Can agents find your site and its capabilities?
The page registers no tools via the WebMCP browser API (navigator.modelContext).
Fix: Expose your actions to AI agents with the WebMCP browser API: register tools via navigator.modelContext.registerTool. Optionally also publish a /.well-known/webmcp.json tool catalog as a discovery signpost.
Per llmstxt.org, follow the H1 with a "> short summary" blockquote.
Fix: Add a "> One-sentence description of your site." blockquote under the H1.
Per llmstxt.org, /llms.txt should open with a single "# Project name" H1.
Fix: Make the first line of /llms.txt a "# Your site name" H1.
Found https://hotmart.com/llms.txt.
Found at least one "[name](url)" markdown link.
Crawled 12 of 12 discovered pages beyond the homepage.
Could not identify a known website platform (custom stack or unrecognised).
Can agents understand your content?
No lang attribute on <html>.
Fix: Add lang to the <html> root (e.g. lang="en") so screen readers and AI translation engines pick the right voice / model.
Homepage ignored Accept: text/markdown and returned HTML.
Fix: Serve a markdown version of high-value pages when the client asks for text/markdown. AI summarisers, chatbots and IDE agents prefer markdown — fewer tokens, no DOM noise.
Missing landmark elements: footer.
5 of 12 pages are missing <title> and/or <h1>: /social-midia, /home-dobra-provas-sociais, /comunidades, /afiliados, /patrocine.
Fix: Make sure every page sets a unique <title> and exactly one <h1>. The title is how an AI agent confirms it landed on the right page after navigating.
2 of 12 pages return <80 words of visible text — agents without JavaScript see an empty page: /home-dobra-provas-sociais (33w), /afiliados (33w).
Fix: Pre-render or server-render these pages so AI crawlers (which usually don't execute JS) can read them. Frameworks: Next.js Server Components, Nuxt SSR, Astro, or build-time prerendering.
Homepage server response contains 1338 words of visible text — content is reachable without executing JavaScript.
Homepage contains ~789 elements.
20 headings, no level skips.
14 of 14 <img> tags have alt attributes.
14/14 images set width and height — no layout shift.
27 internal links found.
Exactly one <h1> on the homepage.
Can agents actually operate the page?
The page registers no tools via the navigator.modelContext browser API, so an AI agent has no structured way to operate it.
Fix: Expose your site’s actions to AI agents with the WebMCP browser API: call navigator.modelContext.registerTool({ name, description, inputSchema, execute }) from your page so an agent can invoke them. Implement it directly, or with a library like the @mcp-b polyfill (https://mcp-b.ai). Spec: https://github.com/webmachinelearning/webmcp.
All 11 agent-critical accessibility audits passed — an agent can perceive and operate the page through its accessibility tree.
`[aria-*]` attributes match their roles passed.
`[aria-hidden="true"]` is not present on the document `<body>` passed.
`[aria-hidden="true"]` elements do not contain focusable descendents passed.
`[role]`s have all required `[aria-*]` attributes passed.
`[role]` values are valid passed.
`[aria-*]` attributes are valid and not misspelled passed.
`[aria-*]` attributes have valid values passed.
Buttons have an accessible name passed.
Document has a `<title>` element passed.
`<frame>` or `<iframe>` elements have a title passed.
Links have a discernible name passed.
Lighthouse accessibility score: 96/100. Agents read the page through its accessibility tree, so this is a proxy for how navigable your site is to an AI agent.
0.000 (field data from CrUX) — good.
779ms (field data from CrUX) — good.
No tool catalog was found at /.well-known/webmcp.json (or /.well-known/webmcp). The catalog is a community convention, not part of the WebMCP standard, so this does not affect WebMCP presence.
Fix: Consider also publishing a tool catalog at /.well-known/webmcp.json: a JSON document with a "spec" of "webmcp/0.1" and a "tools" array, where each tool declares a name and a clear description. It is a community convention (optional, not part of the WebMCP standard) that lets crawlers and agents discover your tools without executing JavaScript.
Can agents safely transact?
/.well-known/oauth-authorization-server returned 404.
Fix: Publish /.well-known/oauth-authorization-server so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
/.well-known/oauth-protected-resource returned 404.
Fix: Publish /.well-known/oauth-protected-resource so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
No Web Bot Auth signature headers — sites can't verify agent identity.
Fix: Web Bot Auth (IETF HTTP Message Signatures over Signature / Signature-Input) lets you cryptographically verify which agent is hitting you. Several CDNs offer turn-key support; otherwise skip until vendor support matures.
No Content-Security-Policy header on the homepage.
Fix: Add a Content-Security-Policy. Even a strict default-src directive cuts XSS blast radius dramatically. Start in report-only mode to find violations.
x-amz-cf-id: -IMhE_hLSxWNLQp7PtQ8JECRx0GUZI5BkiGTvTru (AWS CloudFront)
max-age=31536000, includeSubDomains=true, preload=true.
Homepage scheme is https:.
http://hotmart.com → https://hotmart.com/en (2 hops).
No stack-trace markers in the first 5KB.
Homepage HTML references no http:// resources.
Referrer-Policy: same-origin.
Valid for 73 more days (Oct 2 23:59:59 2026 GMT, issuer: Amazon RSA 2048 M01).
Server / X-Powered-By headers don't leak product version.
X-Content-Type-Options: nosniff.
X-Frame-Options: SAMEORIGIN.