MCP connector for Claude

Site Check: measured, not guessed.

Site Check reads any public website the way a browser, a search engine and an AI assistant would, and reports what it found: how fast the server answers, whether the certificate and domain are about to lapse, whether anyone can send email as the business, whether Google and AI engines are allowed to read it, and whether a visitor can call or write. No model judges anything. Every line says what we measured, and every problem comes with a fix.

Connector URL

https://mcp.modernmustardseed.com/site-check

Streamable HTTP. No sign-in. Every tool is read-only.

Connect it

  1. In Claude, open Settings, then Connectors.
  2. Choose Add custom connector, paste https://mcp.modernmustardseed.com/site-check, and save. No account or key is needed.
  3. In a chat, ask about any public website. Claude calls the tools when the question needs them.

In Claude Code: claude mcp add --transport http site-check https://mcp.modernmustardseed.com/site-check

Try these

The tools

scan_website

Scan a website

Runs about 40 measured checks on a public homepage across seven sections: speed, security and trust, domain, email, search basics, AI search, and contact paths. Returns a 0 to 100 website score, the top fixes with an effort level, the checks that warn or fail (or every check with detail "full"), and the page as it appears in a search result.

Inputs: url (required); sections (optional subset); detail: "summary" or "full".

check_ai_search_readiness

Check AI search readiness

Reports which AI crawlers the site robots.txt allows or blocks, whether llms.txt is published, the structured data types the homepage declares, its title and description as an answer engine reads them, and the search and AI checks with fixes.

Inputs: url (required).

score_local_presence

Score local presence

Blends three pillars into one 0 to 100 score: website 45 percent (from a live scan), Google reviews 30 percent, Google Business Profile 25 percent. Review and profile facts come from you or from a public listing Claude reads; the tool does not look them up. A pillar with no facts is left out rather than scored as zero.

Inputs: business_name (required); website, rating, review_count, phone, address, city, state, hours, open_24_7, emergency_service, trade, listing_seen, details_read, source_urls (all optional).

explain_check

Explain a check

Explains any check id from a scan: what it measures, the pass and fail thresholds, why it matters, how to fix it, and the typical effort. No network access.

Inputs: check_id (required, one of the ids a scan returns).

Every check

Each check returns pass, warn, fail or info. Info is reported but never counted against a site. A check that could not run is left out and its section is listed under not_measured with the reason, never failed. When a homepage draws its words with JavaScript, content checks that need readable text turn to info rather than claiming something is missing.

Speed

  • ttfb

    How fast the server answers

    Time to first byte of the homepage, measured from our server in the United States. 0.8 seconds or less passes, up to 1.8 seconds warns, slower fails.

  • html-weight

    Weight of the homepage HTML

    Size of the homepage HTML document itself, before images, scripts and styles. 300 KB or less passes, up to 900 KB warns, heavier fails.

  • scripts

    Separate scripts the page loads

    Count of external script files referenced by the homepage. 20 or fewer passes, up to 40 warns, more fails.

  • image-format

    Images in a modern format

    Share of homepage images served as WebP or AVIF, or through a builder CDN that converts them. Runs when the page has 3 or more images. 60 percent or more modern (or no JPEG or PNG at all) passes, 20 percent warns, less fails.

  • lazy

    Images below the fold wait their turn

    Share of homepage images set to lazy load. Runs when the page has 6 or more images. At least a third of images lazy load passes, fewer warns.

Security and trust

  • https

    Secure connection (HTTPS)

    Whether the homepage loads over HTTPS with a certificate a browser accepts. The page loads over HTTPS.

  • http-redirect

    http:// forwards to the secure address

    Whether a request to http:// redirects to https://. The http:// address redirects to an https:// address.

  • cert

    Security certificate

    The TLS certificate on port 443: whether it validates, when it expires, and who issued it. Valid, with more than 21 days left, or issued by an authority that renews automatically.

  • headers

    Security headers

    Which of Strict-Transport-Security, X-Content-Type-Options, Content-Security-Policy, X-Frame-Options and Referrer-Policy the homepage sends. 3 or more of the 5 passes, 1 or 2 warns, none fails.

  • mixed

    Everything on the page loads securely

    Images, scripts, frames and stylesheets on the homepage still requested over plain http://. None found.

  • copyright

    The site looks looked-after

    The year in the footer copyright line, when there is one. This year or last year.

Domain

  • domain-expiry

    Domain registration paid up

    The expiration date from the registry's RDAP record. Skipped for hosted builder subdomains. More than 60 days left passes, 30 to 60 warns, under 30 fails.

  • domain-age

    How long the name has been registered

    The registration date from RDAP. Informational, never graded. Not graded.

Email

  • mx

    Email at the business domain

    MX records on the domain, and the mail provider they point to. Informational. Not graded as a failure: a domain without mail is reported as info.

  • spf

    SPF record

    The SPF TXT record on the domain, when the domain receives or sends mail. Exactly one SPF record ending in ~all or -all.

  • dmarc

    DMARC record

    The TXT record at _dmarc.(domain) and its policy. p=quarantine or p=reject passes, p=none warns, no record fails.

Search basics

  • title

    Page title

    The homepage <title> and its length. Present and 15 to 70 characters.

  • description

    Meta description

    The homepage meta description and its length. Present and 70 to 170 characters.

  • h1

    One clear main heading

    Number of H1 headings on the homepage. Exactly one.

  • viewport

    Built for phones

    Whether the homepage declares a mobile viewport. A viewport meta tag is present.

  • indexable

    Search engines are allowed to list the site

    noindex in the robots meta tag or X-Robots-Tag header, and Disallow: / for all crawlers in robots.txt. No noindex and no site-wide block.

  • canonical

    One official address for the page

    Whether the homepage sets a canonical link. A canonical link is present.

  • sitemap

    A sitemap for search engines

    /sitemap.xml, or a Sitemap: line in robots.txt. A sitemap is published.

  • alt

    Photos described in words

    Share of homepage images with alt text. Runs when the page has 3 or more images. 80 percent or more passes, 50 percent warns, less fails.

  • lang

    Page language declared

    The lang attribute on <html>. Present.

  • og

    A picture when the link is shared

    An Open Graph or Twitter share image on the homepage. A share image is set.

  • favicon

    Icon in the browser tab

    A site icon link on the homepage. An icon is set.

AI search

  • schema

    Business details in machine-readable form

    JSON-LD structured data on the homepage, and whether any of it is a LocalBusiness, Organization or more specific business type. A business type is present passes, other structured data only warns, none fails.

  • schema-depth

    How complete the business data is

    Which of telephone, address, opening hours, geo, sameAs, rating or review, and areaServed the business JSON-LD fills. 5 or more of 7 passes, 3 or 4 warns, fewer fails.

  • ai-bots

    AI assistants are allowed to read the site

    robots.txt rules for GPTBot, ChatGPT-User, OAI-SearchBot, ClaudeBot, Claude-Web, anthropic-ai, PerplexityBot, Google-Extended, CCBot and Applebot-Extended. None blocked passes, 1 to 3 blocked warns, 4 or more fails.

  • llms

    An llms.txt file

    A plain-text /llms.txt of more than 40 characters that is not an HTML error page. Published.

  • faq

    Questions answered in plain words

    FAQPage structured data, or an FAQ or common questions section on the homepage. Found.

  • words

    Enough words for a machine to quote

    Readable words on the homepage, scripts and styles removed. 300 or more passes, 120 or more warns, fewer fails.

Turning visits into calls

  • tap-to-call

    Tap to call

    A tel: link on the homepage. A tel: link is present.

  • capture

    A way to reach the business without calling

    A contact or quote form on the homepage, or an embedded form service. A form is found.

  • analytics

    Visits are measured

    Known analytics and tracking tags on the homepage (Google Analytics 4, Tag Manager, Meta Pixel, Plausible, Clarity, Vercel Analytics, builder analytics and others). At least one is installed.

  • social

    Other profiles linked

    Links from the homepage to Facebook, Instagram, LinkedIn, YouTube, TikTok, X, Pinterest, Yelp, Nextdoor, Houzz or Google. At least one is linked.

  • reviews-on-site

    Reviews shown on the site

    A review widget, review structured data, or a testimonials or reviews section on the homepage. Found.

  • after-hours

    Something answers after hours

    A chat or assistant widget on the homepage. Informational, never graded. Not graded.

How the scores work

Website score. Within each section a pass earns 1, a warn 0.5 and a fail 0; info is not graded. Sections are weighted: security, search basics and contact paths 20 percent each, speed and AI search 15 percent each, email and domain 5 percent each, scaled over the sections that were measured. A site telling search engines not to list it, or a certificate or domain about to lapse, caps the score at 59 until it is fixed. A site whose homepage could not be read is not scored.

Local presence score. Website 45 percent, reviews 30 percent, Google Business Profile 25 percent. Reviews: stars carry 60 points on a straight line from 3.0 to 5.0, and the count carries 40 on a curve that flattens near 50 reviews. Profile: eight true or false checks worth 100 points together (listing found, phone, website link, address, hours, rating showing, ten or more reviews, and emergency service for urgent trades). A pillar with no facts is marked unknown and left out, and the other weights are scaled to fill. Missing hours or a missing website link are only scored when you say the full listing was read.

Limits

What it will not scan

Site Check only reaches public web servers on ports 80 and 443. It refuses private, loopback, link-local, carrier-grade NAT, multicast and reserved addresses (IPv4 and IPv6), private network names such as localhost and .internal, and addresses with a username or password in them. Every redirect is checked again, at most five are followed, and every response is capped in size and time.

Troubleshooting

“did not return a readable page”
The site is down, the name does not exist, or a firewall refuses automated readers. Nothing is scored in that case. Open the site in a browser to confirm it loads, then try again after ten minutes.
Search and AI sections are missing
The homepage answered with an error page or a bot challenge, so only the certificate, DNS and registry were read. Those sections are listed under not_measured with the reason.
A result looks out of date
Results are cached for 24 hours. The scanned_at field shows when the site was measured.
“reached this hour's limit”
The shared hourly limit was reached. The message names the time to try again. Saved results still return during that time.

For reviewers

No account, key or setup is needed. Add the connector URL above, then:

  1. scan_website with url patagonia.com returns all seven sections. Try detail: "full" and sections: ["email"].
  2. check_ai_search_readiness with url allbirds.com returns crawler rules, llms.txt and structured data.
  3. score_local_presence with business_name Blue Bottle Coffee, website bluebottlecoffee.com, and example listing inputs rating 4.4 and review_count 850 returns all three pillars. Without rating and review_count, the reviews and profile pillars come back unknown.
  4. explain_check with check_id dmarc.
  5. Refusals: http://169.254.169.254, http://localhost and http://10.0.0.1 each return a specific error and are never fetched.

Support and security

Questions, problems and security reports go to sarah@modernmustardseed.com. A machine-readable contact is at /.well-known/security.txt. How we handle data is in the privacy policy.