Website audit scorecard for permeantos.org
The scanner fetched the public page, extracted deterministic facts, and stored scored results across SEO / AEO, security, accessibility, and design.
Submitted
https://permeantos.org/
Final URL
https://www.permeantos.org
Created
Aug 4, 2026, 10:43 PM
Safe fetch
131 ms
77
out of 100
89
out of 100
99/111 rule points
62
out of 100
47/76 rule points
72
out of 100
68/94 rule points
83
out of 100
91/110 rule points
Category point breakdown
Biggest score-losing checks
axe found 1 violation rule(s), including 1 serious or critical rule(s). Top rules: color-contrast (11).
A small allowlist probe returned a public success response.
Detected 2 of 5 common public security headers. Present: x-content-type-options, referrer-policy. Missing: strict-transport-security, content-security-policy, x-frame-options.
sitemap.xml returned HTTP success but did not contain a urlset or sitemapindex root.
Remove exposed sensitive files
-16 rule ptsWhat failed
A small public allowlist probe found a sensitive-looking file path.
Evidence
A small allowlist probe returned a public success response.
Priority
Priority 1: fix before sharing the page publicly.
Why it matters
Publicly exposed config or backup files can leak implementation details or secrets.
How to fix it
Remove the exposed file, block public access to that path, and rotate any secrets that may have been exposed.
Copyable agent prompt
Fix rendered axe accessibility violations
-18 rule ptsWhat failed
The rendered page has accessibility rule violations detected by axe-core.
Evidence
axe found 1 violation rule(s), including 1 serious or critical rule(s). Top rules: color-contrast (11).
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
How to fix it
Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Copyable agent prompt
Add common public security headers
-13 rule ptsWhat failed
Several basic browser protection headers were not visible.
Evidence
Detected 2 of 5 common public security headers. Present: x-content-type-options, referrer-policy. Missing: strict-transport-security, content-security-policy, x-frame-options.
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
These headers reduce avoidable browser-side risk and show a baseline of care before launch.
How to fix it
Configure headers such as Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy.
Copyable agent prompt
Publish a valid sitemap.xml
-12 rule ptsWhat failed
The sitemap file was not reachable or did not look like valid sitemap XML.
Evidence
sitemap.xml returned HTTP success but did not contain a urlset or sitemapindex root.
Priority
Priority 7: fix during launch polish.
Why it matters
A sitemap helps search engines discover the landing page and related public pages sooner.
How to fix it
Add a static sitemap file or dynamic /sitemap.xml route with valid urlset or sitemapindex XML, include your public canonical URLs, and confirm it returns HTTP 200.
Copyable agent prompt
Fix rendered layout ergonomics
-9 rule ptsWhat failed
The browser-rendered page has layout or tap-target issues.
Evidence
Horizontal overflow: 0px. Small tap targets: 18.
Priority
Priority 13: fix during launch polish.
Why it matters
Horizontal overflow and tiny tap targets make the page feel broken on real devices, especially for mobile visitors.
How to fix it
Remove elements wider than the viewport, add responsive constraints, and make important links, buttons, inputs, and controls at least 40px tall and wide where possible.
Copyable agent prompt
SEO / AEO
Severity mix: 1 critical, 7 high, 3 medium, 1 low.
sitemap.xml validity
-12 rule ptssitemap.xml returned HTTP success but did not contain a urlset or sitemapindex root.
Security
Severity mix: 2 critical, 3 high, 0 medium, 0 low.
Sensitive file probes
-16 rule ptsA small allowlist probe returned a public success response.
Common security headers
-13 rule ptsDetected 2 of 5 common public security headers. Present: x-content-type-options, referrer-policy. Missing: strict-transport-security, content-security-policy, x-frame-options.
Accessibility
Severity mix: 0 critical, 3 high, 5 medium, 0 low.
Rendered axe accessibility violations
-18 rule ptsaxe found 1 violation rule(s), including 1 serious or critical rule(s). Top rules: color-contrast (11).
Basic contrast
-8 rule pts20 of 100 rendered text color sample(s) missed WCAG contrast targets. Worst rendered ratio: 1.
Design
Severity mix: 0 critical, 3 high, 6 medium, 2 low.
Trust signals
-10 rule ptsDetected 0 trust-signal keyword occurrence(s).
Rendered layout ergonomics
-9 rule ptsHorizontal overflow: 0px. Small tap targets: 18.
Showing failed checks.
Failed checks
These checks need attention.
sitemap.xml validity
0/12sitemap.xml returned HTTP success but did not contain a urlset or sitemapindex root.
Failed: earned 0 of 12 points.
Priority: Priority 7: fix during launch polish.
Why it matters: A sitemap helps search engines discover the landing page and related public pages sooner.
Fix: Add a static sitemap file or dynamic /sitemap.xml route with valid urlset or sitemapindex XML, include your public canonical URLs, and confirm it returns HTTP 200.
Copyable agent prompt
Common security headers
5/18Detected 2 of 5 common public security headers. Present: x-content-type-options, referrer-policy. Missing: strict-transport-security, content-security-policy, x-frame-options.
Failed: earned 5 of 18 points from partial coverage.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: These headers reduce avoidable browser-side risk and show a baseline of care before launch.
Fix: Configure headers such as Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy.
Copyable agent prompt
Sensitive file probes
0/16A small allowlist probe returned a public success response.
Failed: earned 0 of 16 points.
Priority: Priority 1: fix before sharing the page publicly.
Why it matters: Publicly exposed config or backup files can leak implementation details or secrets.
Fix: Remove the exposed file, block public access to that path, and rotate any secrets that may have been exposed.
Copyable agent prompt
Basic contrast
0/820 of 100 rendered text color sample(s) missed WCAG contrast targets. Worst rendered ratio: 1.
Failed: earned 0 of 8 points.
Priority: Priority 20: lower-risk cleanup after urgent launch blockers.
Why it matters: Low contrast makes a launch page feel less polished and can exclude users with low vision.
Fix: Review key text, buttons, and links against a 4.5:1 contrast target for normal text.
Copyable agent prompt
Rendered axe accessibility violations
0/18axe found 1 violation rule(s), including 1 serious or critical rule(s). Top rules: color-contrast (11).
Failed: earned 0 of 18 points.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
Fix: Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Copyable agent prompt
Trust signals
0/10Detected 0 trust-signal keyword occurrence(s).
Failed: earned 0 of 10 points.
Priority: Priority 16: lower-risk cleanup after urgent launch blockers.
Why it matters: Trust signals reduce hesitation when strangers see the product for the first time.
Fix: Add honest proof such as customer quotes, usage stats, founder credibility, security notes, or relevant logos.
Copyable agent prompt
Rendered layout ergonomics
0/9Horizontal overflow: 0px. Small tap targets: 18.
Failed: earned 0 of 9 points.
Priority: Priority 13: fix during launch polish.
Why it matters: Horizontal overflow and tiny tap targets make the page feel broken on real devices, especially for mobile visitors.
Fix: Remove elements wider than the viewport, add responsive constraints, and make important links, buttons, inputs, and controls at least 40px tall and wide where possible.
Copyable agent prompt
Page-level AEO readiness
Shared eligibility and content signals that affect every search and answer agent.
Index and citation eligibility
No general noindex directive was detected.
Snippet and answer controls
No general nosnippet or max-snippet:0 control was detected.
Canonical alignment
The canonical resolves to the scanned public URL.
Sitemap coverage and freshness
The exact scanned URL was not found in the fetched sitemap.xml.
Structured data
Detected 1 JSON-LD block(s), 0 parse error(s), and types SoftwareSourceCode.
Public or paywalled content
No isAccessibleForFree structured-data value was detected.
Entity clarity
Detected 3 of 3 core identity signals across the title, description, and H1.
Answer-ready visible text
Detected 891 visible words and 15 audience, use-case, pricing, or integration signals.
Authorship and accountability
No author meta value or structured-data author was detected.
Published or updated date
No datePublished or dateModified value was detected in structured data.
Supporting-source links
Detected 3 external source or reference link(s); link quality still requires editorial review.
Rendered content availability
Rendered audit completed with 199 visible text element(s).
Synthetic search-agent reachability
8 of 8 search/discovery User-Agent probes returned reachable content.
Optional LLM-readable summary
https://www.permeantos.org/llms.txt returned HTTP 200; this is supplemental and does not determine AI-search eligibility.
OAI-SearchBotAI search
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large
GPTBotModel training
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large
ChatGPT-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large
ClaudeBotModel training
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large
Claude-SearchBotAI search
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large
Claude-UserUser-requested fetch
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large
GooglebotSearch and discovery
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large
Google-ExtendedData-use policy control
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large
BingbotSearch and discovery
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large
PerplexityBotAI search
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large
Perplexity-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large
ApplebotSearch and discovery
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large
Applebot-ExtendedData-use policy control
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large
MistralAI-IndexAI search
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large
MistralAI-UserUser-requested fetch
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large
meta-externalagentModel training
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large
meta-externalfetcherUser-requested fetch
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large
AmazonbotModel training
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large
Amzn-SearchBotAI search
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large
Amzn-UserUser-requested fetch
Robots: allowed by * allow: / · line 2
Probe: reachable · HTTP 200 · 100% parity
Controls: robots meta: index, follow, max-image-preview:large
CCBotModel training
Robots: allowed by * allow: / · line 2
Probe: not tested for this control
Controls: robots meta: index, follow, max-image-preview:large
Ready combines robots policy, a bounded synthetic User-Agent fetch, indexability, and snippet eligibility. Synthetic probes do not prove vendor-origin traffic. Purple preference states are training or data-use choices and do not lower the AEO score.
Share preview
permeantos.org website audit report
Close to ready: 77/100 overall, with prioritized fixes for SEO, security, accessibility, and design.
Public reports expose the scanned public URL, safe scores, sanitized public evidence, and fix guidance. They do not include credentials, cookies, hidden form values, or sensitive response bodies.
