Evidence: the initial reachability check returned HTTP 403. Cloudflare header(s): cf-ray, server, cf-mitigated, content-security-policy. URL: https://almatjar.app
Review Cloudflare WAF, bot protection, rate-limit, and challenge rules for public marketing/content routes. Allow safe public scans and legitimate search or AI user-fetch crawlers to reach public pages while keeping admin, authenticated, preview, and private paths protected.
Speed Insights
Grade A
98% performance
https://almatjar.app
LCP
332ms
Largest paint
TBT
76ms
Blocking time
CLS
0.001
Layout shift
50
out of 100
41
out of 100
18/44 rule points
92
out of 100
48/52 rule points
0
out of 100
0/18 rule points
68
out of 100
26/38 rule points
Category point breakdown
Biggest score-losing checks
Improve AI search and crawler readiness
-14 rule ptsWhat failed
One or more AI discovery, user-fetch, indexability, snippet, synthetic reachability, or sitemap signals need attention.
Evidence
intake returned HTTP 403 with Cloudflare signals, which can indicate crawler or bot-security blocking. robots.txt blocks OAI-SearchBot, Claude-SearchBot, Googlebot, and 5 more from AI search or discovery for this page path. Synthetic or robots checks block Claude-User, MistralAI-User, meta-externalfetcher, and 1 more from user-requested fetches. GPTBot, ClaudeBot, Google-Extended, and 4 more are explicit training or data-use opt-outs and do not reduce the AEO score. AEO crawler readiness is 65%: discovery 45/45, index and snippet eligibility 20/25, synthetic reachability 0/20, sitemap freshness 0/10.
Priority
Priority 2: fix before sharing the page publicly.
Why it matters
AI search systems need crawlable, reachable, indexable, and quotable public content. Training and data-use choices remain neutral publisher preferences.
How to fix it
Use the component scores and exact matched robots rules in the crawler report. Fix blocked search agents, noindex or snippet restrictions, canonical or sitemap gaps, and synthetic WAF/challenge failures. Preserve intentional training opt-outs and keep private, admin, and authenticated paths protected before rescanning.
Agent Prompt
Fix rendered axe accessibility violations
-18 rule ptsWhat failed
The rendered page has accessibility rule violations detected by axe-core.
Evidence
axe found 1 violation rule(s), including 1 serious or critical rule(s). Top rules: meta-refresh (1).
Affected elements
Delayed refresh under 20 hours must not be used
Fix any of the following: <meta> tag forces timed refresh of page (less than 20 hours)
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
How to fix it
Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Agent Prompt
Add responsive viewport metadata
-12 rule ptsWhat failed
The page is missing the viewport meta tag used for mobile layout.
Evidence
No viewport meta tag was detected.
Priority
Priority 3: fix before sharing the page publicly.
Why it matters
Launch traffic often comes from phones; missing viewport metadata can make the page render poorly.
How to fix it
Add a viewport meta tag with width=device-width and initial-scale=1.
Agent Prompt
Publish a valid sitemap
-12 rule ptsWhat failed
The sitemap file was not reachable or did not look like valid sitemap XML.
Evidence
HTTP 403 returned for sitemap_xml.
Priority
Priority 7: fix during launch polish.
Why it matters
A sitemap helps search engines discover the landing page and related public pages sooner.
How to fix it
Add a static sitemap file, dynamic sitemap route, or robots.txt Sitemap directive that returns valid urlset or sitemapindex XML. Include public canonical URLs and confirm the sitemap URL returns HTTP 200.
Agent Prompt
Add common public security headers
-4 rule ptsWhat failed
Several basic browser protection headers were not visible.
Evidence
Detected 4 of 5 common public security controls. Present: content-security-policy, x-content-type-options, frame protection (x-frame-options), referrer-policy. Missing: strict-transport-security.
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
These headers reduce avoidable browser-side risk and show a baseline of care before launch.
How to fix it
Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Agent Prompt
SEO / AEO
Severity mix: 1 critical, 2 high, 1 medium, 0 low.
Crawler access
-14 rule ptsintake returned HTTP 403 with Cloudflare signals, which can indicate crawler or bot-security blocking. robots.txt blocks OAI-SearchBot, Claude-SearchBot, Googlebot, and 5 more from AI search or discovery for this page path. Synthetic or robots checks block Claude-User, MistralAI-User, meta-externalfetcher, and 1 more from user-requested fetches. GPTBot, ClaudeBot, Google-Extended, and 4 more are explicit training or data-use opt-outs and do not reduce the AEO score. AEO crawler readiness is 65%: discovery 45/45, index and snippet eligibility 20/25, synthetic reachability 0/20, sitemap freshness 0/10.
Sitemap validity
-12 rule ptsHTTP 403 returned for sitemap_xml.
Security
Severity mix: 2 critical, 1 high, 0 medium, 0 low.
Common security headers
-4 rule ptsDetected 4 of 5 common public security controls. Present: content-security-policy, x-content-type-options, frame protection (x-frame-options), referrer-policy. Missing: strict-transport-security.
Accessibility
Severity mix: 0 critical, 1 high, 0 medium, 0 low.
Rendered axe accessibility violations
-18 rule ptsaxe found 1 violation rule(s), including 1 serious or critical rule(s). Top rules: meta-refresh (1).
Affected elements
Delayed refresh under 20 hours must not be used
Fix any of the following: <meta> tag forces timed refresh of page (less than 20 hours)
Design
Severity mix: 0 critical, 1 high, 2 medium, 1 low.
Responsive viewport basics
-12 rule ptsNo viewport meta tag was detected.
Failed checks
These checks need attention.
Crawler access
0/14intake returned HTTP 403 with Cloudflare signals, which can indicate crawler or bot-security blocking. robots.txt blocks OAI-SearchBot, Claude-SearchBot, Googlebot, and 5 more from AI search or discovery for this page path. Synthetic or robots checks block Claude-User, MistralAI-User, meta-externalfetcher, and 1 more from user-requested fetches. GPTBot, ClaudeBot, Google-Extended, and 4 more are explicit training or data-use opt-outs and do not reduce the AEO score. AEO crawler readiness is 65%: discovery 45/45, index and snippet eligibility 20/25, synthetic reachability 0/20, sitemap freshness 0/10.
Failed: earned 0 of 14 points.
Priority: Priority 2: fix before sharing the page publicly.
Why it matters: AI search systems need crawlable, reachable, indexable, and quotable public content. Training and data-use choices remain neutral publisher preferences.
Fix: Use the component scores and exact matched robots rules in the crawler report. Fix blocked search agents, noindex or snippet restrictions, canonical or sitemap gaps, and synthetic WAF/challenge failures. Preserve intentional training opt-outs and keep private, admin, and authenticated paths protected before rescanning.
Agent Prompt
Sitemap validity
0/12HTTP 403 returned for sitemap_xml.
Failed: earned 0 of 12 points.
Priority: Priority 7: fix during launch polish.
Why it matters: A sitemap helps search engines discover the landing page and related public pages sooner.
Fix: Add a static sitemap file, dynamic sitemap route, or robots.txt Sitemap directive that returns valid urlset or sitemapindex XML. Include public canonical URLs and confirm the sitemap URL returns HTTP 200.
Agent Prompt
Common security headers
14/18Detected 4 of 5 common public security controls. Present: content-security-policy, x-content-type-options, frame protection (x-frame-options), referrer-policy. Missing: strict-transport-security.
Failed: earned 14 of 18 points from partial coverage.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: These headers reduce avoidable browser-side risk and show a baseline of care before launch.
Fix: Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Agent Prompt
Rendered axe accessibility violations
0/18axe found 1 violation rule(s), including 1 serious or critical rule(s). Top rules: meta-refresh (1).
Affected elements
Delayed refresh under 20 hours must not be used
Fix any of the following: <meta> tag forces timed refresh of page (less than 20 hours)
Failed: earned 0 of 18 points.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
Fix: Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Agent Prompt
Responsive viewport basics
0/12No viewport meta tag was detected.
Failed: earned 0 of 12 points.
Priority: Priority 3: fix before sharing the page publicly.
Why it matters: Launch traffic often comes from phones; missing viewport metadata can make the page render poorly.
Fix: Add a viewport meta tag with width=device-width and initial-scale=1.
Agent Prompt
Page-level AEO readiness
Shared eligibility and content signals that affect every search and answer agent.
Index and citation eligibility
No general noindex directive was detected.
Snippet and answer controls
No general nosnippet or max-snippet:0 control was detected.
Canonical alignment
No canonical URL was detected.
Sitemap coverage and freshness
Sitemap coverage could not be verified.
Structured data
Semantic schema score 0/100. Detected 0 JSON-LD block(s), 0 parse error(s), 0 graph node(s), and types none. No primary schema type matched the detected page role.
Public or paywalled content
No isAccessibleForFree structured-data value was detected.
Entity clarity
Entity alignment scored 0/100 for “an unnamed subject”. Title/H1 token overlap is 0%; description match not detected; identity schema not detected.
Answer-ready visible text
Answerability scored 0/100 from 0 main-content words, 0 concise answer block(s), 0 question heading(s), 0 definition(s), 0 list(s), and 0 table(s).
Authorship and accountability
Authorship is not a universal requirement for the detected home page role.
Published or updated date
Freshness metadata is contextual for the detected home page role.
Supporting-source links
Supporting sources are contextual for the detected home page role and do not affect readiness.
Rendered content availability
Rendered audit completed with 8 visible text element(s).
Synthetic search-agent reachability
0 of 8 completed search/discovery User-Agent probes returned reachable content.
Optional LLM-readable summary
No llms.txt file was found; this is optional and does not reduce core AEO readiness.
OAI-SearchBotAI search
Robots: allowed by * allow: / · line 31
Probe: challenged · HTTP 403 · 0% parity
GPTBotModel training
Robots: blocked by gptbot disallow: / · line 55
Probe: not tested for this control
ChatGPT-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
ClaudeBotModel training
Robots: blocked by claudebot disallow: / · line 46
Probe: not tested for this control
Claude-SearchBotAI search
Robots: allowed by * allow: / · line 31
Probe: challenged · HTTP 403 · 0% parity
Claude-UserUser-requested fetch
Robots: allowed by * allow: / · line 31
Probe: challenged · HTTP 403 · 0% parity
GooglebotSearch and discovery
Robots: allowed by * allow: / · line 31
Probe: challenged · HTTP 403 · 0% parity
Google-ExtendedData-use policy control
Robots: blocked by google-extended disallow: / · line 52
Probe: not tested for this control
BingbotSearch and discovery
Robots: allowed by * allow: / · line 31
Probe: challenged · HTTP 403 · 0% parity
PerplexityBotAI search
Robots: allowed by * allow: / · line 31
Probe: challenged · HTTP 403 · 0% parity
Perplexity-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
ApplebotSearch and discovery
Robots: allowed by * allow: / · line 31
Probe: challenged · HTTP 403 · 0% parity
Applebot-ExtendedData-use policy control
Robots: blocked by applebot-extended disallow: / · line 37
Probe: not tested for this control
MistralAI-IndexAI search
Robots: allowed by * allow: / · line 31
Probe: challenged · HTTP 403 · 0% parity
MistralAI-UserUser-requested fetch
Robots: allowed by * allow: / · line 31
Probe: challenged · HTTP 403 · 0% parity
meta-externalagentModel training
Robots: blocked by meta-externalagent disallow: / · line 58
Probe: not tested for this control
meta-externalfetcherUser-requested fetch
Robots: allowed by * allow: / · line 31
Probe: challenged · HTTP 403 · 0% parity
AmazonbotModel training
Robots: blocked by amazonbot disallow: / · line 34
Probe: not tested for this control
Amzn-SearchBotAI search
Robots: allowed by * allow: / · line 31
Probe: challenged · HTTP 403 · 0% parity
Amzn-UserUser-requested fetch
Robots: allowed by * allow: / · line 31
Probe: challenged · HTTP 403 · 0% parity
CCBotModel training
Robots: blocked by ccbot disallow: / · line 43
Probe: not tested for this control
Ready combines robots policy, a bounded synthetic User-Agent fetch, indexability, and snippet eligibility. Synthetic probes do not prove vendor-origin traffic. Purple preference states are training or data-use choices and do not lower the AEO score.
The image refreshes from FreeScan after a completed rescan. Clicking it always opens the newest public report saved for this exact scanned URL.
Scan evidence is included as untrusted data. The implementation brief instructs agents to verify findings before editing and to avoid destructive or speculative changes.
