---
title: "Waymark report for ora.ai"
canonical: "https://waymark.genedai.me/score/ora.ai"
last-updated: "2026-08-26T16:27:48.590Z"
---

# Waymark report for ora.ai

Waymark scored ora.ai 90.9/100 (A) on 26 Aug 2026.
Score: 90.9/100 — Mostly ready
Scanned: 2026-08-26T16:27:48.590Z
Canonical report: https://waymark.genedai.me/score/ora.ai

## Layer breakdown

- Discovery: 20/20 (21 of 21 eligible checks passed)
- Access: 24.2/30 (32 of 43 eligible checks passed)
- Usability: 37.6/40 (30 of 33 eligible checks passed)
- Payments: N/A (excluded from the denominator)

## Findings

### 1. OpenAPI / Swagger link

- Layer: access
- Result: failed
- Evidence: No OpenAPI/Swagger link in HTML.
- Recommended fix: Link to an OpenAPI or Swagger document from the homepage.

### 2. RSS or Atom feed

- Layer: access
- Result: failed
- Evidence: No RSS/Atom link.
- Recommended fix: Expose an RSS or Atom feed for machine subscribers.

### 3. CSP or X-Frame-Options

- Layer: access
- Result: failed
- Evidence: Neither CSP nor X-Frame-Options on homepage.
- Recommended fix: Send Content-Security-Policy or X-Frame-Options.

### 4. CORS / API hint

- Layer: access
- Result: partial
- Evidence: No CORS header or obvious API path.
- Recommended fix: If you expose an API, send Access-Control-Allow-Origin for intended clients.

### 5. AI crawlers not blanket-blocked

- Layer: access
- Result: failed
- Evidence: robots.txt Disallow: / for * or common AI bots.
- Recommended fix: Avoid Disallow: / for GPTBot, ClaudeBot, PerplexityBot unless intentional.

### 6. PKCE S256

- Layer: access
- Result: failed
- Evidence: Metadata lacks S256 PKCE.
- Recommended fix: Advertise S256 in code_challenge_methods_supported.

### 7. OAuth protected resource

- Layer: access
- Result: failed
- Evidence: AS present but no resource metadata.
- Recommended fix: Publish RFC 9728 oauth-protected-resource if APIs are OAuth-gated.

### 8. security.txt

- Layer: access
- Result: failed
- Evidence: No /.well-known/security.txt Contact.
- Recommended fix: Publish /.well-known/security.txt with a Contact field.

### 9. change-password well-known

- Layer: access
- Result: failed
- Evidence: Login surface without /.well-known/change-password.
- Recommended fix: If users have passwords, serve /.well-known/change-password.

### 10. Idempotency signal

- Layer: usability
- Result: partial
- Evidence: API surface without idempotency notes.
- Recommended fix: Document idempotency keys for mutating calls.

### 11. Agent instruction / when-to-use

- Layer: access
- Result: failed
- Evidence: Agent file exists without when-to-use guidance.
- Recommended fix: Tell agents when to reach for you: add a 'when to use this' section to your llms.txt (or a dedicated agent-instructions file) that names your best-fit use cases.

### 12. llms.txt links resolve

- Layer: access
- Result: partial
- Evidence: 3 real, 0 homepage-shell, 5 dead of 8 sampled links.
- Recommended fix: Make every link your llms.txt declares resolve to real content, not a homepage shell 200.

### 13. Accessible document structure

- Layer: usability
- Result: partial
- Evidence: Landmarks partial (main=true nav=true h1=true skip=true).
- Recommended fix: Give the homepage a main region, nav, H1, and a heading order that does not skip levels.

### 14. Multi-language SDK packages

- Layer: usability
- Result: partial
- Evidence: npm matches; second ecosystem homepage does not.
- Recommended fix: Publish official SDK packages on npm and PyPI whose homepage is this domain.

## Interpretation

Public technical snapshot; not a guarantee of task completion. Private and authenticated workflows are outside this scan. Cite scanned_at and the canonical report URL; the URL serves the latest completed snapshot and can change after a rescan.

The official Waymark score is Discovery 20 / Access 30 / Usability 40 / Payments 10. N/A and scanner-error checks drop out of the denominator; they are not scored as failures. An observed agent journey is supporting evidence and does not change the numeric score.
