r-lopes.com
Scored by v3 · source-of-truth hashes: score db860d6ac94e · thresholds e94f8b33e500 — verifiable against the canonical scorer.
The 28-day score is the p75 of nightly runs — the stable number to cite. Deterministic metrics (CRR/SSD/TC) show their latest value (they move only when the site changes); timing (TTFUT) and answer-fidelity (AF) are smoothed by 28-day p75 — the same lab-vs-field split Core Web Vitals uses. Synthetic daily measurement, not real-user field data.
An agent can answer questions about you accurately. 4/4 applicable facts come from machine-readable structured data.
Metrics
Token Cost breakdown
Where the page's tokens go (≈832 across regions). Most tokens are real content — the agent isn't paying much for chrome.
Final screenshot
Diagnostics
No issues found — this page is well-prepared for agents.
Rendered profile: headless
Metrics
Token Cost breakdown
Where the page's tokens go (≈832 across regions). Most tokens are real content — the agent isn't paying much for chrome.
Final screenshot
Diagnostics
No issues found — this page is well-prepared for agents.
Rendered profile: headless
Access & discovery checks — separate from the gated CAV metrics above. Click an issue for business impact, what we measured, and how to fix. · Take the Agent Readiness course →
Agent files & endpoints
No discovery issues found.
Passed audits (11)
Declaration Truthfulness (DVS 1.0.0)
This site publishes an agent capability declaration. DVS verifies whether each declared API operation actually exists in the served /openapi.json — measurement, not trust. Separate from the CAV score.
Transport & Trust (SEC 1.0.0)
HTTPS, HSTS, CSP, sniffing, referrer and CORS posture. Diagnostic only — this does not affect the CAV score. A security header does not make a page more legible to an agent, so scoring it would reward a CDN toggle that changes nothing an agent can recover. We measure it and say so.
Per-header findings (6)
| Header | Evidence |
|---|---|
| ✅ HTTPS | served over HTTPS |
| ❌ HSTS | no strict-transport-security header |
| ❌ Content-Security-Policy | no content-security-policy header |
| ❌ X-Content-Type-Options | missing nosniff |
| ⚠️ Referrer-Policy | no referrer-policy header (browser default applies) |
| ➖ CORS exposure | no CORS headers on the document (normal for an HTML page) |
How to improve
whole profile
Third-party impact
1 third-party requests · 11 KiB (34.2% of transfer) — code an agent must also fetch/run before your content settles. Fewer, lazier third-parties = faster, cheaper agent reads.
| Third-party domain | Reqs | Transfer | Main-thread |
|---|---|---|---|
| cloudflareinsights.com | 1 | 11 KiB | — |
Wasted JavaScript (by bundle)
Transfer-accurate — each bundle's transfer size × its unused %, ranked by wasted bytes (the biggest code-splitting wins). Unused JS also inflates Token Cost (TC).
| Bundle | Transfer | Unused | Wasted |
|---|---|---|---|
| https://static.cloudflareinsights.com/beacon.min.js/v4513226cdae34746b4dedf0b4dfa099e1781791509496 3P | 11 KiB | 64.9% | 7 KiB |
Network
Heaviest requests (7)
| URL | Type | Status | Transfer |
|---|---|---|---|
| https://static.cloudflareinsights.com/beacon.min.js/v4513226cdae34746b4dedf0b4dfa099e1781791509496 | Script | 200 | 11 KiB |
| https://r-lopes.com/cdn-cgi/challenge-platform/h/g/scripts/jsd/b0da9f4911ba/main.js? | Script | 200 | 10 KiB |
| https://r-lopes.com/ | Document | 200 | 5 KiB |
| https://blog.r-lopes.com/rafael-lopes-150.webp | Image | 200 | 4 KiB |
| https://r-lopes.com/cdn-cgi/challenge-platform/h/g/jsd/oneshot/b0da9f4911ba/0.4242504976592081:1784952028:qQ48c9rFRzwb5m8_r4B0pJ_a4cWBIBA0I9kAAXsYrkc/a20880f8bb9a50d0 | XHR | 200 | 1 KiB |
| https://r-lopes.com/favicon.ico | Other | 404 | 1 KiB |
| https://r-lopes.com/cdn-cgi/rum? | XHR | 204 | 0 KiB |