[role]`s have all required `[aria-*]` attributes passed.
Elements with an ARIA `[role]` that require children to contain a specific `[role]` have all required children. passed.
`[role]`s are contained by their required parent element passed.
`[role]` values are valid passed.
`[aria-*]` attributes are valid and not misspelled passed.
`[aria-*]` attributes have valid values passed.
Buttons have an accessible name passed.
Document has a `<title>` element passed.
Links have a discernible name passed.
0.030 (field data from CrUX) — good.
409ms (field data from CrUX) — good.
No tool catalog was found at /.well-known/webmcp.json (or /.well-known/webmcp). The catalog is a community convention, not part of the WebMCP standard, so this does not affect WebMCP presence.
Fix: Consider also publishing a tool catalog at /.well-known/webmcp.json: a JSON document with a "spec" of "webmcp/0.1" and a "tools" array, where each tool declares a name and a clear description. It is a community convention (optional, not part of the WebMCP standard) that lets crawlers and agents discover your tools without executing JavaScript.
Can agents safely transact?
/.well-known/oauth-authorization-server returned 403.
Fix: Publish /.well-known/oauth-authorization-server so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
/.well-known/oauth-protected-resource returned 403.
Fix: Publish /.well-known/oauth-protected-resource so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
Homepage returned 403.
Homepage returned 403 — couldn't scan for error markers.
Homepage returned 403 — couldn't scan for mixed content.
cf-ray: a1eae2f50974339e-AMS (Cloudflare); Server: cloudflare
CSP header present.
max-age=31536000, includeSubDomains=true, preload=false.
Homepage scheme is https:.
http://hims.com → https://www.hims.com/ (2 hops).
Referrer-Policy: same-origin.
Valid for 49 more days (Sep 9 05:13:36 2026 GMT, issuer: YR1).
Server / X-Powered-By headers don't leak product version.
X-Content-Type-Options: nosniff.
X-Frame-Options: SAMEORIGIN.