Evidence: security probe returned HTTP 403. Cloudflare header(s): cf-ray, server. URL: https://hitou.site/wp-config.php
Review Cloudflare WAF, bot protection, rate-limit, and challenge rules for public marketing/content routes. Allow safe public scans and legitimate search or AI user-fetch crawlers to reach public pages while keeping admin, authenticated, preview, and private paths protected.
Speed Insights
Grade A
94% performance
https://hitou.site
LCP
1.9s
Largest paint
TBT
180ms
Blocking time
CLS
0.000
Layout shift
81
out of 100
100
out of 100
111/111 rule points
76
out of 100
58/76 rule points
81
out of 100
76/94 rule points
67
out of 100
74/110 rule points
Category point breakdown
Biggest score-losing checks
Detected 0 of 5 common public security controls. Present: none. Missing: strict-transport-security, content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
axe found 1 violation rule(s), including 0 serious or critical rule(s). Top rules: region (12).
Detected 0 trust-signal keyword occurrence(s).
DOMContentLoaded: 2281ms. Load complete: 2358ms. First contentful paint: 1864ms. Resources: 25. Scripts: 11. Images: 10. Third-party origins: 14. Transfer: not available.
Add common public security headers
-18 rule ptsWhat failed
Several basic browser protection headers were not visible.
Evidence
Detected 0 of 5 common public security controls. Present: none. Missing: strict-transport-security, content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
These headers reduce avoidable browser-side risk and show a baseline of care before launch.
How to fix it
Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Agent Prompt
Fix rendered axe accessibility violations
-18 rule ptsWhat failed
The rendered page has accessibility rule violations detected by axe-core.
Evidence
axe found 1 violation rule(s), including 0 serious or critical rule(s). Top rules: region (12).
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
How to fix it
Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Agent Prompt
Fix rendered layout ergonomics
-9 rule ptsWhat failed
The browser-rendered page has layout or tap-target issues.
Evidence
Horizontal overflow: 0px. Small tap targets: 23.
Priority
Priority 13: fix during launch polish.
Why it matters
Horizontal overflow and tiny tap targets make the page feel broken on real devices, especially for mobile visitors.
How to fix it
Remove elements wider than the viewport, add responsive constraints, and make important links, buttons, inputs, and controls at least 40px tall and wide where possible.
Agent Prompt
Improve rendered speed signals
-10 rule ptsWhat failed
The browser-rendered page shows slow or heavy speed signals.
Evidence
DOMContentLoaded: 2281ms. Load complete: 2358ms. First contentful paint: 1864ms. Resources: 25. Scripts: 11. Images: 10. Third-party origins: 14. Transfer: not available.
Priority
Priority 14: fix during launch polish.
Why it matters
Slow pages lose impatient visitors and make every SEO, social, and paid-traffic visit work harder.
How to fix it
Reduce render-blocking scripts/styles, compress and size images, defer non-critical JavaScript, reduce third-party tags, and keep above-the-fold content quick to paint.
Agent Prompt
Add trust signals
-10 rule ptsWhat failed
The page does not expose detectable proof, customer, review, security, or credibility signals.
Evidence
Detected 0 trust-signal keyword occurrence(s).
Priority
Priority 16: lower-risk cleanup after urgent launch blockers.
Why it matters
Trust signals reduce hesitation when strangers see the product for the first time.
How to fix it
Add honest proof such as customer quotes, usage stats, founder credibility, security notes, or relevant logos.
Agent Prompt
SEO / AEO
Severity mix: 1 critical, 7 high, 3 medium, 1 low.
No failed checks in this category.
Security
Severity mix: 2 critical, 3 high, 0 medium, 0 low.
Common security headers
-18 rule ptsDetected 0 of 5 common public security controls. Present: none. Missing: strict-transport-security, content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Accessibility
Severity mix: 0 critical, 3 high, 5 medium, 0 low.
Rendered axe accessibility violations
-18 rule ptsaxe found 1 violation rule(s), including 0 serious or critical rule(s). Top rules: region (12).
Design
Severity mix: 0 critical, 3 high, 6 medium, 2 low.
Trust signals
-10 rule ptsDetected 0 trust-signal keyword occurrence(s).
Rendered speed signals
-10 rule ptsDOMContentLoaded: 2281ms. Load complete: 2358ms. First contentful paint: 1864ms. Resources: 25. Scripts: 11. Images: 10. Third-party origins: 14. Transfer: not available.
Rendered layout ergonomics
-9 rule ptsHorizontal overflow: 0px. Small tap targets: 23.
Failed checks
These checks need attention.
Common security headers
0/18Detected 0 of 5 common public security controls. Present: none. Missing: strict-transport-security, content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Failed: earned 0 of 18 points.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: These headers reduce avoidable browser-side risk and show a baseline of care before launch.
Fix: Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Agent Prompt
Rendered axe accessibility violations
0/18axe found 1 violation rule(s), including 0 serious or critical rule(s). Top rules: region (12).
Failed: earned 0 of 18 points.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
Fix: Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Agent Prompt
Trust signals
0/10Detected 0 trust-signal keyword occurrence(s).
Failed: earned 0 of 10 points.
Priority: Priority 16: lower-risk cleanup after urgent launch blockers.
Why it matters: Trust signals reduce hesitation when strangers see the product for the first time.
Fix: Add honest proof such as customer quotes, usage stats, founder credibility, security notes, or relevant logos.
Agent Prompt
Spacing consistency
0/7Detected 1 spacing class/style signal(s).
Failed: earned 0 of 7 points.
Priority: Priority 25: lower-risk cleanup after urgent launch blockers.
Why it matters: Consistent spacing helps the page feel deliberate and easier to scan.
Fix: Use consistent section padding, gaps, and margins across repeated content blocks.
Agent Prompt
Rendered speed signals
0/10DOMContentLoaded: 2281ms. Load complete: 2358ms. First contentful paint: 1864ms. Resources: 25. Scripts: 11. Images: 10. Third-party origins: 14. Transfer: not available.
Failed: earned 0 of 10 points.
Priority: Priority 14: fix during launch polish.
Why it matters: Slow pages lose impatient visitors and make every SEO, social, and paid-traffic visit work harder.
Fix: Reduce render-blocking scripts/styles, compress and size images, defer non-critical JavaScript, reduce third-party tags, and keep above-the-fold content quick to paint.
Agent Prompt
Rendered layout ergonomics
0/9Horizontal overflow: 0px. Small tap targets: 23.
Failed: earned 0 of 9 points.
Priority: Priority 13: fix during launch polish.
Why it matters: Horizontal overflow and tiny tap targets make the page feel broken on real devices, especially for mobile visitors.
Fix: Remove elements wider than the viewport, add responsive constraints, and make important links, buttons, inputs, and controls at least 40px tall and wide where possible.
Agent Prompt
Page-level AEO readiness
Shared eligibility and content signals that affect every search and answer agent.
Index and citation eligibility
No general noindex directive was detected.
Snippet and answer controls
No general nosnippet or max-snippet:0 control was detected.
Canonical alignment
The canonical resolves to the scanned public URL.
Sitemap coverage and freshness
The exact URL appears in the fetched sitemap with lastmod 2026-08-11.
Structured data
Detected 2 JSON-LD block(s), 0 parse error(s), and types Answer, FAQPage, Organization, Question, WebSite.
Public or paywalled content
No isAccessibleForFree structured-data value was detected.
Entity clarity
Detected 3 of 3 core identity signals across the title, description, and H1.
Answer-ready visible text
Detected 896 visible words and 19 audience, use-case, pricing, or integration signals.
Authorship and accountability
No author meta value or structured-data author was detected.
Published or updated date
No datePublished or dateModified value was detected in structured data.
Supporting-source links
Detected 10 external source or reference link(s); link quality still requires editorial review.
Rendered content availability
Rendered audit completed with 119 visible text element(s).
Synthetic search-agent reachability
8 of 8 search/discovery User-Agent probes returned reachable content.
Optional LLM-readable summary
No llms.txt file was found; this is optional and does not reduce core AEO readiness.
OAI-SearchBotAI search
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
GPTBotModel training
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
ChatGPT-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
ClaudeBotModel training
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
Claude-SearchBotAI search
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
Claude-UserUser-requested fetch
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
GooglebotSearch and discovery
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
Google-ExtendedData-use policy control
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
BingbotSearch and discovery
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
PerplexityBotAI search
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
Perplexity-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
ApplebotSearch and discovery
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
Applebot-ExtendedData-use policy control
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
MistralAI-IndexAI search
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
MistralAI-UserUser-requested fetch
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
meta-externalagentModel training
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
meta-externalfetcherUser-requested fetch
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
AmazonbotModel training
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
Amzn-SearchBotAI search
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
Amzn-UserUser-requested fetch
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
CCBotModel training
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
Ready combines robots policy, a bounded synthetic User-Agent fetch, indexability, and snippet eligibility. Synthetic probes do not prove vendor-origin traffic. Purple preference states are training or data-use choices and do not lower the AEO score.
Share preview
hitou.site website audit report
Close to ready: 81/100 overall, with prioritized fixes for SEO, security, accessibility, and design.
Public reports expose the scanned public URL, safe scores, sanitized public evidence, and fix guidance. They do not include credentials, cookies, hidden form values, or sensitive response bodies.
