Can agents find your site and its capabilities?
Crawled 11 of 12 discovered pages beyond the homepage.
Lighthouse Agentic Browsing audits ran.
Could not identify a known website platform (custom stack or unrecognised).
Can agents understand your content?
No lang attribute on <html>.
Fix: Add lang to the <html> root (e.g. lang="en") so screen readers and AI translation engines pick the right voice / model.
No links found on the homepage.
Fix: Add navigation links so AI crawlers can find the rest of your content. A bare landing page is invisible to anything that doesn't already know where to look.
No semantic landmark elements (main, header, footer, nav) detected on the homepage.
Fix: Wrap your page structure in semantic landmarks. AI structural extractors rely on them to separate navigation from content from boilerplate.
No <h1> tag found on the homepage.
Fix: Add exactly one <h1> that names the page. AI summarisers use it as the document title.
Homepage ignored Accept: text/markdown and returned HTML.
Fix: Serve a markdown version of high-value pages when the client asks for text/markdown. AI summarisers, chatbots and IDE agents prefer markdown — fewer tokens, no DOM noise.
Homepage server response contains only 0 words of visible text. AI agents that don't execute JavaScript may see an empty page.
Fix: Consider pre-rendering or server-rendering the homepage so AI crawlers (which typically don't run JS) can see the content. Frameworks: Next.js (Server Components), Nuxt SSR, Astro, or Vite SSG.
11 of 11 pages are missing <title> and/or <h1>: /browse/content/black-style-designers, /brands/chanel/les-4-ombres-tweed, /browse/activewear, /browse/style-guide/fashion-news/lifestyle/roger-vivier-interview, /browse/content/blog/argan-oil-for-face, /browse/style-guide/fashion-news/lifestyle/stephanie-suberville-oaxaca-travel-tips, /browse/content/how-to-style-utility-jacket, /browse/home/five-two-by-food52, /browse/content/blog/benzoyl-peroxide-vs-salicylic-acid, /browse/content/blog/trail-running-shoes-guide, /browse/content/monthly-edit-freshdew.
Fix: Make sure every page sets a unique <title> and exactly one <h1>. The title is how an AI agent confirms it landed on the right page after navigating.
11 of 11 pages return <80 words of visible text — agents without JavaScript see an empty page: /browse/content/black-style-designers (0w), /brands/chanel/les-4-ombres-tweed (0w), /browse/activewear (0w), /browse/style-guide/fashion-news/lifestyle/roger-vivier-interview (0w), /browse/content/blog/argan-oil-for-face (0w), /browse/style-guide/fashion-news/lifestyle/stephanie-suberville-oaxaca-travel-tips (0w), /browse/content/how-to-style-utility-jacket (0w), /browse/home/five-two-by-food52 (0w), /browse/content/blog/benzoyl-peroxide-vs-salicylic-acid (0w), /browse/content/blog/trail-running-shoes-guide (0w), /browse/content/monthly-edit-freshdew (0w).
Fix: Pre-render or server-render these pages so AI crawlers (which usually don't execute JS) can read them. Frameworks: Next.js Server Components, Nuxt SSR, Astro, or build-time prerendering.
Homepage contains ~50 elements.
Can agents actually operate the page?
0.240 (field data from CrUX) — needs improvement.
Fix: A layout that shifts while loading makes an AI agent mis-click the element it targeted. Eliminate CLS by setting explicit width/height on images and embeds, avoiding inserted content above existing content, and reserving space for ad slots.
All 11 agent-critical accessibility audits passed — an agent can perceive and operate the page through its accessibility tree.
`[aria-*]` attributes match their roles passed.
`[aria-hidden="true"]` is not present on the document `<body>` passed.
`[aria-hidden="true"]` elements do not contain focusable descendents passed.
`[role]`s have all required `[aria-*]` attributes passed.
`[role]` values are valid passed.
`[aria-*]` attributes are valid and not misspelled passed.
`[aria-*]` attributes have valid values passed.
Buttons have an accessible name passed.
Document has a `<title>` element passed.
`<frame>` or `<iframe>` elements have a title passed.
Links have a discernible name passed.
Lighthouse accessibility score: 100/100. Agents read the page through its accessibility tree, so this is a proxy for how navigable your site is to an AI agent.
All audits passed
0.045
521ms (field data from CrUX) — good.
1 form missing annotations
Lists the [WebMCP tools](http://goo.gle/webmcp-docs) registered at the time of analysis.
No tool catalog was found at /.well-known/webmcp.json (or /.well-known/webmcp). The catalog is a community convention, not part of the WebMCP standard, so this does not affect WebMCP presence.
Fix: Consider also publishing a tool catalog at /.well-known/webmcp.json: a JSON document with a "spec" of "webmcp/0.1" and a "tools" array, where each tool declares a name and a clear description. It is a community convention (optional, not part of the WebMCP standard) that lets crawlers and agents discover your tools without executing JavaScript.
Can agents safely transact?
/.well-known/oauth-authorization-server returned 404.
Fix: Publish /.well-known/oauth-authorization-server so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
/.well-known/oauth-protected-resource returned 404.
Fix: Publish /.well-known/oauth-protected-resource so AI agents discovering your OAuth setup can negotiate flows automatically. Required if your site offers an authenticated API.
No Web Bot Auth signature headers — sites can't verify agent identity.
Fix: Web Bot Auth (IETF HTTP Message Signatures over Signature / Signature-Input) lets you cryptographically verify which agent is hitting you. Several CDNs offer turn-key support; otherwise skip until vendor support matures.
No Content-Security-Policy header on the homepage.
Fix: Add a Content-Security-Policy. Even a strict default-src directive cuts XSS blast radius dramatically. Start in report-only mode to find violations.
No Referrer-Policy header on the homepage.
Fix: Add `Referrer-Policy: strict-origin-when-cross-origin` so outbound links don't leak full URLs (including query strings) to third parties.
No X-Frame-Options header and no CSP frame-ancestors directive.
Fix: Add `X-Frame-Options: SAMEORIGIN` (or a CSP frame-ancestors directive) to prevent your site being framed by a phishing host.
x-served-by: cache-ams-eham8680099-AMS, cache-ams-eha (Fastly / Varnish)
max-age=31536000, includeSubDomains=true, preload=false.
Homepage scheme is https:.
http://nordstrom.com → https://www.nordstrom.com/ (2 hops).
No stack-trace markers in the first 5KB.
Homepage HTML references no http:// resources.
Valid for 64 more days (Sep 23 23:59:59 2026 GMT, issuer: Sectigo Public Server Authentication CA OV R36).
Server / X-Powered-By headers don't leak product version.
X-Content-Type-Options: nosniff.