www.expressjs.com

Report from 7/23/2026, 12:14:12 PM https://www.expressjs.com
Latest run · lab, cold cache
49
7/23/2026
28-day score · p75 · the standard
49
10 runs
CRR100%latest
SSD23%latest
TC170 toklatest
TTFUT121 ms28-day p75

Scored by v3 · source-of-truth hashes: score db860d6ac94e · thresholds e94f8b33e500 — verifiable against the canonical scorer.

The 28-day score is the p75 of nightly runs — the stable number to cite. Deterministic metrics (CRR/SSD/TC) show their latest value (they move only when the site changes); timing (TTFUT) and answer-fidelity (AF) are smoothed by 28-day p75 — the same lab-vs-field split Core Web Vitals uses. Synthetic daily measurement, not real-user field data.

Core Agent Vitals badge  Embed this badge

Show your agent-readiness score anywhere — it links back to this report.

[![Core Agent Vitals](https://agentvitals.dev/badge/expressjs.com.svg)](https://agentvitals.dev/results?url=https%3A%2F%2Fwww.expressjs.com)
<a href="https://agentvitals.dev/results?url=https%3A%2F%2Fwww.expressjs.com"><img src="https://agentvitals.dev/badge/expressjs.com.svg" alt="Core Agent Vitals" height="20"></a>
What AI tells your customers about youAgent confidence: LOW
🟡Business nameExpress.js · guessed from page text (no structured data)
Categorynot found
Pricenot applicable · not applicable to this page type
Locationnot applicable · not applicable to this page type
Hoursnot applicable · not applicable to this page type
Productsnot applicable · not applicable to this page type
🟡DescriptionFast, unopinionated, minimalist web framework for Node.js · guessed from page text (no structured data)

An agent is likely to fabricate missing details rather than say “I don’t know”. 0/3 applicable facts come from machine-readable structured data.

We recovered only a shell of this page (under 200 tokens) — likely a soft bot-block or a client-rendered app that served our scanner almost no content. The metrics below reflect that shell, not your real site; the score is capped until an agent can retrieve real content.
49
Overall score
weighted CAV (0–100)
FAIL
0–4950–8990–100

Metrics

100%
CRR Content Recovery Good
0.23
SSD Semantic Signal Density Poor
170 tok
TC Token Cost Good
121 ms
TTFUT Time to First Useful Token N/A

Token Cost breakdown

Where the page's tokens go (≈1,916 across regions). 85% is non-content — chrome and boilerplate an agent pays for. Add landmark roles (main/nav/header/footer) so agents can skip it.

Content
15.1% · 290
Chrome (nav / header / footer)
84.9% · 1,626
Boilerplate (cookie / ad)
0% · 0
Other
0% · 0

Final screenshot

Final screenshot of https://www.expressjs.com

Diagnostics

high SSD Low signal-to-noise for agents

content vs chrome/boilerplate

Evidencesignal 0.31 +llms.txt bonus · JSON-LD 0/1 · missing: structured-data
ImpactAgent spends tokens parsing nav/boilerplate instead of content.
Effort30–90 min

Fix: Wrap the real content in <main>/<article>, cut repeated nav/boilerplate, and keep the primary content dense and early in the DOM.

high TC 84.9% of tokens are non-content (boilerplate/chrome)

agent representation — token decomposition

EvidenceToken decomposition: content 15.1%, chrome 84.9%, boilerplate 0%, other 0%. Only 15.099999999999994% of the agent's tokens are real content.
ImpactAn agent pays for boilerplate on every request and has less context left for the real content.
Effort30–90 min

Fix: Strip repeated nav/header/footer/cookie chrome from the agent-visible output; wrap content in <main>/<article> so the extractor keeps signal and drops boilerplate.

Rendered profile: headless

Agent Discoverability 80/100 · Agent Ready

Access & discovery checks — separate from the gated CAV metrics above. Click an issue for business impact, what we measured, and how to fix. · Take the Agent Readiness course →

Agent files & endpoints

llms.txt Found at /llms.txt Learn →
robots.txt (AI bots) Major AI bots allowed Learn →
sitemap.xml No /sitemap.xml Learn →
JSON-LD structured data No JSON-LD found Learn →
~ agents.json Absent (emerging standard) Learn →
~ WebMCP endpoint Absent (emerging standard) Learn →
~ OpenAPI / API docs No OpenAPI/Swagger found Learn →

Issues (5)

Structured data (JSON-LD) medium impact No JSON-LD found

Business impact Schema.org JSON-LD tells agents what a page IS (product, article, business) with typed fields (price, rating, hours). Without it agents extract less reliably.

What we measured We parse <script type=application/ld+json>, validate it, and check for populated @type fields.

How to fix Add JSON-LD: Organization/LocalBusiness on the homepage, Product on product pages, Article on posts.

Learn how to implement →

<script type="application/ld+json">{"@context":"https://schema.org","@type":"Organization","name":"Your Co","url":"https://example.com"}</script>

Spec: https://schema.org/

XML sitemap present medium impact No /sitemap.xml

Business impact A sitemap is your table of contents for AI crawlers. Without it agents follow homepage links and miss deep pages (products, docs, pricing) — shrinking what they can recommend.

What we measured We fetch /sitemap.xml (and /sitemap_index.xml), confirm valid XML with <loc> entries, and check <lastmod> freshness.

How to fix Generate an XML sitemap of all public pages with current lastmod dates and reference it in robots.txt.

Learn how to implement →

# robots.txt
Sitemap: https://example.com/sitemap.xml

Spec: https://www.sitemaps.org/

~ agents.json discovery low impact Absent (emerging standard)

Business impact agents.json describes what your site can DO for agents (services, endpoints, capabilities) — an emerging discovery standard. Early adopters get native agent integration.

What we measured We check /agents.json and /.well-known/agents.json for a valid configuration.

How to fix Publish /agents.json describing your site's capabilities and actions.

Learn how to implement →

Spec: https://github.com/wild-card-ai/agents-json

~ WebMCP endpoint low impact Absent (emerging standard)

Business impact WebMCP lets agents call actions on your site directly (book, buy, query) instead of scraping the DOM. Early adopters get native AI-agent interoperability.

What we measured We check /.well-known/webmcp and /webmcp.json for a valid actions array.

How to fix Add a WebMCP endpoint exposing your key actions to agents.

Learn how to implement →

Spec: https://webmcp.org

~ API documentation low impact No OpenAPI/Swagger found

Business impact Programmatic agents prefer a typed API. An OpenAPI/Swagger spec lets them integrate without scraping.

What we measured We probe /openapi.json, /swagger.json, /api-docs and /.well-known/openapi.json.

How to fix Publish an OpenAPI spec at a well-known path.

Learn how to implement →

Spec: https://www.openapis.org/

Passed audits (6)

✓ robots.txt allows AI bots✓ No CAPTCHA wall✓ No content-blocking cookie wall✓ llms.txt present + valid✓ No login wall on public content✓ Server response (TTFB)

Transport & Trust (SEC 1.0.0)

HTTPS, HSTS, CSP, sniffing, referrer and CORS posture. Diagnostic only — this does not affect the CAV score. A security header does not make a page more legible to an agent, so scoring it would reward a CDN toggle that changes nothing an agent can recover. We measure it and say so.

43Transport posture (0–100, unscored)
2pass
1warn
3fail
Per-header findings (6)
HeaderEvidence
✅ HTTPSserved over HTTPS
❌ HSTSno strict-transport-security header
❌ Content-Security-Policyno content-security-policy header
❌ X-Content-Type-Optionsmissing nosniff
⚠️ Referrer-Policyno referrer-policy header (browser default applies)
✅ CORS exposureaccess-control-allow-origin: *
Full profile — how to improve · unused JS · network · timing

How to improve

highProfile reflects a block/challenge page — not your contenthighest leverage

whole profile

EvidenceMeasured against a block/challenge page (a bot-wall/CAPTCHA was served (static.cloudflareinsights.com)); every number here describes the wall, not your site.
ImpactAn AI agent hits the same wall and recovers none of your content — fix the block before optimizing anything else.
FixAllowlist legitimate agent user-agents / IP ranges in your WAF or bot-management and serve real content (not a challenge), then re-run.

Third-party impact

1 third-party requests · 11 KiB (14.2% of transfer) — code an agent must also fetch/run before your content settles. Fewer, lazier third-parties = faster, cheaper agent reads.

Third-party domainReqsTransferMain-thread
cloudflareinsights.com111 KiB

Wasted JavaScript (by bundle)

Transfer-accurate — each bundle's transfer size × its unused %, ranked by wasted bytes (the biggest code-splitting wins). Unused JS also inflates Token Cost (TC).

BundleTransferUnusedWasted
https://static.cloudflareinsights.com/beacon.min.js/v4513226cdae34746b4dedf0b4dfa099e1781791509496 3P11 KiB64.3%7 KiB
https://expressjs.com/_astro/Sidebar.astro_astro_type_script_index_0_lang.CEoQxosF.js3 KiB67.4%2 KiB
https://expressjs.com/_astro/ec.0vx5m.js1 KiB70.6%1 KiB
https://expressjs.com/_astro/preload-helper.L5lOfJxi.js1 KiB78.9%1 KiB
https://expressjs.com/_astro/hero-background.BS0E6Kpw.js3 KiB11.8%0 KiB
https://expressjs.com/_astro/LanguageSelect.astro_astro_type_script_index_0_lang.DWc0a3Ra.js0 KiB32.1%0 KiB
https://expressjs.com/_astro/utils.BX9mKOpu.js13 KiB0.7%0 KiB
https://expressjs.com/_astro/Hero.astro_astro_type_script_index_0_lang.iBKPZB5E.js1 KiB3.5%0 KiB

Network

19Requests
80 KiBTransferred
8Scripts
14.2%3rd-party
10Long tasks
Script (8)
34 KiB
Stylesheet (4)
20 KiB
Document (1)
20 KiB
Image (3)
4 KiB
Other (1)
1 KiB
Manifest (1)
1 KiB
XHR (1)
0 KiB
Heaviest requests (19)
URLTypeStatusTransfer
https://expressjs.com/Document20020 KiB
https://expressjs.com/_astro/utils.BX9mKOpu.jsScript20013 KiB
https://static.cloudflareinsights.com/beacon.min.js/v4513226cdae34746b4dedf0b4dfa099e1781791509496Script20011 KiB
https://expressjs.com/_astro/patterns.AUl6JVFk.cssStylesheet2009 KiB
https://expressjs.com/_astro/Layout.DBFzs0sV.cssStylesheet2004 KiB
https://expressjs.com/_astro/ec.t09bm.cssStylesheet2004 KiB
https://expressjs.com/_astro/Sidebar.astro_astro_type_script_index_0_lang.CEoQxosF.jsScript2003 KiB
https://expressjs.com/_astro/primitives.9-yIY7ON.cssStylesheet2003 KiB
https://expressjs.com/_astro/hero-background.BS0E6Kpw.jsScript2003 KiB
https://expressjs.com/openjs-logo-black.svgImage2002 KiB
https://expressjs.com/netlify-logo.svgImage2002 KiB
https://expressjs.com/_astro/ec.0vx5m.jsScript2001 KiB
https://expressjs.com/favicon.icoOther2001 KiB
https://expressjs.com/_astro/preload-helper.L5lOfJxi.jsScript2001 KiB
https://expressjs.com/_astro/Hero.astro_astro_type_script_index_0_lang.iBKPZB5E.jsScript2001 KiB
https://expressjs.com/site.webmanifestManifest2001 KiB
https://expressjs.com/_astro/LanguageSelect.astro_astro_type_script_index_0_lang.DWc0a3Ra.jsScript2000 KiB
https://expressjs.com/cdn-cgi/rum?XHR2040 KiB
data:image/svg+xml,%3Csvg%20xmlns%3D'http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg'%20viewBox%3D'0%200%2024%2024'%20fill%3D'none'%20stroke%3D'black'%20stroke-width%3D'1.75'%3E%3Cpath%20d%3D'M3%2019a2%202%200%200%201-1-2V2a2%202%200%200%201%201-1h13a2%202%200%200%201%202%201'%2F%3E%3Crect%20x%3D'6'%20y%3D'5'%20width%3D'16'%20height%3D'18'%20rx%3D'1.5'%20ry%3D'1.5'%2F%3E%3C%2Fsvg%3EImage2000 KiB

Long tasks (>50 ms)

StartDuration
26622 ms604 ms
931 ms597 ms
30725 ms594 ms
2541 ms586 ms
33833 ms583 ms
6082 ms580 ms
32567 ms572 ms
6663 ms571 ms
360 ms566 ms
11510 ms566 ms
Analyzing…
running mobile + desktop · ~30s