Mega Analyzer Changelog

Back to methodology · Open the tool

Dated history of probe additions, scoring weight changes, and false-positive guards. The check set is versioned so external citations to specific scores stay reproducible.

v2026.09.26 ·

One false page-type count, relative links, and two display fixes

No new rows and no weight changes. Two fixes change a verdict on some sites; the other two change only how rows look.

  • Translations are not a second page-type node: a workTranslation or translationOfWork reference points at the page in the other language, so it no longer counts toward "page-type nodes describing this URL". A bilingual site whose English WebPage referenced its Spanish twin as {"@type":"WebPage","@id":"https://example.com/es/#webpage"} read "Multiple page-type blocks describing this URL (2)", showed DILUTION on the entity-anchor signal and lost the single-page-type points. Every other page-type node, anywhere in the graph, is still counted.
  • Relative canonical, feed and Webmention links: these are now resolved against the audited page, and against its own <base href> when it has one. They were resolved against jwatte.com, so a relative canonical such as href="/" read "Canonical points to jwatte.com" and was treated as pointing off the site.
  • Crawl Health formatting: these rows showed their own formatting as raw text. The ARD rows ended in "<br><br>Learn more: <a href=...>", and other rows read "&lt;head&gt;" instead of "<head>". Their line breaks, code spans and links to our own articles and tools now render. Anything taken from the audited site is still shown as plain text.
  • Phones: a JSON-LD example with no spaces in the B2B SaaS readiness row made the Perf + AI tab 665px wide, so a phone zoomed the whole page out to fit it. Long unbroken text now wraps inside its row.

v2026.09.24 ·

Meta's crawlers, link previews, and the WebMCP registerTool change

Meta publishes no "Muse" standard for websites (checked September 24, 2026). What it does document for site owners is five robots.txt tokens, the limits its link-preview crawler works within, and WhatsApp's own preview limits. These rows test those, plus three results from a Facebook Sharing Debugger test we ran on September 24. They sit in Perf + AI, in the AI Search Readiness and Social preview readiness cards, and rows marked for information never cost points. Background: Is Your Site Ready for Meta Muse? There Is No Standard. Here Is What Meta Actually Documents. The full single-site version is the Meta AI Crawler + Link Preview Audit.

  • Meta-WebIndexer: the crawler behind Meta AI citations, resolved under RFC 9309 through the shared parser at /js/rfc9309-robots.js. A robots.txt that answers 4xx counts as allow-all, one that answers 5xx as a complete disallow, and one we could not read is "not verified". Meta-WebIndexer also joins the answer-engine crawler row, and that row's score now covers it.
  • The five Meta tokens: a table showing which group facebookexternalhit, Meta-WebIndexer, Meta-ExternalAgent, Meta-ExternalFetcher and Meta-ExternalAds each obey, the verdict at the scanned path, and any Content-Signal line in that group. It only warns (and scores) when facebookexternalhit is disallowed, because that blanks every shared link.
  • robots.txt groups: named groups that can fetch paths the * group blocks (a named group inherits nothing from *), and rules stranded below a blank line or comment inside a named group, which still bind to it. A blanket Disallow: / under * with named Allow groups is the deliberate allow-list pattern and is not reported.
  • Link-preview crawler access: the page is requested as facebookexternalhit and as Meta-WebIndexer and compared with the normal request. A refusal (403, 503 or a challenge page) fails, and a different og:title or og:image warns. A refusal the normal request also got, or a bare 429, is not judged. Skipped in fast mode.
  • Range request: Meta's crawler sends Range: bytes=0-524288. A 200 (Range ignored) or a 206 whose body matches its Content-Range passes; a 206 whose body length disagrees with Content-Range warns; a 416, or returned bytes without the og: tags, fails. A reply our proxy could not decode is not checked for og: tags.
  • Open Graph placement: byte offsets of every og: tag and of </head>. An og: tag past Meta's first 1 MB, a head that ends after WhatsApp's first 300 KB, or og:title, og:description or og:url after </head> fails; other og: tags after it warn.
  • og:image file size: over 8,000,000 bytes fails (in our test a 9,430,028-byte PNG came back "Image Too Big"), and over 600 KB warns for WhatsApp. The size comes from Content-Length (not used when that reply is compressed, because it is then the encoded size), or from counting the bytes when the server sends none.
  • og:image format: JPEG, PNG and GIF pass. WebP is for information only: it is outside Meta's documented list, but it rendered as the normal large card in our test. AVIF is for information only and untested. SVG warns, because in our test it rendered only as a small, cropped square thumbnail. An og:image:type that disagrees with the file also warns.
  • og:image real size: measured in the browser, or read from the file header when the image cannot load here (an image that sends Cross-Origin-Resource-Policy same-site or same-origin is read from the header without trying the browser). An SVG has no fixed pixel size, so its size is for information only and the format row carries the verdict. Under 200x200 fails; missing or wrong og:image:width and og:image:height, under 600x315, or outside WhatsApp's limits warns. When more than one og:image is present the order is listed (the first one is used), with a warning when the first fails and a later one would work.
  • Public phone number on a local business: for information only. Meta is testing Muse calls to businesses whose numbers are public, and the row links Meta's opt-out form. Taking those calls is a business decision.
  • WebMCP registration, rewritten: the WebMCP draft removed provideContext() on March 5, 2026 (pull request 132). The row now passes on registerTool() (on document.modelContext, or the navigator alias) in the page or in a WebMCP script it loads, and warns when only provideContext() is found. Only inline JavaScript and the loaded WebMCP scripts count, so an article that mentions the API is not read as calling it. A page with no agent actions and no WebMCP code gets its own "not applicable" row instead of the registerTool pass.
  • Form labels: the failing detail now notes that Meta says its Muse agent reads an accessibility tree snapshot, so an unlabeled field probably reaches it as a nameless control (our inference, not a Meta rule).

v2026.09.23 ·

Two iPhone form rows, judged from the page's own CSS

Every browser on an iPhone runs WebKit, and WebKit's iOS theme rewrites date fields after the page's CSS has run. Desktop Chrome never shows the result, so these rows read the CSS the page ships and work out what an iPhone does with it. Both sit in Perf + AI, under Mobile presentation. Background: Why iPhone date fields stick out of forms that look fine in desktop Chrome.

  • Date and time inputs not normalized for WebKit: for each date, time, datetime-local, month and week input, the cascade is resolved (importance, cascade layers, specificity, order, the style attribute) at 375 and at 430px wide, to see whether appearance: none or -webkit-appearance: none wins at both. It fails only when the page's own CSS sets a width, padding or border on the field (a reset such as padding: 0 or a page-wide * rule does not count) and nothing turns the iOS theme off, and only when every stylesheet the HTML links was read; otherwise it says "not verified" and names the unread files. A date field nobody styled is reported as the native control, for information, and one that is never drawn (hidden, opacity: 0, 1px by 1px) is left out. Media queries are evaluated at phone widths, including the range syntax and not; rules for print, for hover or fine pointers and for landscape only are left out.
  • Text fields below 16px: iPhone browsers zoom the page when a field under 16px takes focus. Font sizes are resolved through inheritance, rem against the root, var(), min(), max() and clamp() at 375 and at 430px, and a field under 16px at either width counts; a field with no font size of its own is 11px on iOS but is only counted when the page styles its box, and anything that cannot be resolved without layout is left out. Advisory, and hidden when the viewport tag already blocks zoom or the page has no mobile viewport.
  • What it reads: inline <style> blocks and the first two same-origin stylesheets, as before, plus, when the page has date or time inputs, up to four more stylesheets (later same-origin ones, other hosts, one level of @import). Font, icon and animation libraries are not counted as unread. It never renders the page or loads it as an iPhone, and CSS added later by scripts is not seen.
  • Checked against Chromium: on 15 live pages, the resolved font size of 99 text fields and the winning appearance of 19 date fields matched Chromium's computed style at 375 and at 430px, apart from one textarea that Chromium shrinks to 13px through its own monospace default, which iPhone WebKit does not have.

v2026.09.22b — (second release)

Fifteen more, mostly from data the run already had

The last of the candidates that need no capability the analyzer lacks. Several of these read signals that were already being collected for other rows and simply never rendered.

  • robots.txt blocking the AI discovery paths the audit itself fetches (llms.txt, the .well-known files, the sitemap, the markdown companions), evaluated with the same RFC 9309 parser as the answer-engine row. A site can publish llms.txt and forbid every compliant crawler from reading it.
  • Sitemap lastmod trustworthiness: future dates, unparseable values, or every entry sharing one build timestamp. Google uses lastmod only while it is consistently accurate and discounts it site-wide when it is not.
  • Navigation links a crawler cannot follow: a javascript: href, an empty href with a click handler, or a click handler on a div inside the nav or header.
  • Internal links on non-canonical variants: a different scheme or host, the same path linked in two letter cases, or the same path linked both with and without a trailing slash. Consistent camelCase URLs and a directory index that ends in a slash are not defects, so both tests compare a path against itself rather than against a house style.
  • A public JavaScript source map beside the first same-origin script, verified by parsing it rather than by the 200 alone.
  • security.txt validity per RFC 9116: a Contact field, an Expires date, and an Expires that is neither past nor more than a year out.
  • Sampled same-origin images that do not load (a HEAD on up to four), and camera or screenshot default filenames (IMG_4521.jpg, a bare content hash), which throw away the filename signal Google Images reads.
  • Social links that stop at a platform home page rather than a profile, including sameAs entries, which give Google no entity to reconcile.
  • Three privacy rows that reuse the policy this audit already fetches: a "Do Not Sell or Share" link when an advertising pixel loads, a policy with no last-updated date or one older than two years, and a policy still carrying its template placeholders.
  • CAA against the CA that actually issued the live certificate. The record says who may issue; the certificate says who did. When they disagree the site keeps working until the next renewal is refused, which is the kind of failure that surfaces at 2am on a holiday.
  • Two more shared WCAG rules: a positive tabindex (which pulls an element to the front of the tab order for the whole page), and focusable controls inside an aria-hidden="true" block that is still rendered, where keyboard focus lands on something a screen reader will not announce.

v2026.09.22 —

Sixteen more checks: the runners-up from the same review

The review that produced the previous release ranked far more candidates than it shipped. These are the ones that scored next, all of them measurable from the inputs the analyzer already has plus a handful of extra probes.

  • Canonical target reachable and indexable. When a page names a different URL as canonical, that URL is now fetched: a 404, a redirect away from it, or a noindex on it means Google discards the hint and picks its own canonical. Self-referencing canonicals pass without a fetch.
  • Launch leftovers. Links and assets pointing at localhost, a dev/staging/preview subdomain, an ngrok tunnel, a placeholder image service or example.com (the page's own host is excluded); a meta http-equiv="refresh" redirect where a 301 belongs; utm_, fbclid and gclid parameters on the site's own internal links; affiliate and paid links without rel="sponsored" (matched on known networks and affiliate-specific parameters, not on a bare ref=, which is ordinary attribution).
  • Directory listings on /uploads/, /images/, /assets/, /files/ and /backup/ (the WordPress path when WordPress is detected), each verified by an "Index of" signature rather than a 200 alone.
  • Sibling-host TLS. The www or apex twin gets its own handshake: a certificate that does not name it, or no certificate at all, is a browser warning for every visitor who types the other host form, and the redirect never gets a chance to run.
  • Local schema depth: Review nodes without an author or a ratingValue and AggregateRating nodes without a count; GeoCoordinates that are 0,0, out of range, or carry a longitude whose sign contradicts a US address; a PostalAddress that is a bare string or missing streetAddress, locality, region, postal code or country; hours printed on the page with no openingHoursSpecification behind them, which is what Maps and the AI assistants read for "open now".
  • Web app manifest actually installable (parses, has a name, a 192px and a 512px icon, a start_url and a standalone-style display), not merely linked.
  • Two more shared WCAG rules: controls nested inside other controls (a button inside a link), and unrecognized ARIA roles or misspelled aria-* attributes, which assistive technology ignores silently.
  • Email and DNS: the DKIM selector implied by the newsletter service the page's form posts to (Mailchimp, SendGrid, Mandrill, Amazon SES, Postmark, Zoho); an MX exchange with no A or AAAA record, which bounces inbound mail; and linked subdomains of your own domain that do not resolve, including a CNAME to a service that someone else could claim.

v2026.09.21b — (second release)

Sixty-four new checks, one new card, eight new tools

Ten independent reviews (performance, security, accessibility, technical SEO, AI and agent discovery, local business, privacy law, hygiene, email and DNS, multilingual and mobile) each proposed the checks a generalist 2026 audit is expected to carry and the analyzer did not; a second pass tried to prove each one was already there under other words; a third scored value and false-positive risk. Sixty-four survived and every one carries Learn, Fix and Audit pills. Anything that costs points is a visible row, as before.

  • Performance: the likely LCP image is found by position (before the first H2, inside a hero container, or in the first 15% of the body) and fails when it is lazy-loaded or JS-placeholdered; a second row asks for fetchpriority="high" or a preload; parser-blocking <script src> in <head>; embed iframes without loading="lazy"; web fonts without font-display (Google Fonts URLs, inline and same-origin @font-face); srcset with width descriptors but no sizes; HTML cached for hours without revalidation; sampled same-origin CSS/JS served uncompressed; unversioned assets cached immutable or fingerprinted assets cached under a day. The first two same-origin stylesheets and the first script are now fetched through the proxy (HEAD for the script).
  • Trust / Security Headers: mixed content (active vs passive, from a stub that had never been built); cookie flags on the first response (Secure, HttpOnly on session-looking names, SameSite, None-without-Secure); CSP quality ('unsafe-inline' with no nonce or hash, wildcards, report-only, no frame-ancestors); HSTS max-age and includeSubDomains; server, X-Powered-By and generator version disclosure; live API secrets in source (fixed-prefix patterns, masked); /.git/HEAD, /.env and wp-config.php.bak probes verified by content signature; WordPress REST user enumeration and xmlrpc.php (WordPress sites only); certificate expiry and chain validity from the existing TLS probe the analyzer had never called.
  • New card, Email + domain posture (DNS): DMARC presence (exactly one record) and enforcement (p=, t=y, pct), SPF validity (one record, an all mechanism, no +all, lookup mechanisms over ten), the DKIM selector the MX provider signs with (Google, Microsoft 365, Zoho, Proton, Fastmail), and whether the contact address on the page belongs to a domain that has MX at all. One probe-dns call.
  • Crawl Health: the http:// twin must redirect to https; the www/apex twin must redirect to the canonical host; robots.txt must not block the page’s own CSS/JS (RFC 9309 group semantics, longest-match, wildcards); canonical must be absolute, https, same-host and unique; sitemap URLs must use the canonical scheme and host; a URL in the sitemap must be indexable; <head> closed early (metadata parsed into the body, with the offending tag named); duplicate title, description, canonical or viewport tags.
  • E-E-A-T: stale footer copyright year; dateModified vs datePublished vs sitemap lastmod disagreement; Article author that is a plain string or a Person with no url, @id or sameAs.
  • AI Search Readiness: snippet suppression that removes the page from AI Overviews and AI Mode (nosnippet, max-snippet under 160, data-nosnippet on most of the body, googlebot-specific metas and X-Robots-Tag); noarchive / nocache (Bing Copilot); answer-engine crawlers (OAI-SearchBot, PerplexityBot, Claude-SearchBot, Applebot, bingbot, DuckAssistBot) evaluated per RFC 9309. The old five-point deduction for any disallowed AI bot is gone: blocking a training-only crawler is a legitimate choice with no citation cost.
  • Accessibility (shared with the Site Analyzer): eleven more quick rules: iframe accessible names, filename or placeholder alt text, keyboard-unreachable div controls, focus ring removed with no :focus-visible replacement (reads the fetched stylesheets), videos with sound and no captions track, autocomplete tokens on personal-data fields, radio and checkbox groups without fieldset, html lang invalid or contradicting the text (stopword detection across six languages), empty headings, aria / label / skip-link references to missing ids, data tables without header cells. The GTM <noscript> iframe that the parser hoists out of <head> is recognized from the raw markup and ignored.
  • Structured Data and Trust + Conversion: self-serving review markup on the business node; openingHoursSpecification and openingHours shape; placeholder contact data in JSON-LD; phone parity between JSON-LD, tel: links and visible text; visible numbers not tap-to-call; the privacy policy link resolves and names the trackers the page loads; pre-ticked consent checkboxes; session-replay recorders (informational); an advertising pixel on a healthcare-provider page.
  • Also: og:image fetched and checked for an image content-type; JS-only translation widgets; hreflang shape (BCP 47, absolute, self-reference); phone, email and ZIP fields that open the wrong mobile keyboard. The Mega AI fix prompt now carries every failing or advisory row from the rendered report.
  • Eight new tools back the rows that had no deep-dive: Cookie Flags Audit, Exposed Files Probe, Iframe Embed Audit, Asset Cache Policy Audit, Head Integrity Audit, Local Schema Validity Audit, Click to Call Audit and Privacy Disclosure Audit; ten companion articles explain the rows that had no on-topic post.

v2026.09.21 —

Every row gets its pills, eleven false positives closed, and “cannot” stops reading as “did not”

  • Learn / Fix / Audit on every check row. A static inventory of all 421 row titles (pass and fail wording) plus live runs on thirteen sites found 116 rows rendering without a pill cluster; 60 new resource entries close them, and the Retrieval (AEO) card gained a summary row so it carries pills too. The Full Summary copies of each row now match as well (the bucket badge and the N/A button were being read as part of the title, which defeated every anchored pattern).
  • DNS-AID SVCB reads n/a, not fail, on a DNS host that cannot publish it. The zone’s NS set is now probed alongside the agent records; a Netlify-DNS zone (NS1 delegation on a Netlify-served site) exposes no SVCB and no DNSSEC through its control plane, so the row is excluded from the Agent Readiness Score and the isitagentready.com figure — which still counts it as a failure — is printed beside ours instead of silently disagreeing.
  • OAuth discovery (RFC 8414 / 9728) is gated on a protected surface, not merely an agent surface. A site whose auth.md and manifests declare no authentication has no authorization server to describe; a 404 at /.well-known/oauth-protected-resource is the specified answer and the rows now say so.
  • Resource-hint advice counts hosts the page fetches assets from, not every absolute href. A hub page whose footer links to twelve sister domains read as “12 third-party hosts, 0 hints” while loading nothing cross-origin; a fully self-hosted page no longer fails for needing no hints, and a page whose only cross-origin loads are async analytics gets an info row (dns-prefetch at most).
  • Vertical classification is schema-first for lodging. A motel whose landmark copy mentioned a hospital was keyword-classified YMYL-Health and handed a critical “missing HIPAA notice”; the e-commerce module also fired on room-rate Offer nodes and, because the hotel module stands down to it, the hotel card never ran. Lodging schema without cart or commerce-platform signals is a hotel.
  • WCAG quick checks: a 1×1px skip link parked off-screen until focus is not a 24×24 pointer target; controls inside a [hidden] subtree (Netlify Forms’ registration shadow form) are not unlabelled form controls.
  • Scores now match the rows. A page with no failing row scored 91 because Wikidata, ORCID, kgmid, Gravatar, six-plus sameAs, <cite>, Speakable and mainEntityOfPage (all rendered as optional info rows) still cost points, info-severity crawl checks counted against SEO, the Voice score used stricter hidden bands than the Voice rows, and four Perf signals (HTML weight, DOM size, image dimensions, legacy image formats) were stat tiles rather than rows. Optional signals are now bonuses (present earns, absent costs nothing), the Voice score uses the same landing-page bands the rows show, the four Perf signals are check rows with pills, and alt="" on a decorative image no longer counts as missing alt. Rule going forward: anything that costs points is a visible row, and a row that reads as optional cannot cost points.
  • Sixteen new companion articles. Every Learn pill added in this release was re-read against its check; where the target post did not actually explain the signal, a dedicated article now does (landmarks and unique ids, placeholder leftovers, canonical target mismatch, content hub link, table of contents, expertise word count, sitemap slug hygiene, shipping policy page, Speakable selector validation, repeated site name in the title, visible contact signals, article:author meta, ImageObject creator, CreativeWork.usageInfo, x402, and the Organization node).
  • Smaller guards: the nav-item count is scoped to the primary nav (the whole document was being counted); a two-column key/value table needs no scroll wrapper; the team-page row is informational for a local business whose About page names the owner; a multi-property operator page (subOrganization list, no lodging type of its own) is not asked for its own TripAdvisor pin.

v2026.08.31 —

Agent-readiness parity, and four scoring corrections

  • Agent Readiness Score card reproduces isitagentready.com’s arithmetic so the two reports can be diffed line by line. Their check set was read from a live /api/scan response rather than from the rendered page.
  • DNS-AID probe widened to the seven queries they actually issue: SVCB and HTTPS at _index._agents, _a2a._agents and _mcp._agents, plus TXT at _index._agents. Previously only SVCB at _index was asked for, so a zone publishing an HTTPS record passed there and failed here. _catalog._agents is kept as a deliberate superset.
  • A2A Agent Card added to the parity card. Their discovery category carries nine checks and ours carried eight, so every site serving /.well-known/agent-card.json was undercounted.
  • Three parity rows now read the fetched artifact instead of a check row’s severity. Content Signals passed on any site with named per-bot rules and no Content-Signal line; x402 and MPP returned neutral on a real commerce surface and dropped out of the denominator, inflating the reproduced score.
  • Agent Skills v0.2.0 validation corrected. The required entry shape is name/type/description/url/digest, where type must be skill-md or archive and digest must be sha256:<64 hex> — not the Subresource-Integrity sha256-<base64> form. The $schema URI is an opaque identifier that deliberately does not resolve.
  • DNS-AID wildcard control probe. A wildcard in a parent zone answers ANY name, so an answer at _index._agents is not by itself evidence that a site published anything. Measured: every *.netlify.app name returns 1 . alpn=h2 for HTTPS at that label — including deliberately nonexistent ones — because it is Netlify’s generic HTTP/2 service binding. isitagentready.com scores that as a PASS, so every netlify.app site collects a free point there. The analyzer now runs a control lookup, discards anything matching it, and says so in the finding.
  • Known disagreement, kept on purpose: Web Bot Auth stays neutral. The http-message-signatures-directory is published by the bot operator to advertise its signing keys, not by the site receiving the requests.

v2026.06.22 —

Full-control hosts in the platform override

  • Platform override dropdown now lists Cloudflare Pages, Cloudflare Workers, Netlify, and Vercel as selectable static/edge hosts.
  • Because these hosts give full file control, root-file probes (ai.txt, llms.txt, AGENTS.md, security.txt, humans.txt) stay real findings rather than softening to informational.
  • Contrasts with locked builder platforms (Wix, Squarespace tenants, Linktree, etc.) where the same probes correctly downgrade to info.

v2026.06.17 —

Hotel/lodging and B2B-SaaS readiness modules

  • New hotel / lodging readiness module: Hotel/LodgingBusiness typing, check-in/check-out times, star rating, per-room HotelRoom/Offer, and a local-listing sameAs graph check (Google Hotels/Maps, Apple Maps, Yelp, TripAdvisor, OTAs).
  • New B2B SaaS / AI-product readiness module: SoftwareApplication/WebApplication typing, brand entity graph, WebSite node, FAQPage over a visible FAQ, per-route Open Graph, templated-<title> detection, and BreadcrumbList.
  • Each module gates on detected vertical and stands down to professional/commerce verticals to avoid double-flagging.

v2026.06.10 —

Per-site platform + vertical override dropdowns

  • New Audit alignment bar atop results with two dropdowns to correct the detected business vertical and platform. Changing either re-runs the whole audit — score, checks, and AI fix prompts regenerate.
  • Overrides save per site in your browser, so a corrected vertical or stack sticks across re-runs.
  • Platform fingerprint coverage expanded to ~60 stacks, adding headless CMSes (Sanity, Contentful), enterprise CMSes (Drupal, Optimizely), and many vertical-SaaS/local-marketing platforms.
  • Correcting the platform realigns the root-file softeners and [PLATFORM]/[VENDOR-CONTACT-REQUIRED] fix tagging to the real stack.

v2026.06.09 —

Large false-positive-guard wave (publishers, apps, testimonials)

  • Publisher / aggregator / app guard: sites typed NewsMediaOrganization, WebApplication, SoftwareApplication, Dataset, or Periodical (with no business-vertical schema) no longer get keyword-misclassified into YMYL, Local, or E-commerce.
  • Editorial pull-quotes and prose-shape voice metrics on publisher/app pages downgrade to informational; only density checks still fail.
  • @graph double-walk fixed across JSON-LD walkers — nodes inside one @graph are no longer counted twice (was inflating duplicate-node and date-field counts).
  • Self-quote testimonials exempted: a <blockquote> whose <cite> matches a Person/Org named in the page's own JSON-LD no longer counts as a customer review.
  • Outbound-marketplace stores (CTAs routing to a third-party marketplace, no on-site checkout) stop tripping agentic-commerce checks; appointment-only businesses can satisfy the hours check with a literal "by appointment" statement.
  • ImageObject licensing fields, Product/Offer suggestions, and review checks on publisher/app contexts downgrade to info per current Search Console guidance.

v2026.06.03 —

Craft-butcher / meat-DTC module + ACP feed validator

  • New craft-butcher / meat-DTC readiness layer atop e-commerce: hybrid GroceryStore/LocalBusiness typing, perishable cold-chain OfferShippingDetails, Recipe schema, provenance/countryOfOrigin, per-lb UnitPriceSpecification, and substantiation for USDA / grade / "Product of USA" claims.
  • New companion tool: ACP feed validator — checks a product feed against the Agentic Commerce spec (required fields, ISO-4217/ISO-3166 enums, conditional seller ToS + privacy on checkout, GTIN check-digit, NDJSON shape).
  • Regulated-claim regexes (superlatives, reviews, guarantees, provenance) now match a bounded title-plus-lead region instead of the whole page, so nav/footer/related-product carousels stop misattributing findings.
  • Wired Learn/Fix/Audit pills onto the CPA and defense-contractor cards (blocks existed without them).

v2026.06.02 —

Trade-company entity-typing fixes + HVAC module

  • Trade-company person-typing fixed: company types like HVACBusiness, GeneralContractor, Plumber, Electrician, and RoofingContractor are no longer nagged to dual-type as Person or carry worksFor — they're companies with a separately-named owner.
  • New HVAC / heating-and-cooling readiness module: HVACBusiness typing, EPA 608 / NATE / state-license trifecta, heat-pump growth nudge, permit / CO-safety, brands & maintenance-plan / financing signals.
  • Disabled a sitemap sub-check that fired "no usable XML sitemap" on trade home pages; sitemap coverage already lives in the crawl-health checks.
  • Breadcrumb check now exempts the site root; first-party relative scripts are no longer flagged as SRI-eligible (SRI is cross-origin only).

v2026.06.01 —

Electrician and men's-health readiness modules

  • New electrician / electrical-contractor readiness module: Electrician subtype, the http://www.schema.org @context defect, visible state-license-number display, per-service Service, EV-charger growth nudge, and permit/NEC compliance signal.
  • New men's-health / hormone-clinic readiness module (YMYL-Health): MedicalClinic typing, per-location identity, and E-E-A-T plus Ryan Haight / FDA / FTC / HIPAA compliance signals.
  • Both gate on detected vertical and stand down cleanly to adjacent local/professional verticals.

v2026.05.31 —

E-commerce, handyman, and brand-presence modules

  • New e-commerce / DTC readiness module: Product/Offer completeness (condition, priceValidUntil, GTIN/MPN/SKU, shipping, return policy, countryOfOrigin when "Made in X" appears), brand Organization @id + founder, review-as-data (FTC 16 CFR 465), CollectionPage/ItemList, and deceptive-pricing guards.
  • New handyman / home-services readiness module: LocalBusiness/HomeAndConstructionBusiness + NAP, per-trade Service, Google Business Profile probe, placeholder-555 phone trap, client-rendered-SPA invisibility trap, and a state-licensed-trade guardrail.
  • New brand presence / entity alignment check: sameAs breadth across Instagram, Pinterest, TikTok, Facebook, YouTube, LinkedIn, and Google Business Profile.

v2026.05.30 —

Production-homebuilder module + BigLaw layer

  • New production-homebuilder readiness module: firm HomeAndConstructionBusiness, per-community Place/areaServed/geo, SingleFamilyResidence + Offer (price/availability) on floor plans, plus Fair Housing 3604(c), RESPA Section 8, and TILA/Reg Z 1026.24 compliance checks.
  • New BigLaw / multinational-firm layer extending the legal module: ranking-directory sameAs (Chambers, Legal 500, Best Lawyers), corpus-scale Article + author binding, Event/VideoObject/PodcastEpisode on relevant paths, and hreflang-vs-office-footprint checks.
  • The BigLaw layer activates only for large/multinational firms; small-firm legal audits are unaffected.

v2026.05.21 —

Brand-copy quality and page-meta hygiene checks

  • New brand-copy checks: font-glyph-collision typos (e.g. capital-I vs lowercase-L), dev placeholders left in production (lorem ipsum, TBD, "coming soon"), joined-word headlines, and all-caps headings that should be CSS-uppercased.
  • New page-meta checks: over-long meta descriptions (Google rewrites past ~170 chars), missing og:image, and twitter:card downgrade detection.
  • New nonprofit checks (501(c)(3) sites): visible EIN and a stated 501(c)(3) status line for donor and grant-officer diligence.
  • New operational-hygiene checks: thank-you / confirmation funnel pages indexed without noindex, and thin pages missing noindex.

v2026.05.20 —

Platform fingerprinting, bot-challenge detection, and sitemap-debris checks

  • New bot-challenge detector: flags when the audited page is actually a Vercel / Cloudflare / AWS WAF / Imperva / Akamai challenge wall — the same wall AI crawlers hit — instead of reporting every signal as missing.
  • robots.txt platform fingerprint fallback catches managed platforms even when no CDN URL is visible in the HTML, so root-file advice gates correctly.
  • New sitemap-debris checks: indexed placeholder slugs (hello-world, sample-page, templated blog titles), republished-draft random-suffix URLs, and duplicate home-page aliases (/home, /home-2) competing with /.
  • New photographer-vertical image-rights check: recommends ImageObject/Photograph schema when none is present.

v2026.05.17 —

Cross-page reference "missing name" detector

  • New detector for JSON-LD cross-page @id references that carry @type but no name — the next Search Console error after the "Invalid object type" fix.
  • Covers mainEntity, about, author, publisher, isPartOf, and mainEntityOfPage reference fields; same-page refs stay bare and pass.
  • Fix copy instructs adding name alongside @id + @type on each cross-page reference.

v2026.05.16 —

Search Console "invalid object type" and "invalid datetime" detectors

  • New detector for bare {"@id":"..."} reference objects with no inline @type and no on-page definition — the trigger for Search Console's "Invalid object type" rich-result error that public validators pass silently.
  • New detector for date-only dateCreated/dateModified/datePublished values (YYYY-MM-DD), the "Invalid datetime value" trigger; fix copy shows full ISO 8601 with timezone offset.
  • Both become top-priority entity-binding penalties with explicit GSC TYPE / GSC DATE labels.

v2026.05.13 —

Knowledge-Graph entity-anchor reconciliation

  • New entity-anchors section: scores binding to Google's Knowledge Graph via sameAs kgmid, Google Maps cid, Google Business Profile, LinkedIn, and Wikidata — distinct from just adding more schema.
  • Checks Person/Org dual-typing on vertical nodes, shared-@id consolidation, worksFor/parentOrganization employer relations, and flags circular self-referential sameAs.
  • New mainEntityOfPage object-form check enforces a closed bidirectional Person ↔ ProfilePage loop, plus a guard for HTML-encoded &amp; in sameAs URLs (a templating autoescape bug).

v2026.05.12 —

Vertical classification overhaul + self-host and mobile checks

  • Vertical classifier rebuilt around ~120 schema.org LocalBusiness subtypes plus dozens of keyword verticals (restaurant, trades, fitness, beauty, auto, nonprofit, industrial, religious, education, senior-care, and more) so businesses without explicit schema still classify correctly.
  • YMYL gating tightened: Legal/Finance/Health now require the regulated schema or ≥5 keyword hits, so editorial blog mentions no longer mislabel a site as YMYL.
  • Trust, voice-density, and editorial-only checks (dateModified, RSS, llms-full, etc.) downgrade to informational on local-service and publisher contexts that shouldn't be held to them.
  • New self-host opportunity check (third-party CDN fonts/scripts that could move on-site) and a mobile auto-scaling check (zoom-blocking viewport, fixed widths, unwrapped wide tables) with drop-in CSS.
  • Sitemap discovery now falls back through Yoast / WP-core / index variants and parses Sitemap: directives from robots.txt; apex↔www are treated as the same site.

v2026.05 —

  • Added SoftwareApplication, HowTo, and FAQPage JSON-LD to the tool page itself. Author byline and visible last-updated stamp moved into the page hero. (Eat-your-own-dog-food for the E-E-A-T bucket.)
  • Published this /methodology/ page and changelog. Linked from the tool hero.
  • Bucket count documented as 10 in /.well-known/agent-skills/index.json, /.well-known/agent-card, and /llms-full.txt (previously documented as 6).

v2026.05.10 —

Nine SHIP-NOW signal additions from the Cloudflare Agents v2 research pass:

  • AGENTS.md probe at /AGENTS.md (per agents.md).
  • /.well-known/mcp.json (Cloudflare path), probed in parallel with the SEP-2127 /.well-known/mcp/server-card.json. Dual-publish gap is flagged when only one of the two is present.
  • x402 v2 advertisement via Link: rel="payment-required" response header or Accept-Payment: x402. Gated to commerce / dev surfaces.
  • OAuth Resource Server Link: rel="oauth-protected-resource" header on 401 responses. Gated on presence of an OAuth Protected Resource metadata file.
  • Vary: Accept on the markdown response — confirms server actually negotiates text/markdown.
  • Per-page .md companion + /index.md root marker. Warn on /blog, /posts, /articles, /docs, /news.
  • /llms-ctx.txt + /llms-ctx-full.txt (FastHTML llmstxt.org extension).
  • JSON Feed v1.1 enrichment fields in /feed.json: language, authors[], feed_url.
  • schema:CreativeWork.usageInfo URL — Schema.org canonical AI-rights pointer.

v2026.04.17 — Cloudflare Agent Readiness baseline

Initial 13-probe Cloudflare Agent Readiness coverage:

  • Content-Signal directive in robots.txt.
  • Link response headers (RFC 8288).
  • API Catalog at /.well-known/api-catalog (RFC 9727).
  • MCP Server Card at /.well-known/mcp/server-card.json (SEP-2127). Gated on _isAgentTarget.
  • Agent Skills at /.well-known/agent-skills/index.json (v0.2.0).
  • Web Bot Auth signature directory (informational; never penalized).
  • OAuth metadata + OAuth Protected Resource. Gated on _isAgentTarget.
  • WebMCP imperative API. Gated on _hasAgentCta.
  • ACP discovery + MPP openapi.json. Gated on _isCommerceSurface.

v2026.04 — Foundation

  • SEO, Schema, E-E-A-T, Voice, Mobile parity, Performance, A11y, Indexing hygiene, Retrieval (AEO) buckets shipped.
  • Mega AI fix prompt output bucket.
  • Mark It N/A feature: excludes a check from both the score and the AI prompt.
  • Export / Import scan JSON: save the full scan, re-run the prompt without re-fetching, diff against past scans.
  • JSON-LD walker fix: recurses into all object values (not only @graph) so Review and AggregateRating nested inside Product.review / OfferCatalog are detected.
  • Physical-goods gate: shippingDetails / hasMerchantReturnPolicy only flagged on Products with gtin/mpn/isbn/productID/itemCondition, or when the root schema is not Service / LocalBusiness / SelfStorage / OfferCatalog family.

Accessibility Options

Text Size
High Contrast
Reduce Motion
Reading Guide
Link Highlighting
Accessibility Statement

J.A. Watte is committed to ensuring digital accessibility for people with disabilities. This site conforms to WCAG 2.1 and 2.2 Level AA guidelines.

Measures Taken

  • Semantic HTML with proper heading hierarchy
  • ARIA labels and roles for interactive components
  • Color contrast ratios meeting WCAG AA (4.5:1)
  • Full keyboard navigation support
  • Skip navigation link
  • Visible focus indicators (3:1 contrast)
  • 44px minimum touch/click targets
  • Dark/light theme with system preference detection
  • Responsive design for all devices
  • Reduced motion support (CSS + toggle)
  • Text size customization (14px–20px)
  • Print stylesheet

Feedback

Contact: jwatte.com/contact

Full Accessibility Statement • Privacy Policy

Last updated: April 2026