Can agents find your site and its capabilities?
Per llmstxt.org, follow the H1 with a "> short summary" blockquote.
Fix: Add a "> One-sentence description of your site." blockquote under the H1.
Found a Markdown guide at /AGENTS.md.
Found https://ritual.com/llms.txt.
Found at least one "[name](url)" markdown link.
First line is a top-level "# Title" heading.
Crawled 4 of 12 discovered pages beyond the homepage.
Built on Shopify.
Can agents understand your content?
Homepage contains ~2037 elements — heavy.
Fix: Aim for under 1500 elements on the homepage. Heavier DOMs slow first paint and overflow some AI crawlers' parse buffers.
Detected 3 heading level skips (e.g. h2 → h5).
Fix: Tighten the heading order so each level only steps down by one. Skipped levels confuse both screen-readers and AI structural extractors.
43 of 53 images have alt attributes (81%).
Fix: Add alt text to the remaining images. Empty alt="" is fine for purely-decorative graphics.
1 of 4 pages are missing <title> and/or <h1>: /pages/terms-of-service.
Fix: Make sure every page sets a unique <title> and exactly one <h1>. The title is how an AI agent confirms it landed on the right page after navigating.
Homepage returns text/markdown when requested.
Homepage server response contains 1044 words of visible text — content is reachable without executing JavaScript.
Language declared as "en".
53/53 images set width and height — no layout shift.
162 internal links found.
All four landmark elements present (main, header, footer, nav).
Exactly one <h1> on the homepage.
All 4 pages return ≥80 words of visible text without JavaScript.
Can agents actually operate the page?
No autocomplete attributes on any data-collecting form field.
Fix: Add autocomplete hints (email, tel, name, etc.) so form-filling agents and browsers can populate fields without guessing.
0/1 data-collecting forms expose errors via ARIA attributes.
Fix: Wire inputs to their error containers with `aria-describedby` and toggle `aria-invalid` on validation failure. Agents that can't see styled error text rely on these attributes.
All 11 agent-critical accessibility audits passed — an agent can perceive and operate the page through its accessibility tree.
`[aria-*]` attributes match their roles passed.
`[aria-hidden="true"]` is not present on the document `<body>` passed.
`[aria-hidden="true"]` elements do not contain focusable descendents passed.
`[role]`s have all required `[aria-*]` attributes passed.
Elements with an ARIA `[role]` that require children to contain a specific `[role]` have all required children. passed.
`[role]` values are valid passed.
`[aria-*]` attributes are valid and not misspelled passed.
`[aria-*]` attributes have valid values passed.
Buttons have an accessible name passed.
Document has a `<title>` element passed.
Links have a discernible name passed.
Lighthouse accessibility score: 94/100. Agents read the page through its accessibility tree, so this is a proxy for how navigable your site is to an AI agent.
4 of 4 visible interactive form fields have labels.
1/1 data-collecting forms mark required fields.
All 1 data-collecting forms include pattern/min/max constraints.
0.000 (field data from CrUX) — good.
384ms (field data from CrUX) — good.
No tool catalog was found at /.well-known/webmcp.json (or /.well-known/webmcp). The catalog is a community convention, not part of the WebMCP standard, so this does not affect WebMCP presence.
Fix: Consider also publishing a tool catalog at /.well-known/webmcp.json: a JSON document with a "spec" of "webmcp/0.1" and a "tools" array, where each tool declares a name and a clear description. It is a community convention (optional, not part of the WebMCP standard) that lets crawlers and agents discover your tools without executing JavaScript.
Can agents safely transact?
Found 3 http:// references in the homepage HTML — browsers will block these resources.
Fix: Update every http:// resource URL to https:// (or use protocol-relative `//`). Common offenders: image CDNs and legacy embed snippets.
No Web Bot Auth signature headers — sites can't verify agent identity.
Fix: Web Bot Auth (IETF HTTP Message Signatures over Signature / Signature-Input) lets you cryptographically verify which agent is hitting you. Several CDNs offer turn-key support; otherwise skip until vendor support matures.
HSTS max-age=7889238 is below six months.
Fix: Raise max-age to at least 15768000 (six months). The HSTS preload list requires 31536000 (one year).
No Referrer-Policy header on the homepage.
Fix: Add `Referrer-Policy: strict-origin-when-cross-origin` so outbound links don't leak full URLs (including query strings) to third parties.
/.well-known/oauth-authorization-server returns parseable JSON.
/.well-known/oauth-protected-resource returns parseable JSON.
cf-ray: a1eb7e795b880c13-AMS (Cloudflare); Server: cloudflare
CSP header present.
Homepage scheme is https:.
http://ritual.com → https://ritual.com/ (1 hop).
No stack-trace markers in the first 5KB.
Valid for 38 more days (Aug 29 01:01:35 2026 GMT, issuer: YE1).
Server / X-Powered-By headers don't leak product version.
X-Content-Type-Options: nosniff.
X-Frame-Options: DENY.
Can agents shop and check out?
Found the human-approval-for-checkout rule.
Content-Type: text/markdown; charset=utf-8.
Mentions the store ("ritual") — looks customised beyond the default.
References UCP / a UCP version or /.well-known/ucp.
No secret/token or admin-path references found.
Found at https://ritual.com/agents.md.
References the UCP MCP endpoint (/api/ucp/mcp).
Manifest parses as JSON.
Manifest reachable at https://ritual.com/.well-known/ucp.
Services: dev.ucp.shopping.
Transports: mcp, embedded.