MCP connector for Claude
Site Check: measured, not guessed.
Site Check reads any public website the way a browser, a search engine and an AI assistant would, and reports what it found: how fast the server answers, whether the certificate and domain are about to lapse, whether anyone can send email as the business, whether Google and AI engines are allowed to read it, and whether a visitor can call or write. No model judges anything. Every line says what we measured, and every problem comes with a fix.
Connector URL
https://mcp.modernmustardseed.com/site-check
Streamable HTTP. No sign-in. Every tool is read-only.
Connect it
- In Claude, open Settings, then Connectors.
- Choose Add custom connector, paste
https://mcp.modernmustardseed.com/site-check, and save. No account or key is needed. - In a chat, ask about any public website. Claude calls the tools when the question needs them.
In Claude Code: claude mcp add --transport http site-check https://mcp.modernmustardseed.com/site-check
Try these
- “Run a site check on patagonia.com and tell me the three fixes that matter most.”
- “Is allbirds.com ready for AI search? Check its llms.txt and which AI crawlers it allows.”
- “Find the Google rating and review count for Blue Bottle Coffee, then score its local presence using bluebottlecoffee.com.”
The tools
scan_website
Scan a website
Runs about 40 measured checks on a public homepage across seven sections: speed, security and trust, domain, email, search basics, AI search, and contact paths. Returns a 0 to 100 website score, the top fixes with an effort level, the checks that warn or fail (or every check with detail "full"), and the page as it appears in a search result.
Inputs: url (required); sections (optional subset); detail: "summary" or "full".
check_ai_search_readiness
Check AI search readiness
Reports which AI crawlers the site robots.txt allows or blocks, whether llms.txt is published, the structured data types the homepage declares, its title and description as an answer engine reads them, and the search and AI checks with fixes.
Inputs: url (required).
score_local_presence
Score local presence
Blends three pillars into one 0 to 100 score: website 45 percent (from a live scan), Google reviews 30 percent, Google Business Profile 25 percent. Review and profile facts come from you or from a public listing Claude reads; the tool does not look them up. A pillar with no facts is left out rather than scored as zero.
Inputs: business_name (required); website, rating, review_count, phone, address, city, state, hours, open_24_7, emergency_service, trade, listing_seen, details_read, source_urls (all optional).
explain_check
Explain a check
Explains any check id from a scan: what it measures, the pass and fail thresholds, why it matters, how to fix it, and the typical effort. No network access.
Inputs: check_id (required, one of the ids a scan returns).
Every check
Each check returns pass, warn, fail or info. Info is reported but never counted against a site. A check that could not run is left out and its section is listed under not_measured with the reason, never failed. When a homepage draws its words with JavaScript, content checks that need readable text turn to info rather than claiming something is missing.
Speed
ttfbHow fast the server answers
Time to first byte of the homepage, measured from our server in the United States. 0.8 seconds or less passes, up to 1.8 seconds warns, slower fails.
html-weightWeight of the homepage HTML
Size of the homepage HTML document itself, before images, scripts and styles. 300 KB or less passes, up to 900 KB warns, heavier fails.
scriptsSeparate scripts the page loads
Count of external script files referenced by the homepage. 20 or fewer passes, up to 40 warns, more fails.
image-formatImages in a modern format
Share of homepage images served as WebP or AVIF, or through a builder CDN that converts them. Runs when the page has 3 or more images. 60 percent or more modern (or no JPEG or PNG at all) passes, 20 percent warns, less fails.
lazyImages below the fold wait their turn
Share of homepage images set to lazy load. Runs when the page has 6 or more images. At least a third of images lazy load passes, fewer warns.
Security and trust
httpsSecure connection (HTTPS)
Whether the homepage loads over HTTPS with a certificate a browser accepts. The page loads over HTTPS.
http-redirecthttp:// forwards to the secure address
Whether a request to http:// redirects to https://. The http:// address redirects to an https:// address.
certSecurity certificate
The TLS certificate on port 443: whether it validates, when it expires, and who issued it. Valid, with more than 21 days left, or issued by an authority that renews automatically.
headersSecurity headers
Which of Strict-Transport-Security, X-Content-Type-Options, Content-Security-Policy, X-Frame-Options and Referrer-Policy the homepage sends. 3 or more of the 5 passes, 1 or 2 warns, none fails.
mixedEverything on the page loads securely
Images, scripts, frames and stylesheets on the homepage still requested over plain http://. None found.
copyrightThe site looks looked-after
The year in the footer copyright line, when there is one. This year or last year.
Domain
domain-expiryDomain registration paid up
The expiration date from the registry's RDAP record. Skipped for hosted builder subdomains. More than 60 days left passes, 30 to 60 warns, under 30 fails.
domain-ageHow long the name has been registered
The registration date from RDAP. Informational, never graded. Not graded.
mxEmail at the business domain
MX records on the domain, and the mail provider they point to. Informational. Not graded as a failure: a domain without mail is reported as info.
spfSPF record
The SPF TXT record on the domain, when the domain receives or sends mail. Exactly one SPF record ending in ~all or -all.
dmarcDMARC record
The TXT record at _dmarc.(domain) and its policy. p=quarantine or p=reject passes, p=none warns, no record fails.
Search basics
titlePage title
The homepage <title> and its length. Present and 15 to 70 characters.
descriptionMeta description
The homepage meta description and its length. Present and 70 to 170 characters.
h1One clear main heading
Number of H1 headings on the homepage. Exactly one.
viewportBuilt for phones
Whether the homepage declares a mobile viewport. A viewport meta tag is present.
indexableSearch engines are allowed to list the site
noindex in the robots meta tag or X-Robots-Tag header, and Disallow: / for all crawlers in robots.txt. No noindex and no site-wide block.
canonicalOne official address for the page
Whether the homepage sets a canonical link. A canonical link is present.
sitemapA sitemap for search engines
/sitemap.xml, or a Sitemap: line in robots.txt. A sitemap is published.
altPhotos described in words
Share of homepage images with alt text. Runs when the page has 3 or more images. 80 percent or more passes, 50 percent warns, less fails.
langPage language declared
The lang attribute on <html>. Present.
ogA picture when the link is shared
An Open Graph or Twitter share image on the homepage. A share image is set.
faviconIcon in the browser tab
A site icon link on the homepage. An icon is set.
AI search
schemaBusiness details in machine-readable form
JSON-LD structured data on the homepage, and whether any of it is a LocalBusiness, Organization or more specific business type. A business type is present passes, other structured data only warns, none fails.
schema-depthHow complete the business data is
Which of telephone, address, opening hours, geo, sameAs, rating or review, and areaServed the business JSON-LD fills. 5 or more of 7 passes, 3 or 4 warns, fewer fails.
ai-botsAI assistants are allowed to read the site
robots.txt rules for GPTBot, ChatGPT-User, OAI-SearchBot, ClaudeBot, Claude-Web, anthropic-ai, PerplexityBot, Google-Extended, CCBot and Applebot-Extended. None blocked passes, 1 to 3 blocked warns, 4 or more fails.
llmsAn llms.txt file
A plain-text /llms.txt of more than 40 characters that is not an HTML error page. Published.
faqQuestions answered in plain words
FAQPage structured data, or an FAQ or common questions section on the homepage. Found.
wordsEnough words for a machine to quote
Readable words on the homepage, scripts and styles removed. 300 or more passes, 120 or more warns, fewer fails.
Turning visits into calls
tap-to-callTap to call
A tel: link on the homepage. A tel: link is present.
captureA way to reach the business without calling
A contact or quote form on the homepage, or an embedded form service. A form is found.
analyticsVisits are measured
Known analytics and tracking tags on the homepage (Google Analytics 4, Tag Manager, Meta Pixel, Plausible, Clarity, Vercel Analytics, builder analytics and others). At least one is installed.
socialOther profiles linked
Links from the homepage to Facebook, Instagram, LinkedIn, YouTube, TikTok, X, Pinterest, Yelp, Nextdoor, Houzz or Google. At least one is linked.
reviews-on-siteReviews shown on the site
A review widget, review structured data, or a testimonials or reviews section on the homepage. Found.
after-hoursSomething answers after hours
A chat or assistant widget on the homepage. Informational, never graded. Not graded.
How the scores work
Website score. Within each section a pass earns 1, a warn 0.5 and a fail 0; info is not graded. Sections are weighted: security, search basics and contact paths 20 percent each, speed and AI search 15 percent each, email and domain 5 percent each, scaled over the sections that were measured. A site telling search engines not to list it, or a certificate or domain about to lapse, caps the score at 59 until it is fixed. A site whose homepage could not be read is not scored.
Local presence score. Website 45 percent, reviews 30 percent, Google Business Profile 25 percent. Reviews: stars carry 60 points on a straight line from 3.0 to 5.0, and the count carries 40 on a curve that flattens near 50 reviews. Profile: eight true or false checks worth 100 points together (listing found, phone, website link, address, hours, rating showing, ten or more reviews, and emergency service for urgent trades). A pillar with no facts is marked unknown and left out, and the other weights are scaled to fill. Missing hours or a missing website link are only scored when you say the full listing was read.
Limits
- Results are saved for 24 hours. Asking about the same address again within a day returns the saved result instantly, marked cached, with the time it was measured.
- Fresh scans are limited across all users: 60 an hour and 600 a day, and one fresh scan per site every 10 minutes. Over a limit, the tool says so and gives the time to try again.
- A scan reads the homepage, robots.txt, sitemap.xml and llms.txt, the TLS certificate, public DNS (MX, SPF, DMARC) and the domain registry's public RDAP record. It finishes in under a minute, usually in a few seconds.
- Core Web Vitals from Google PageSpeed are not part of this version.
What it will not scan
Site Check only reaches public web servers on ports 80 and 443. It refuses private, loopback, link-local, carrier-grade NAT, multicast and reserved addresses (IPv4 and IPv6), private network names such as localhost and .internal, and addresses with a username or password in them. Every redirect is checked again, at most five are followed, and every response is capped in size and time.
Troubleshooting
- “did not return a readable page”
- The site is down, the name does not exist, or a firewall refuses automated readers. Nothing is scored in that case. Open the site in a browser to confirm it loads, then try again after ten minutes.
- Search and AI sections are missing
- The homepage answered with an error page or a bot challenge, so only the certificate, DNS and registry were read. Those sections are listed under not_measured with the reason.
- A result looks out of date
- Results are cached for 24 hours. The scanned_at field shows when the site was measured.
- “reached this hour's limit”
- The shared hourly limit was reached. The message names the time to try again. Saved results still return during that time.
For reviewers
No account, key or setup is needed. Add the connector URL above, then:
scan_websitewith urlpatagonia.comreturns all seven sections. Trydetail: "full"andsections: ["email"].check_ai_search_readinesswith urlallbirds.comreturns crawler rules, llms.txt and structured data.score_local_presencewith business_nameBlue Bottle Coffee, websitebluebottlecoffee.com, and example listing inputs rating4.4and review_count850returns all three pillars. Without rating and review_count, the reviews and profile pillars come back unknown.explain_checkwith check_iddmarc.- Refusals:
http://169.254.169.254,http://localhostandhttp://10.0.0.1each return a specific error and are never fetched.
Support and security
Questions, problems and security reports go to sarah@modernmustardseed.com. A machine-readable contact is at /.well-known/security.txt. How we handle data is in the privacy policy.