---
title: "Waymark report for substack.com"
canonical: "https://waymark.genedai.me/score/substack.com"
last-updated: "2026-09-13T12:18:04.642Z"
---

# Waymark report for substack.com

Waymark scored substack.com 45.5/100 (D) on 13 Sep 2026.
Score: 45.5/100 — Major gaps
Scanned: 2026-09-13T12:18:04.642Z
Canonical report: https://waymark.genedai.me/score/substack.com

## Layer breakdown

- Discovery: 8.8/20 (6 of 17 eligible checks passed)
- Access: 13.4/30 (15 of 29 eligible checks passed)
- Usability: 18.8/40 (4 of 9 eligible checks passed)
- Payments: N/A (excluded from the denominator)

## Findings

### 1. llms.txt

- Layer: discovery
- Result: failed
- Evidence: llms.txt status 404.
- Recommended fix: Add /llms.txt describing the site for language models.

### 2. AGENTS.md

- Layer: discovery
- Result: failed
- Evidence: agents.md status 404.
- Recommended fix: Publish /agents.md with agent-oriented usage notes.

### 3. Well-known AI catalog

- Layer: discovery
- Result: failed
- Evidence: No ai-plugin.json or ai-catalog.json.
- Recommended fix: Add /.well-known/ai-plugin.json or /.well-known/ai-catalog.json.

### 4. JSON-LD structured data

- Layer: access
- Result: failed
- Evidence: No JSON-LD on the homepage.
- Recommended fix: Add JSON-LD (Organization, WebSite, or SoftwareApplication).

### 5. RSS or Atom feed

- Layer: access
- Result: failed
- Evidence: No RSS/Atom link.
- Recommended fix: Expose an RSS or Atom feed for machine subscribers.

### 6. CORS / API hint

- Layer: access
- Result: partial
- Evidence: No CORS header or obvious API path.
- Recommended fix: If you expose an API, send Access-Control-Allow-Origin for intended clients.

### 7. Login or docs link

- Layer: access
- Result: failed
- Evidence: No login/docs/developers link.
- Recommended fix: Link to login and developer documentation from the homepage.

### 8. MCP well-known card

- Layer: usability
- Result: failed
- Evidence: MCP mentioned without a well-known card.
- Recommended fix: Publish /.well-known/mcp.json describing your MCP server.

### 9. Webhook or API docs

- Layer: usability
- Result: failed
- Evidence: No webhook/API docs mention.
- Recommended fix: Document webhooks and REST/RPC APIs for agents.

### 10. robots.txt AI policy

- Layer: discovery
- Result: partial
- Evidence: robots.txt present but no named AI crawlers.
- Recommended fix: Name GPTBot, ClaudeBot, Google-Extended, PerplexityBot and state allow or deny.

### 11. llms.txt index

- Layer: discovery
- Result: failed
- Evidence: Missing /llms.txt.
- Recommended fix: Add a markdown index at /llms.txt.

### 12. llms-full.txt

- Layer: discovery
- Result: failed
- Evidence: llms-full.txt status 404.
- Recommended fix: Optionally publish /llms-full.txt for one-shot ingest.

### 13. HTTP Link header

- Layer: discovery
- Result: failed
- Evidence: No rel=sitemap|describedby|api-catalog|alternate on homepage.
- Recommended fix: Send RFC 8288 Link headers for related machine resources.

### 14. JSON-LD entities

- Layer: access
- Result: failed
- Evidence: No JSON-LD.
- Recommended fix: Embed Organization, Product, Offer, SoftwareApplication, or FAQPage.

### 15. MCP server card

- Layer: usability
- Result: partial
- Evidence: MCP mentioned without a card.
- Recommended fix: Publish /.well-known/mcp.json or mcp/server-card.json.

### 16. ai-plugin.json

- Layer: discovery
- Result: failed
- Evidence: No /.well-known/ai-plugin.json.
- Recommended fix: Optionally publish a plugin-style capability manifest.

### 17. OAuth protected resource

- Layer: access
- Result: failed
- Evidence: AS present but no resource metadata.
- Recommended fix: Publish RFC 9728 oauth-protected-resource if APIs are OAuth-gated.

### 18. security.txt

- Layer: access
- Result: failed
- Evidence: No /.well-known/security.txt Contact.
- Recommended fix: Publish /.well-known/security.txt with a Contact field.

### 19. change-password well-known

- Layer: access
- Result: failed
- Evidence: Login surface without /.well-known/change-password.
- Recommended fix: If users have passwords, serve /.well-known/change-password.

### 20. llms.txt size and links

- Layer: discovery
- Result: failed
- Evidence: No llms.txt to score.
- Recommended fix: Keep /llms.txt over ~200 characters with absolute URLs to docs.

### 21. Public API surface

- Layer: access
- Result: failed
- Evidence: No public API or docs surface.
- Recommended fix: Document a public API at /docs or /developers.

### 22. Pricing page

- Layer: access
- Result: failed
- Evidence: No pricing page.
- Recommended fix: Publish /pricing.

### 23. Scoped permissions

- Layer: access
- Result: failed
- Evidence: No named OAuth scopes.
- Recommended fix: Declare OAuth scopes in a spec.

### 24. MCP server

- Layer: usability
- Result: partial
- Evidence: MCP mentioned without a documented initialize.
- Recommended fix: Publish an MCP card or document the MCP URL in llms.txt, then answer initialize.

### 25. Trust pages

- Layer: access
- Result: failed
- Evidence: No about/privacy/contact link.
- Recommended fix: Link about or privacy from the homepage.

### 26. Sitemap lastmod

- Layer: discovery
- Result: failed
- Evidence: Sitemap without lastmod.
- Recommended fix: Add lastmod dates to sitemap entries.

### 27. Package homepage match

- Layer: discovery
- Result: failed
- Evidence: No npm package homepage matching substack.com.
- Recommended fix: Publish an official package whose homepage is this domain.

### 28. Content without JavaScript

- Layer: access
- Result: partial
- Evidence: Raw HTML has 2107 characters but no H1.
- Recommended fix: Server-side render your homepage so AI crawlers see meaningful content without JavaScript. Ensure an H1 and 500+ chars of text in raw HTML.

### 29. Accessible document structure

- Layer: usability
- Result: partial
- Evidence: Incomplete document structure (main=true nav=true h1=false).
- Recommended fix: Give the homepage a main region, nav, H1, and a heading order that does not skip levels.

### 30. Agent-UA markdown docs

- Layer: access
- Result: failed
- Evidence: Docs host did not serve markdown to GPTBot (HTTP 200, text/html; charset=utf-8).
- Recommended fix: Serve text/markdown to GPTBot (and similar agent UAs) on your docs host.

## Interpretation

Public technical snapshot; not a guarantee of task completion. Private and authenticated workflows are outside this scan. Cite scanned_at and the canonical report URL; the URL serves the latest completed snapshot and can change after a rescan.

The official Waymark score is Discovery 20 / Access 30 / Usability 40 / Payments 10. N/A and scanner-error checks drop out of the denominator; they are not scored as failures. An observed agent journey is supporting evidence and does not change the numeric score.
