Evidence: security probe returned HTTP 403. Cloudflare header(s): cf-ray, server. URL: https://www.cadetai.com/.env
Review Cloudflare WAF, bot protection, rate-limit, and challenge rules for public marketing/content routes. Allow safe public scans and legitimate search or AI user-fetch crawlers to reach public pages while keeping admin, authenticated, preview, and private paths protected.
Speed Insights
Grade A
91% performance
https://www.cadetai.com
From cadetai.com
LCP
2.0s
Largest paint
TBT
11ms
Blocking time
CLS
0.13
Layout shift
72
out of 100
61
out of 100
63/103 rule points
82
out of 100
62/76 rule points
66
out of 100
62/94 rule points
80
out of 100
88/110 rule points
Category point breakdown
Biggest score-losing checks
axe found 3 violation rule(s), including 1 serious or critical rule(s). Top rules: link-name (2), landmark-one-main (1), region (27).
Detected 1 of 5 common public security controls. Present: strict-transport-security. Missing: content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Detected labels or accessible names for 7 of 12 form control(s).
Detected 2 H1 heading(s) and 61 meta-description characters.
Add common public security headers
-14 rule ptsWhat failed
Several basic browser protection headers were not visible.
Evidence
Detected 1 of 5 common public security controls. Present: strict-transport-security. Missing: content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
These headers reduce avoidable browser-side risk and show a baseline of care before launch.
How to fix it
Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Agent Prompt
Fix rendered axe accessibility violations
-18 rule ptsWhat failed
The rendered page has accessibility rule violations detected by axe-core.
Evidence
axe found 3 violation rule(s), including 1 serious or critical rule(s). Top rules: link-name (2), landmark-one-main (1), region (27).
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
How to fix it
Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Agent Prompt
Label public form fields
-14 rule ptsWhat failed
Some form controls do not have a detectable label or accessible name.
Evidence
Detected labels or accessible names for 7 of 12 form control(s).
Priority
Priority 7: fix during launch polish.
Why it matters
Unlabeled inputs make email capture, demo requests, and signups harder for assistive technology users.
How to fix it
Connect each input to a visible label or an accurate aria-label/aria-labelledby value.
Agent Prompt
Publish a valid sitemap
-12 rule ptsWhat failed
The sitemap file was not reachable or did not look like valid sitemap XML.
Evidence
HTTP 404 returned for sitemap_xml.
Priority
Priority 7: fix during launch polish.
Why it matters
A sitemap helps search engines discover the landing page and related public pages sooner.
How to fix it
Add a static sitemap file, dynamic sitemap route, or robots.txt Sitemap directive that returns valid urlset or sitemapindex XML. Include public canonical URLs and confirm the sitemap URL returns HTTP 200.
Agent Prompt
Clarify the hero promise
-13 rule ptsWhat failed
The hero area does not provide enough clear product context.
Evidence
Detected 2 H1 heading(s) and 61 meta-description characters.
Priority
Priority 6: fix during launch polish.
Why it matters
Visitors decide quickly whether the product is relevant; a vague hero weakens every acquisition channel.
How to fix it
Use one clear H1 plus supporting copy that names the audience, problem, and outcome.
Agent Prompt
SEO / AEO
Severity mix: 1 critical, 6 high, 3 medium, 1 low.
Sitemap validity
-12 rule ptsHTTP 404 returned for sitemap_xml.
Canonical tag
-10 rule ptsNo canonical link tag was detected.
Schema presence
-10 rule ptsDetected 0 JSON-LD schema block(s).
Security
Severity mix: 2 critical, 3 high, 0 medium, 0 low.
Common security headers
-14 rule ptsDetected 1 of 5 common public security controls. Present: strict-transport-security. Missing: content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Accessibility
Severity mix: 0 critical, 3 high, 5 medium, 0 low.
Rendered axe accessibility violations
-18 rule ptsaxe found 3 violation rule(s), including 1 serious or critical rule(s). Top rules: link-name (2), landmark-one-main (1), region (27).
Form labels
-14 rule ptsDetected labels or accessible names for 7 of 12 form control(s).
Design
Severity mix: 0 critical, 3 high, 6 medium, 2 low.
Hero clarity signals
-13 rule ptsDetected 2 H1 heading(s) and 61 meta-description characters.
Rendered layout ergonomics
-9 rule ptsHorizontal overflow: 0px. Small tap targets: 14.
Failed checks
These checks need attention.
Heading structure
0/8Detected 2 H1 heading(s) and 2 total headings.
Failed: earned 0 of 8 points.
Priority: Priority 9: fix during launch polish.
Why it matters: Clear headings help visitors, search engines, and assistive technology understand the page quickly.
Fix: Keep one H1 for the main promise, then use H2 and H3 headings in order for sections below it.
Agent Prompt
Canonical tag
0/10No canonical link tag was detected.
Failed: earned 0 of 10 points.
Priority: Priority 9: fix during launch polish.
Why it matters: A canonical tag reduces duplicate URL confusion before marketing links start spreading.
Fix: Add a canonical link tag that points to the final public landing page URL.
Agent Prompt
Sitemap validity
0/12HTTP 404 returned for sitemap_xml.
Failed: earned 0 of 12 points.
Priority: Priority 7: fix during launch polish.
Why it matters: A sitemap helps search engines discover the landing page and related public pages sooner.
Fix: Add a static sitemap file, dynamic sitemap route, or robots.txt Sitemap directive that returns valid urlset or sitemapindex XML. Include public canonical URLs and confirm the sitemap URL returns HTTP 200.
Agent Prompt
Schema presence
0/10Detected 0 JSON-LD schema block(s).
Failed: earned 0 of 10 points.
Priority: Priority 12: fix during launch polish.
Why it matters: Structured data gives search and answer engines explicit facts about your product.
Fix: Add JSON-LD for SoftwareApplication, Product, Organization, or WebSite using only accurate public facts.
Agent Prompt
Common security headers
4/18Detected 1 of 5 common public security controls. Present: strict-transport-security. Missing: content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Failed: earned 4 of 18 points from partial coverage.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: These headers reduce avoidable browser-side risk and show a baseline of care before launch.
Fix: Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Agent Prompt
Form labels
0/14Detected labels or accessible names for 7 of 12 form control(s).
Failed: earned 0 of 14 points.
Priority: Priority 7: fix during launch polish.
Why it matters: Unlabeled inputs make email capture, demo requests, and signups harder for assistive technology users.
Fix: Connect each input to a visible label or an accurate aria-label/aria-labelledby value.
Agent Prompt
Rendered axe accessibility violations
0/18axe found 3 violation rule(s), including 1 serious or critical rule(s). Top rules: link-name (2), landmark-one-main (1), region (27).
Failed: earned 0 of 18 points.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
Fix: Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Agent Prompt
Hero clarity signals
0/13Detected 2 H1 heading(s) and 61 meta-description characters.
Failed: earned 0 of 13 points.
Priority: Priority 6: fix during launch polish.
Why it matters: Visitors decide quickly whether the product is relevant; a vague hero weakens every acquisition channel.
Fix: Use one clear H1 plus supporting copy that names the audience, problem, and outcome.
Agent Prompt
Rendered layout ergonomics
0/9Horizontal overflow: 0px. Small tap targets: 14.
Failed: earned 0 of 9 points.
Priority: Priority 13: fix during launch polish.
Why it matters: Horizontal overflow and tiny tap targets make the page feel broken on real devices, especially for mobile visitors.
Fix: Remove elements wider than the viewport, add responsive constraints, and make important links, buttons, inputs, and controls at least 40px tall and wide where possible.
Agent Prompt
Page-level AEO readiness
Shared eligibility and content signals that affect every search and answer agent.
Index and citation eligibility
No general noindex directive was detected.
Snippet and answer controls
No general nosnippet or max-snippet:0 control was detected.
Canonical alignment
No canonical URL was detected.
Sitemap coverage and freshness
Sitemap coverage could not be verified.
Structured data
Detected 0 JSON-LD block(s), 0 parse error(s), and types none.
Public or paywalled content
No isAccessibleForFree structured-data value was detected.
Entity clarity
Detected 3 of 3 core identity signals across the title, description, and H1.
Answer-ready visible text
Detected 1120 visible words and 33 audience, use-case, pricing, or integration signals.
Authorship and accountability
No author meta value or structured-data author was detected.
Published or updated date
No datePublished or dateModified value was detected in structured data.
Supporting-source links
Detected 5 external source or reference link(s); link quality still requires editorial review.
Rendered content availability
Rendered audit completed with 110 visible text element(s).
Synthetic search-agent reachability
8 of 8 search/discovery User-Agent probes returned reachable content.
Optional LLM-readable summary
No llms.txt file was found; this is optional and does not reduce core AEO readiness.
OAI-SearchBotAI search
Robots: allowed
Probe: reachable · HTTP 200 · 98% parity
GPTBotModel training
Robots: allowed
Probe: not tested for this control
ChatGPT-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
ClaudeBotModel training
Robots: allowed
Probe: not tested for this control
Claude-SearchBotAI search
Robots: allowed
Probe: reachable · HTTP 200 · 98% parity
Claude-UserUser-requested fetch
Robots: allowed
Probe: reachable · HTTP 200 · 98% parity
GooglebotSearch and discovery
Robots: allowed
Probe: reachable · HTTP 200 · 98% parity
Google-ExtendedData-use policy control
Robots: allowed
Probe: not tested for this control
BingbotSearch and discovery
Robots: allowed
Probe: reachable · HTTP 200 · 98% parity
PerplexityBotAI search
Robots: allowed
Probe: reachable · HTTP 200 · 98% parity
Perplexity-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
ApplebotSearch and discovery
Robots: allowed
Probe: reachable · HTTP 200 · 98% parity
Applebot-ExtendedData-use policy control
Robots: allowed
Probe: not tested for this control
MistralAI-IndexAI search
Robots: allowed
Probe: reachable · HTTP 200 · 98% parity
MistralAI-UserUser-requested fetch
Robots: allowed
Probe: reachable · HTTP 200 · 98% parity
meta-externalagentModel training
Robots: allowed
Probe: not tested for this control
meta-externalfetcherUser-requested fetch
Robots: allowed
Probe: reachable · HTTP 200 · 98% parity
AmazonbotModel training
Robots: allowed
Probe: not tested for this control
Amzn-SearchBotAI search
Robots: allowed
Probe: reachable · HTTP 200 · 98% parity
Amzn-UserUser-requested fetch
Robots: allowed
Probe: reachable · HTTP 200 · 98% parity
CCBotModel training
Robots: allowed
Probe: not tested for this control
Ready combines robots policy, a bounded synthetic User-Agent fetch, indexability, and snippet eligibility. Synthetic probes do not prove vendor-origin traffic. Purple preference states are training or data-use choices and do not lower the AEO score.
Share preview
cadetai.com website audit report
Close to ready: 72/100 overall, with prioritized fixes for SEO, security, accessibility, and design.
Public reports expose the scanned public URL, safe scores, sanitized public evidence, and fix guidance. They do not include credentials, cookies, hidden form values, or sensitive response bodies.
