Can agents find your site and its capabilities?
Per llmstxt.org, follow the H1 with a "> short summary" blockquote.
Fix: Add a "> One-sentence description of your site." blockquote under the H1.
Found https://hubspot.com/llms.txt.
Found at least one "[name](url)" markdown link.
First line is a top-level "# Title" heading.
Crawled 12 of 12 discovered pages beyond the homepage.
Built on HubSpot CMS.
Can agents understand your content?
Homepage returned 406 for Accept: text/markdown.
Homepage contains ~2686 elements — heavy.
Fix: Aim for under 1500 elements on the homepage. Heavier DOMs slow first paint and overflow some AI crawlers' parse buffers.
83/84 images have explicit width+height.
Fix: Add width and height to every <img>. Without them the browser doesn't know the aspect ratio and reflows the page on load (CLS).
Only 0 internal links on the homepage.
Fix: Add at least 5-10 internal links pointing to your top product, pricing, docs, blog and about pages so an AI agent can navigate to them from the homepage.
1 of 12 pages are missing <title> and/or <h1>: /company/management/jim-oneill.
Fix: Make sure every page sets a unique <title> and exactly one <h1>. The title is how an AI agent confirms it landed on the right page after navigating.
Homepage server response contains 2218 words of visible text — content is reachable without executing JavaScript.
108 headings, no level skips.
Language declared as "en".
84 of 84 <img> tags have alt attributes.
All four landmark elements present (main, header, footer, nav).
Exactly one <h1> on the homepage.
All 12 pages return ≥80 words of visible text without JavaScript.
Can agents actually operate the page?
Lighthouse flagged this audit — agents may be unable to perceive or operate the affected elements.
Fix: Add a title to every <iframe> so agents can identify embedded content.
1 of 14 agent-critical accessibility audits failed (`<frame>` or `<iframe>` elements do not have a title) — an agent may be unable to identify or operate the affected elements.
Fix: Fix the failing agent-accessibility audits listed below (accessible names on controls, valid ARIA roles/relationships, nothing interactive hidden from the tree).
`[aria-*]` attributes match their roles passed.
Uses ARIA roles only on compatible elements passed.
`[aria-hidden="true"]` is not present on the document `<body>` passed.
`[aria-hidden="true"]` elements do not contain focusable descendents passed.
`[role]`s have all required `[aria-*]` attributes passed.
Elements with an ARIA `[role]` that require children to contain a specific `[role]` have all required children. passed.
`[role]`s are contained by their required parent element passed.
`[role]` values are valid passed.
`[aria-*]` attributes are valid and not misspelled passed.
`[aria-*]` attributes have valid values passed.
Buttons have an accessible name passed.
Document has a `<title>` element passed.
Links have a discernible name passed.
Lighthouse accessibility score: 94/100. Agents read the page through its accessibility tree, so this is a proxy for how navigable your site is to an AI agent.
2 of 2 visible interactive form fields have labels.
0.060 (field data from CrUX) — good.
282ms (field data from CrUX) — good.
No tool catalog was found at /.well-known/webmcp.json (or /.well-known/webmcp). The catalog is a community convention, not part of the WebMCP standard, so this does not affect WebMCP presence.
Fix: Consider also publishing a tool catalog at /.well-known/webmcp.json: a JSON document with a "spec" of "webmcp/0.1" and a "tools" array, where each tool declares a name and a clear description. It is a community convention (optional, not part of the WebMCP standard) that lets crawlers and agents discover your tools without executing JavaScript.
Can agents safely transact?
/.well-known/oauth-authorization-server returned 404.
Fix: Publish /.well-known/oauth-authorization-server so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
/.well-known/oauth-protected-resource returned 404.
Fix: Publish /.well-known/oauth-protected-resource so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
No Web Bot Auth signature headers — sites can't verify agent identity.
Fix: Web Bot Auth (IETF HTTP Message Signatures over Signature / Signature-Input) lets you cryptographically verify which agent is hitting you. Several CDNs offer turn-key support; otherwise skip until vendor support matures.
cf-ray: a1eacfbee9b2a4bf-AMS (Cloudflare); Server: cloudflare
CSP header present.
max-age=31536000, includeSubDomains=true, preload=true.
Homepage scheme is https:.
http://hubspot.com → https://www.hubspot.com/ (2 hops).
No stack-trace markers in the first 5KB.
Homepage HTML references no http:// resources.
Referrer-Policy: no-referrer-when-downgrade.
Valid for 83 more days (Oct 12 23:10:04 2026 GMT, issuer: WE1).
Server / X-Powered-By headers don't leak product version.
X-Content-Type-Options: nosniff.
X-Frame-Options: DENY.