Website audit scorecard for minikode.my.id
The scanner fetched the public page, extracted deterministic facts, and stored scored results across SEO / AEO, security, accessibility, and design.
Submitted
minikode.my.id
Final URL
https://minikode.my.id
Created
Aug 7, 2026, 4:19 AM
Safe fetch
187 ms
Evidence: security probe returned HTTP 403. Cloudflare header(s): cf-ray, server. URL: https://minikode.my.id/wp-config.php
Review Cloudflare WAF, bot protection, rate-limit, and challenge rules for public marketing/content routes. Allow safe public scans and legitimate search or AI user-fetch crawlers to reach public pages while keeping admin, authenticated, preview, and private paths protected.
53
out of 100
66
out of 100
68/103 rule points
61
out of 100
46/76 rule points
50
out of 100
47/94 rule points
35
out of 100
38/110 rule points
Category point breakdown
Biggest score-losing checks
axe found 3 violation rule(s), including 2 serious or critical rule(s). Top rules: color-contrast (4), link-name (3), heading-order (1).
A small allowlist probe returned a public success response.
Detected 1 of 5 common public security controls. Present: strict-transport-security. Missing: content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Detected 0 CTA candidate(s).
Remove exposed sensitive files
-16 rule ptsWhat failed
A small public allowlist probe found a sensitive-looking file path.
Evidence
A small allowlist probe returned a public success response.
Priority
Priority 1: fix before sharing the page publicly.
Why it matters
Publicly exposed config or backup files can leak implementation details or secrets.
How to fix it
Remove the exposed file, block public access to that path, and rotate any secrets that may have been exposed.
Copyable agent prompt
Improve AI search and crawler readiness
-1 rule ptsWhat failed
One or more AI discovery, user-fetch, indexability, snippet, synthetic reachability, or sitemap signals need attention.
Evidence
FreeScan.app reached the public page with HTTP 200. robots.txt blocks Claude-SearchBot, PerplexityBot from AI search or discovery for this page path. Synthetic or robots checks block Claude-User, MistralAI-User from user-requested fetches. GPTBot, ClaudeBot, Google-Extended, and 4 more are explicit training or data-use opt-outs and do not reduce the AEO score. AEO crawler readiness is 93%: discovery 45/45, index and snippet eligibility 25/25, synthetic reachability 13/20, sitemap freshness 10/10.
Priority
Priority 2: fix before sharing the page publicly.
Why it matters
AI search systems need crawlable, reachable, indexable, and quotable public content. Training and data-use choices remain neutral publisher preferences.
How to fix it
Use the component scores and exact matched robots rules in the crawler report. Fix blocked search agents, noindex or snippet restrictions, canonical or sitemap gaps, and synthetic WAF/challenge failures. Preserve intentional training opt-outs and keep private, admin, and authenticated paths protected before rescanning.
Copyable agent prompt
Add common public security headers
-14 rule ptsWhat failed
Several basic browser protection headers were not visible.
Evidence
Detected 1 of 5 common public security controls. Present: strict-transport-security. Missing: content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
These headers reduce avoidable browser-side risk and show a baseline of care before launch.
How to fix it
Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Copyable agent prompt
Fix rendered axe accessibility violations
-18 rule ptsWhat failed
The rendered page has accessibility rule violations detected by axe-core.
Evidence
axe found 3 violation rule(s), including 2 serious or critical rule(s). Top rules: color-contrast (4), link-name (3), heading-order (1).
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
How to fix it
Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Copyable agent prompt
Make the primary CTA obvious
-14 rule ptsWhat failed
The page does not have a detectable call to action.
Evidence
Detected 0 CTA candidate(s).
Priority
Priority 4: fix before sharing the page publicly.
Why it matters
Early visitors need a clear next step, such as trying the product, joining a waitlist, or booking a demo.
How to fix it
Add one prominent CTA above the fold with action-oriented text such as Start, Join, Try, Book, or Get started.
Copyable agent prompt
SEO / AEO
Severity mix: 1 critical, 6 high, 3 medium, 1 low.
Crawler access
-1 rule ptsFreeScan.app reached the public page with HTTP 200. robots.txt blocks Claude-SearchBot, PerplexityBot from AI search or discovery for this page path. Synthetic or robots checks block Claude-User, MistralAI-User from user-requested fetches. GPTBot, ClaudeBot, Google-Extended, and 4 more are explicit training or data-use opt-outs and do not reduce the AEO score. AEO crawler readiness is 93%: discovery 45/45, index and snippet eligibility 25/25, synthetic reachability 13/20, sitemap freshness 10/10.
Meta description
-10 rule ptsMeta description is 178 characters.
Schema presence
-10 rule ptsDetected 0 JSON-LD schema block(s).
Security
Severity mix: 2 critical, 3 high, 0 medium, 0 low.
Sensitive file probes
-16 rule ptsA small allowlist probe returned a public success response.
Common security headers
-14 rule ptsDetected 1 of 5 common public security controls. Present: strict-transport-security. Missing: content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Accessibility
Severity mix: 0 critical, 3 high, 5 medium, 0 low.
Rendered axe accessibility violations
-18 rule ptsaxe found 3 violation rule(s), including 2 serious or critical rule(s). Top rules: color-contrast (4), link-name (3), heading-order (1).
Heading order
-11 rule ptsHeading levels found: none.
Landmark presence
-10 rule ptsDetected 0 landmark element(s) or roles.
Design
Severity mix: 0 critical, 3 high, 6 medium, 2 low.
Visible primary CTA
-14 rule ptsDetected 0 CTA candidate(s).
Hero clarity signals
-13 rule ptsDetected 0 H1 heading(s) and 178 meta-description characters.
Text density
-10 rule ptsDetected about 5 visible word(s). General page range: 80-1800 words.
Showing failed checks.
Failed checks
These checks need attention.
Crawler access
13/14FreeScan.app reached the public page with HTTP 200. robots.txt blocks Claude-SearchBot, PerplexityBot from AI search or discovery for this page path. Synthetic or robots checks block Claude-User, MistralAI-User from user-requested fetches. GPTBot, ClaudeBot, Google-Extended, and 4 more are explicit training or data-use opt-outs and do not reduce the AEO score. AEO crawler readiness is 93%: discovery 45/45, index and snippet eligibility 25/25, synthetic reachability 13/20, sitemap freshness 10/10.
Failed: earned 13 of 14 points from partial coverage.
Priority: Priority 2: fix before sharing the page publicly.
Why it matters: AI search systems need crawlable, reachable, indexable, and quotable public content. Training and data-use choices remain neutral publisher preferences.
Fix: Use the component scores and exact matched robots rules in the crawler report. Fix blocked search agents, noindex or snippet restrictions, canonical or sitemap gaps, and synthetic WAF/challenge failures. Preserve intentional training opt-outs and keep private, admin, and authenticated paths protected before rescanning.
Copyable agent prompt
Meta description
0/10Meta description is 178 characters.
Failed: earned 0 of 10 points.
Priority: Priority 3: fix before sharing the page publicly.
Why it matters: A missing description makes previews weaker when early users share or find the page.
Fix: Add a meta description around 50 to 170 characters that says who the product helps and what outcome it creates.
Copyable agent prompt
Heading structure
0/8Detected 0 H1 heading(s) and 0 total headings.
Failed: earned 0 of 8 points.
Priority: Priority 9: fix during launch polish.
Why it matters: Clear headings help visitors, search engines, and assistive technology understand the page quickly.
Fix: Keep one H1 for the main promise, then use H2 and H3 headings in order for sections below it.
Copyable agent prompt
Schema presence
0/10Detected 0 JSON-LD schema block(s).
Failed: earned 0 of 10 points.
Priority: Priority 12: fix during launch polish.
Why it matters: Structured data gives search and answer engines explicit facts about your product.
Fix: Add JSON-LD for SoftwareApplication, Product, Organization, or WebSite using only accurate public facts.
Copyable agent prompt
Internal link basics
0/6Detected 0 internal link(s).
Failed: earned 0 of 6 points.
Priority: Priority 16: lower-risk cleanup after urgent launch blockers.
Why it matters: Internal links help visitors find pricing, docs, contact, legal, or product details without getting stuck.
Fix: Add clear public links such as pricing, docs, contact, privacy, terms, or product detail pages where appropriate.
Copyable agent prompt
Common security headers
4/18Detected 1 of 5 common public security controls. Present: strict-transport-security. Missing: content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Failed: earned 4 of 18 points from partial coverage.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: These headers reduce avoidable browser-side risk and show a baseline of care before launch.
Fix: Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Copyable agent prompt
Sensitive file probes
0/16A small allowlist probe returned a public success response.
Failed: earned 0 of 16 points.
Priority: Priority 1: fix before sharing the page publicly.
Why it matters: Publicly exposed config or backup files can leak implementation details or secrets.
Fix: Remove the exposed file, block public access to that path, and rotate any secrets that may have been exposed.
Copyable agent prompt
Heading order
0/11Heading levels found: none.
Failed: earned 0 of 11 points.
Priority: Priority 13: fix during launch polish.
Why it matters: A clean heading outline helps visitors scan the page and helps assistive technology navigate it.
Fix: Use headings in order: one H1, then H2 for major sections, then H3 for subsections.
Copyable agent prompt
Landmark presence
0/10Detected 0 landmark element(s) or roles.
Failed: earned 0 of 10 points.
Priority: Priority 18: lower-risk cleanup after urgent launch blockers.
Why it matters: Landmarks make the page easier to navigate for assistive technology and keyboard users.
Fix: Use semantic elements such as header, nav, main, and footer around the appropriate page areas.
Copyable agent prompt
Basic contrast
0/88 of 100 rendered text color sample(s) missed WCAG contrast targets. Worst rendered ratio: 1.07.
Failed: earned 0 of 8 points.
Priority: Priority 20: lower-risk cleanup after urgent launch blockers.
Why it matters: Low contrast makes a launch page feel less polished and can exclude users with low vision.
Fix: Review key text, buttons, and links against a 4.5:1 contrast target for normal text.
Copyable agent prompt
Rendered axe accessibility violations
0/18axe found 3 violation rule(s), including 2 serious or critical rule(s). Top rules: color-contrast (4), link-name (3), heading-order (1).
Failed: earned 0 of 18 points.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
Fix: Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Copyable agent prompt
Visible primary CTA
0/14Detected 0 CTA candidate(s).
Failed: earned 0 of 14 points.
Priority: Priority 4: fix before sharing the page publicly.
Why it matters: Early visitors need a clear next step, such as trying the product, joining a waitlist, or booking a demo.
Fix: Add one prominent CTA above the fold with action-oriented text such as Start, Join, Try, Book, or Get started.
Copyable agent prompt
Hero clarity signals
0/13Detected 0 H1 heading(s) and 178 meta-description characters.
Failed: earned 0 of 13 points.
Priority: Priority 6: fix during launch polish.
Why it matters: Visitors decide quickly whether the product is relevant; a vague hero weakens every acquisition channel.
Fix: Use one clear H1 plus supporting copy that names the audience, problem, and outcome.
Copyable agent prompt
Text density
0/10Detected about 5 visible word(s). General page range: 80-1800 words.
Failed: earned 0 of 10 points.
Priority: Priority 21: lower-risk cleanup after urgent launch blockers.
Why it matters: Too little copy can leave visitors confused; too much copy can bury the value proposition.
Fix: Add concise sections for value, proof, how it works, and next steps, then remove repetitive copy.
Copyable agent prompt
Trust signals
0/10Detected 0 trust-signal keyword occurrence(s).
Failed: earned 0 of 10 points.
Priority: Priority 16: lower-risk cleanup after urgent launch blockers.
Why it matters: Trust signals reduce hesitation when strangers see the product for the first time.
Fix: Add honest proof such as customer quotes, usage stats, founder credibility, security notes, or relevant logos.
Copyable agent prompt
Spacing consistency
0/7Detected 0 spacing class/style signal(s).
Failed: earned 0 of 7 points.
Priority: Priority 25: lower-risk cleanup after urgent launch blockers.
Why it matters: Consistent spacing helps the page feel deliberate and easier to scan.
Fix: Use consistent section padding, gaps, and margins across repeated content blocks.
Copyable agent prompt
Visual hierarchy
0/9Detected 0 hierarchy signal(s) from headings, CTA, and emphasized text.
Failed: earned 0 of 9 points.
Priority: Priority 12: fix during launch polish.
Why it matters: Hierarchy tells visitors what to read first and what action to take next.
Fix: Create a clear H1, supportive section headings, emphasized proof, and one visually prominent primary CTA.
Copyable agent prompt
Rendered layout ergonomics
0/9Horizontal overflow: 0px. Small tap targets: 14.
Failed: earned 0 of 9 points.
Priority: Priority 13: fix during launch polish.
Why it matters: Horizontal overflow and tiny tap targets make the page feel broken on real devices, especially for mobile visitors.
Fix: Remove elements wider than the viewport, add responsive constraints, and make important links, buttons, inputs, and controls at least 40px tall and wide where possible.
Copyable agent prompt
Page-level AEO readiness
Shared eligibility and content signals that affect every search and answer agent.
Index and citation eligibility
No general noindex directive was detected.
Snippet and answer controls
No general nosnippet or max-snippet:0 control was detected.
Canonical alignment
The canonical resolves to the scanned public URL.
Sitemap coverage and freshness
The exact URL appears in the fetched sitemap with lastmod 2026-05-17.
Structured data
Detected 0 JSON-LD block(s), 0 parse error(s), and types none.
Public or paywalled content
No isAccessibleForFree structured-data value was detected.
Entity clarity
Detected 2 of 3 core identity signals across the title, description, and H1.
Answer-ready visible text
Detected 5 visible words and 0 audience, use-case, pricing, or integration signals.
Authorship and accountability
Detected author or accountable entity: Minikode.
Published or updated date
No datePublished or dateModified value was detected in structured data.
Supporting-source links
No external supporting links were detected; this is contextual rather than a universal requirement.
Rendered content availability
Rendered audit completed with 181 visible text element(s).
Synthetic search-agent reachability
6 of 8 search/discovery User-Agent probes returned reachable content.
Optional LLM-readable summary
https://minikode.my.id/llms.txt returned HTTP 200; this is supplemental and does not determine AI-search eligibility.
OAI-SearchBotAI search
Robots: allowed by * allow: / · line 31
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow
GPTBotModel training
Robots: blocked by gptbot disallow: / · line 55
Probe: not tested for this control
Controls: robots meta: index, follow
ChatGPT-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
Controls: robots meta: index, follow
ClaudeBotModel training
Robots: blocked by claudebot disallow: / · line 46
Probe: not tested for this control
Controls: robots meta: index, follow
Claude-SearchBotAI search
Robots: allowed by * allow: / · line 31
Probe: blocked · HTTP 403
Controls: robots meta: index, follow
Claude-UserUser-requested fetch
Robots: allowed by * allow: / · line 31
Probe: blocked · HTTP 403
Controls: robots meta: index, follow
GooglebotSearch and discovery
Robots: allowed by googlebot allow: / · line 63
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow
Google-ExtendedData-use policy control
Robots: blocked by google-extended disallow: / · line 52
Probe: not tested for this control
Controls: robots meta: index, follow
BingbotSearch and discovery
Robots: allowed by bingbot allow: / · line 66
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow
PerplexityBotAI search
Robots: allowed by * allow: / · line 31
Probe: blocked · HTTP 403
Controls: robots meta: index, follow
Perplexity-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
Controls: robots meta: index, follow
ApplebotSearch and discovery
Robots: allowed by * allow: / · line 31
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow
Applebot-ExtendedData-use policy control
Robots: blocked by applebot-extended disallow: / · line 37
Probe: not tested for this control
Controls: robots meta: index, follow
MistralAI-IndexAI search
Robots: allowed by * allow: / · line 31
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow
MistralAI-UserUser-requested fetch
Robots: allowed by * allow: / · line 31
Probe: blocked · HTTP 403
Controls: robots meta: index, follow
meta-externalagentModel training
Robots: blocked by meta-externalagent disallow: / · line 58
Probe: not tested for this control
Controls: robots meta: index, follow
meta-externalfetcherUser-requested fetch
Robots: allowed by * allow: / · line 31
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow
AmazonbotModel training
Robots: blocked by amazonbot disallow: / · line 34
Probe: not tested for this control
Controls: robots meta: index, follow
Amzn-SearchBotAI search
Robots: allowed by * allow: / · line 31
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow
Amzn-UserUser-requested fetch
Robots: allowed by * allow: / · line 31
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow
CCBotModel training
Robots: blocked by ccbot disallow: / · line 43
Probe: not tested for this control
Controls: robots meta: index, follow
Ready combines robots policy, a bounded synthetic User-Agent fetch, indexability, and snippet eligibility. Synthetic probes do not prove vendor-origin traffic. Purple preference states are training or data-use choices and do not lower the AEO score.
Share preview
minikode.my.id website audit report
Needs fixes before launch: 53/100 overall, with prioritized fixes for SEO, security, accessibility, and design.
Public reports expose the scanned public URL, safe scores, sanitized public evidence, and fix guidance. They do not include credentials, cookies, hidden form values, or sensitive response bodies.
