The Census · 2026-Q4 · drupal-100

AI crawlers cannot reach this site. AIR-1.2 failed, so an assistant asking about this organization gets nothing from here whatever the page contains. The score beside it says how well the site is built; this says none of it is currently reachable. Both are true, and neither replaces the other — which is why the score is no longer capped to say it.

https://www.tenable.com/ · ranked 42 in its cohort · 32 pages read · 51 tests · 19 September 2026

Scan

tenable.com

Score

49/100

16 of 51 tests pass · 51 points still on the table

You · 49
NOT READY 0–39 WEAK 40–59 ADEQUATE 60–74 STRONG 75–89 EXEMPLARY 90–99

We ran all 51 scored tests across 7 dimensions, against the 32 pages we read.

Weak

AI crawlers are turned away before they reach the content, so nothing else on this page has had a chance to matter.

Do these three first

The fastest 10 points on this scan

1 +5

AIR-1.2 · medium effort

CDN and WAF do not silently reject AI crawlers

8 of 8 AI user-agents are rejected or challenged at the edge.

Do this: Stop rejecting AI crawlers at the CDN or WAF.

2 +3

AIR-1.4 · small effort

Content Signals declared in robots.txt

No Content-Signal line in robots.txt. Missing: search, ai-input, ai-train.

Do this: Declare a Content Signals position in robots.txt.

3 +2

AIR-3.2 · small effort

BreadcrumbList on every page below the homepage

0% of pages below the homepage carry a BreadcrumbList with at least two steps.

Do this: Generate BreadcrumbList from the menu.

Nine dimensions, most to least left on the table

32 pages crawled

Every test · all 67 tests, in order

67 of 67 showing

Show
AIR-1.1 Can AI crawlers reach your site? PASS 5 pt
Why we test this

All 10 AI agents may fetch content paths.

Your robots.txt file tells crawlers what they may read. A line left behind by a previous site or a copied template can quietly shut out the assistants people now use to find you.

AIR-1.2 Does your CDN let AI crawlers through?8 of 8 AI user-agents are rejected or challenged at the edge. PROBLEM +5
What's wrong

8 of 8 AI user-agents are rejected or challenged at the edge.

Even when robots.txt says yes, a firewall or bot-protection rule can turn assistants away before they reach your pages. We sent a request as each one and recorded what came back.

AIR-1.3 Is your page readable without a security challenge?12 of 32 sampled pages return an interactive challenge (Cloudflare Turnstile, Google reCAPTCHA, edge challenge cookie). NEEDS WORK +0
What's half-done

12 of 32 sampled pages return an interactive challenge (Cloudflare Turnstile, Google reCAPTCHA, edge challenge cookie).

A CAPTCHA or bot check on an ordinary page stops an assistant at the door. These belong on forms and logins, not on pages anyone can read.

AIR-1.4 Have you stated what AI may do with your content?No Content-Signal line in robots.txt. Missing: search, ai-input, ai-train. PROBLEM +3
What's wrong

No Content-Signal line in robots.txt. Missing: search, ai-input, ai-train.

There is now a machine-readable way to say whether AI may search, quote or train on your material. Having a position — any position — is the point.

AIR-1.5 Can a person read your AI policy?robots.txt carries a 241-character comment, too thin to read as a policy statement. NEEDS WORK +0
What's half-done

robots.txt carries a 241-character comment, too thin to read as a policy statement.

A few plain sentences in robots.txt saying what you permit. Journalists and lawyers read this file, and right now most sites say nothing.

AIR-1.6 Are you allowing assistants to quote you? PASS 1 pt
Why we test this

No noarchive, nosnippet or max-snippet:0 directives found.

Some sites carry old settings that tell search engines not to show excerpts. Those same settings stop an assistant quoting your page in an answer.

AIR-1.7 Does this page declare its real address? PASS 2 pt
Why we test this

94% of sampled pages emit a valid, self-consistent canonical. 2 have problems.

A canonical link tells a machine which URL is the true one. Without it the same content can be treated as several competing pages.

AIR-1.8 Is your page structured so a machine can follow it? PASS 2 pt
Why we test this

79% of sampled pages carry one main element, a wrapping article or section, and a nav. 4 exceed 12 divs per semantic element.

Meaningful sections rather than an undifferentiated wall of containers. It is the difference between a document and a soup of boxes.

AIR-1.9 Do your headings tell a clear story? PASS 2 pt
Why we test this

94% of sampled pages have exactly one non-empty h1 and no skipped heading levels. 2 have no h1

One main heading, then sub-headings in order. Assistants use headings to work out what a page is about and which part answers a question.

AIR-1.10 Do you publish a guide for AI assistants?/llms.txt lists 54 links across 8 sections, covering 1% of the sitemap. NEEDS WORK +1
What's half-done

/llms.txt lists 54 links across 8 sections, covering 1% of the sitemap.

A file at /llms.txt listing your most important pages. It is early and cheap, and it forces a useful conversation about what actually matters on your site.

AIR-1.11 Can a machine tell what your organization is?3 of 71 entity nodes carry an @id (4%). The WebPage to WebSite to Organization chain is broken at WebPage->WebSite, WebSite->Organization. 2 duplicate definitions of Organization. PROBLEM +1
What's wrong

3 of 71 entity nodes carry an @id (4%). The WebPage to WebSite to Organization chain is broken at WebPage->WebSite, WebSite->Organization. 2 duplicate definitions of Organization.

Structured data that links together — your organization, your site, this page — rather than a scattering of disconnected labels.

AIR-1.12 Can a machine be certain it is you?4 sameAs links: 0 tier-1 authority identifiers, 2 tier-2, 2 social. NEEDS WORK +1
What's half-done

4 sameAs links: 0 tier-1 authority identifiers, 2 tier-2, 2 social.

Links from your markup to authoritative records like Wikidata or ROR. Without one, an assistant is guessing which organization of your name it has found.

AIR-1.13 Can a machine find out who you are?2 of 7 organizational facts are present in the Organization markup: contactPoint, description. PROBLEM +1
What's wrong

2 of 7 organizational facts are present in the Organization markup: contactPoint, description.

Founding date, leadership, address, contact details, legal identifiers. Thin About pages are the most common weakness we see.

AIR-2.1 Primary content is present without JavaScript PASS 5 pt
Why we test this

Raw HTML contains 91% of rendered text on average across 32 URLs. The worst template is /about-tenable/*: 72% across 1 pages.

AIR-2.2 Progressive disclosure content ships in the initial HTML NOT SCORED —
AIR-2.3 Real data tables with header cells NOT SCORED —
AIR-2.4 Stable, human-readable anchor IDs on section headings1 of 3037 subheadings carry a slug-like id (0%); 0 have generated or unstable ids. PROBLEM +1
What's wrong

1 of 3037 subheadings carry a slug-like id (0%); 0 have generated or unstable ids.

AIR-2.5 Alt text on content images, empty alt on decorative PASS 1 pt
Why we test this

371 of 449 images carry appropriate alt text: 49 have no alt attribute, 29 use the filename.

AIR-2.6 Key facts exist as HTML text, not only in images or PDFs1 of 32 sampled pages are thin relative to their images or lead with a document download. NEEDS WORK +0
What's half-done

1 of 32 sampled pages are thin relative to their images or lead with a document download.

AIR-3.1 JSON-LD is generated from mapped fields, not hardcoded1 of 2 templates repeat identical schema literals across pages whose visible content differs. NEEDS WORK +1
What's half-done

1 of 2 templates repeat identical schema literals across pages whose visible content differs.

AIR-3.2 BreadcrumbList on every page below the homepage0% of pages below the homepage carry a BreadcrumbList with at least two steps. PROBLEM +2
What's wrong

0% of pages below the homepage carry a BreadcrumbList with at least two steps.

AIR-3.3 Vertical-specific schema types NOT SCORED —
AIR-3.4 FAQPage and QAPage on genuine question-and-answer content0 pages carry FAQ or QA markup; 11 pages show visible question-and-answer content. PROBLEM +2
What's wrong

0 pages carry FAQ or QA markup; 11 pages show visible question-and-answer content.

AIR-3.5 isAccessibleForFree, about, and mentions with entity references0 of 30 substantive pages declare isAccessibleForFree; 1 reference subject entities by identifier. NEEDS WORK +0
What's half-done

0 of 30 substantive pages declare isAccessibleForFree; 1 reference subject entities by identifier.

AIR-3.6 Product, Offer, and Service with real prices PASS 1 pt
Why we test this

4 Offer nodes: 4 complete and matching the page, 0 drifting from visible values, 0 past priceValidUntil.

AIR-3.7 SearchAction on the WebSite node NOT SCORED —
AIR-3.8 Schema validation of the structured data on the page PASS 2 pt
Why we test this

Everything parses and every node carries what its type needs; 3 of 31 pages hold a value in the wrong shape.

AIR-4.1 RSL licensing document published and referenced NOT SCORED —
AIR-4.2 RSL terms propagated to feeds and schema NOT SCORED —
AIR-4.3 Web Bot Auth verification configured NOT SCORED —
AIR-4.4 Correct X-Robots-Tag on non-HTML resources0 of 25 non-HTML resources carry an X-Robots-Tag. PROBLEM +1
What's wrong

0 of 25 non-HTML resources carry an X-Robots-Tag.

AIR-4.5 Missing pages return 404 or 4100 of 8 deliberately invalid URLs returned HTTP 200; 1 sampled pages are thin enough to be not-found templates. NEEDS WORK +0
What's half-done

0 of 8 deliberately invalid URLs returned HTTP 200; 1 sampled pages are thin enough to be not-found templates.

AIR-4.6 Redirects resolve in a single hop PASS 1 pt
Why we test this

0 of 32 sampled URLs redirect.

AIR-4.7 Faceted, calendar, and parameterized URLs are controlled PASS 2 pt
Why we test this

10 of 10 parameterized URLs are held in check by noindex or a canonical back to the unfiltered listing.

AIR-4.8 Sitemap lastmod reflects real content changes PASS 2 pt
Why we test this

6562 of 6562 sitemap URLs carry a lastmod across 1732 distinct dates; 8% share 2013-05-13.

AIR-4.9 Sitemap index split by type, with media sitemaps PASS 1 pt
Why we test this

An index with 2 child sitemaps covering 6562 URLs, with no image or video sitemap.

AIR-4.10 Paginated series are coherently signaled NOT SCORED —
AIR-5.1 Author entity pages with credentialsNo Person entities appear anywhere in the sample. PROBLEM +2
What's wrong

No Person entities appear anywhere in the sample.

AIR-5.2 Bylines linked to author entities0 of 30 substantive pages reference an author by @id; 0 carry a bare string; 30 are unsigned. PROBLEM +2
What's wrong

0 of 30 substantive pages reference an author by @id; 0 carry a bare string; 30 are unsigned.

AIR-5.3 reviewedBy on YMYL content NOT SCORED —
AIR-5.4 datePublished and dateModified are accurate0 of 32 pages carry a publication or modification date across 0 distinct dateModified values. PROBLEM +2
What's wrong

0 of 32 pages carry a publication or modification date across 0 distinct dateModified values.

AIR-5.5 citation markup on primary-source references NOT SCORED —
AIR-5.6 C2PA Content Credentials on original assets NOT SCORED —
AIR-6.1 OpenAPI specification for public APIs NOT SCORED —
AIR-6.2 /.well-known/ discovery entries for agent capabilities NOT SCORED —
AIR-6.3 Form fields carry label, name, and autocomplete PASS 2 pt
Why we test this

423 of 424 form fields carry an accessible name, a meaningful name attribute and a valid autocomplete token where one applies.

AIR-6.4 No captchas on browse, search, or filter interactions PASS 2 pt
Why we test this

No search or filter surface in the sample returned a challenge.

AIR-7.1 Markdown companion for every canonical page0 of 16 sampled pages have a Markdown companion at {path}.md returning a Markdown content type. PROBLEM +2
What's wrong

0 of 16 sampled pages have a Markdown companion at {path}.md returning a Markdown content type.

AIR-7.2 link rel=alternate advertises the Markdown version NOT SCORED —
AIR-7.3 Accept: text/markdown content negotiation0 of 25 URLs serve Markdown for Accept: text/markdown. PROBLEM +2
What's wrong

0 of 25 URLs serve Markdown for Accept: text/markdown.

AIR-7.4 Alternate representations are edge-cached PASS 2 pt
Why we test this

1 of 1 generated representations show evidence of an edge cache hit on a repeat request.

LI-1 HowTo on procedural content0 of 5 procedural pages carry HowTo with ordered HowToStep. NOT SCORED —
What's wrong

0 of 5 procedural pages carry HowTo with ordered HowToStep.

LI-2 speakable on summaries and ledesNo speakable specification found on any sampled page. NOT SCORED —
What's wrong

No speakable specification found on any sampled page.

LI-3 IndexNow fires on publish and updateNo IndexNow key file was discoverable. The file is named after the key, which is not published, so this is 'not discoverable' rather than proof of absence. NOT SCORED —
What's wrong

No IndexNow key file was discoverable. The file is named after the key, which is not published, so this is 'not discoverable' rather than proof of absence.

LI-4 Editorial policy page referenced via publishingPrinciples0 of 12 Organization nodes reference publishingPrinciples. NOT SCORED —
What's wrong

0 of 12 Organization nodes reference publishingPrinciples.

LI-5 NLWeb endpoint exposed as an MCP server with an ask methodNo NLWeb endpoint was discoverable. NOT SCORED —
What's wrong

No NLWeb endpoint was discoverable.

LI-6 Domain MCP server over real content APIsNo domain MCP server or tool descriptor was discoverable. NOT SCORED —
What's wrong

No domain MCP server or tool descriptor was discoverable.

LI-7 /llms-full.txt where full-text inclusion is appropriate NOT SCORED —
BP-1 Critical flows complete without JS-only interactions NOT SCORED —
BP-2 Stable selectors on critical-flow elements NOT SCORED —
BP-3 GA4 channel group for AI assistant referrersWhether a channel group exists for AI assistant referrers is not visible from outside. Analytics presence is; the grouping is not. NOT SCORED —
What we're measuring

Whether a channel group exists for AI assistant referrers is not visible from outside. Analytics presence is; the grouping is not.

BP-4 Server-side tagging captures stripped referrersReconciliation between server-side and client-side numbers has to be attested. NOT SCORED —
What we're measuring

Reconciliation between server-side and client-side numbers has to be attested.

BP-5 Access log retention with a queryable storeLog retention and queryability are not observable from outside the site. NOT SCORED —
What we're measuring

Log retention and queryability are not observable from outside the site.

BP-6 Scheduled AI crawler activity report NOT SCORED —
BP-7 Fixed prompt panel run monthly across modelsAnswer-share tracking happens outside the site and must be attested. NOT SCORED —
What we're measuring

Answer-share tracking happens outside the site and must be attested.

BP-8 Extraction-fidelity baseline capturedNo extraction-fidelity baseline is captured by this version of the scanner, which makes no live model calls. NOT SCORED —
What we're measuring

No extraction-fidelity baseline is captured by this version of the scanner, which makes no live model calls.

BP-9 Search Console and Bing Webmaster Tools verifiedNeither Search Console nor Bing Webmaster Tools verification was found. NOT SCORED —
What's wrong

Neither Search Console nor Bing Webmaster Tools verification was found.

Not applicable — 23 tests answered with a dash, excluded from the score: AIR-2.2, AIR-2.3, AIR-3.3, AIR-3.7, AIR-4.1, AIR-4.2, AIR-4.3, AIR-4.10, AIR-5.3, AIR-5.5, AIR-5.6, AIR-6.1, AIR-6.2, AIR-7.2, LI-7, BP-1, BP-2, BP-3, BP-4, BP-5, BP-6, BP-7, BP-8.

By dimension

Where tenable.com's 49 came from. Open a line to see its tests, worst first.

DimensionShare earnedEarnedScore
1 · Primary Indicators 15 50
Scored zero — 4 problems
AIR-1.2 Does your CDN let AI crawlers through?8 of 8 AI user-agents are rejected or challenged at the edge. PROBLEM
What's wrong

8 of 8 AI user-agents are rejected or challenged at the edge.

Even when robots.txt says yes, a firewall or bot-protection rule can turn assistants away before they reach your pages. We sent a request as each one and recorded what came back.

AIR-1.4 Have you stated what AI may do with your content?No Content-Signal line in robots.txt. Missing: search, ai-input, ai-train. PROBLEM
What's wrong

No Content-Signal line in robots.txt. Missing: search, ai-input, ai-train.

There is now a machine-readable way to say whether AI may search, quote or train on your material. Having a position — any position — is the point.

AIR-1.11 Can a machine tell what your organization is?3 of 71 entity nodes carry an @id (4%). The WebPage to WebSite to Organization chain is broken at WebPage->WebSite, WebSite->Organization. 2 duplicate definitions of Organization. PROBLEM
What's wrong

3 of 71 entity nodes carry an @id (4%). The WebPage to WebSite to Organization chain is broken at WebPage->WebSite, WebSite->Organization. 2 duplicate definitions of Organization.

Structured data that links together — your organization, your site, this page — rather than a scattering of disconnected labels.

AIR-1.13 Can a machine find out who you are?2 of 7 organizational facts are present in the Organization markup: contactPoint, description. PROBLEM
What's wrong

2 of 7 organizational facts are present in the Organization markup: contactPoint, description.

Founding date, leadership, address, contact details, legal identifiers. Thin About pages are the most common weakness we see.

Partly scored — 4 need work
AIR-1.3 Is your page readable without a security challenge?12 of 32 sampled pages return an interactive challenge (Cloudflare Turnstile, Google reCAPTCHA, edge challenge cookie). NEEDS WORK
What's half-done

12 of 32 sampled pages return an interactive challenge (Cloudflare Turnstile, Google reCAPTCHA, edge challenge cookie).

A CAPTCHA or bot check on an ordinary page stops an assistant at the door. These belong on forms and logins, not on pages anyone can read.

AIR-1.5 Can a person read your AI policy?robots.txt carries a 241-character comment, too thin to read as a policy statement. NEEDS WORK
What's half-done

robots.txt carries a 241-character comment, too thin to read as a policy statement.

A few plain sentences in robots.txt saying what you permit. Journalists and lawyers read this file, and right now most sites say nothing.

AIR-1.10 Do you publish a guide for AI assistants?/llms.txt lists 54 links across 8 sections, covering 1% of the sitemap. NEEDS WORK
What's half-done

/llms.txt lists 54 links across 8 sections, covering 1% of the sitemap.

A file at /llms.txt listing your most important pages. It is early and cheap, and it forces a useful conversation about what actually matters on your site.

AIR-1.12 Can a machine be certain it is you?4 sameAs links: 0 tier-1 authority identifiers, 2 tier-2, 2 social. NEEDS WORK
What's half-done

4 sameAs links: 0 tier-1 authority identifiers, 2 tier-2, 2 social.

Links from your markup to authoritative records like Wikidata or ROR. Without one, an assistant is guessing which organization of your name it has found.

Full marks — 5 pass
AIR-1.1 Can AI crawlers reach your site? PASS
Why we test this

All 10 AI agents may fetch content paths.

Your robots.txt file tells crawlers what they may read. A line left behind by a previous site or a copied template can quietly shut out the assistants people now use to find you.

AIR-1.6 Are you allowing assistants to quote you? PASS
Why we test this

No noarchive, nosnippet or max-snippet:0 directives found.

Some sites carry old settings that tell search engines not to show excerpts. Those same settings stop an assistant quoting your page in an answer.

AIR-1.7 Does this page declare its real address? PASS
Why we test this

94% of sampled pages emit a valid, self-consistent canonical. 2 have problems.

A canonical link tells a machine which URL is the true one. Without it the same content can be treated as several competing pages.

AIR-1.8 Is your page structured so a machine can follow it? PASS
Why we test this

79% of sampled pages carry one main element, a wrapping article or section, and a nav. 4 exceed 12 divs per semantic element.

Meaningful sections rather than an undifferentiated wall of containers. It is the difference between a document and a soup of boxes.

AIR-1.9 Do your headings tell a clear story? PASS
Why we test this

94% of sampled pages have exactly one non-empty h1 and no skipped heading levels. 2 have no h1

One main heading, then sub-headings in order. Assistants use headings to work out what a page is about and which part answers a question.

2 · Rendering and Extraction 6 40
Scored zero — 1 problem
AIR-2.4 Stable, human-readable anchor IDs on section headings1 of 3037 subheadings carry a slug-like id (0%); 0 have generated or unstable ids. PROBLEM
What's wrong

1 of 3037 subheadings carry a slug-like id (0%); 0 have generated or unstable ids.

Partly scored — 1 needs work
AIR-2.6 Key facts exist as HTML text, not only in images or PDFs1 of 32 sampled pages are thin relative to their images or lead with a document download. NEEDS WORK
What's half-done

1 of 32 sampled pages are thin relative to their images or lead with a document download.

Full marks — 2 pass
AIR-2.1 Primary content is present without JavaScript PASS
Why we test this

Raw HTML contains 91% of rendered text on average across 32 URLs. The worst template is /about-tenable/*: 72% across 1 pages.

AIR-2.5 Alt text on content images, empty alt on decorative PASS
Why we test this

371 of 449 images carry appropriate alt text: 49 have no alt attribute, 29 use the filename.

3 · Structured Data and the Entity Graph 4 27
Scored zero — 2 problems
AIR-3.2 BreadcrumbList on every page below the homepage0% of pages below the homepage carry a BreadcrumbList with at least two steps. PROBLEM
What's wrong

0% of pages below the homepage carry a BreadcrumbList with at least two steps.

AIR-3.4 FAQPage and QAPage on genuine question-and-answer content0 pages carry FAQ or QA markup; 11 pages show visible question-and-answer content. PROBLEM
What's wrong

0 pages carry FAQ or QA markup; 11 pages show visible question-and-answer content.

Partly scored — 2 need work
AIR-3.1 JSON-LD is generated from mapped fields, not hardcoded1 of 2 templates repeat identical schema literals across pages whose visible content differs. NEEDS WORK
What's half-done

1 of 2 templates repeat identical schema literals across pages whose visible content differs.

AIR-3.5 isAccessibleForFree, about, and mentions with entity references0 of 30 substantive pages declare isAccessibleForFree; 1 reference subject entities by identifier. NEEDS WORK
What's half-done

0 of 30 substantive pages declare isAccessibleForFree; 1 reference subject entities by identifier.

Full marks — 2 pass
AIR-3.6 Product, Offer, and Service with real prices PASS
Why we test this

4 Offer nodes: 4 complete and matching the page, 0 drifting from visible values, 0 past priceValidUntil.

AIR-3.8 Schema validation of the structured data on the page PASS
Why we test this

Everything parses and every node carries what its type needs; 3 of 31 pages hold a value in the wrong shape.

4 · Crawl, Index and Licensing Hygiene 6 50
Scored zero — 1 problem
AIR-4.4 Correct X-Robots-Tag on non-HTML resources0 of 25 non-HTML resources carry an X-Robots-Tag. PROBLEM
What's wrong

0 of 25 non-HTML resources carry an X-Robots-Tag.

Partly scored — 1 needs work
AIR-4.5 Missing pages return 404 or 4100 of 8 deliberately invalid URLs returned HTTP 200; 1 sampled pages are thin enough to be not-found templates. NEEDS WORK
What's half-done

0 of 8 deliberately invalid URLs returned HTTP 200; 1 sampled pages are thin enough to be not-found templates.

Full marks — 4 pass
AIR-4.6 Redirects resolve in a single hop PASS
Why we test this

0 of 32 sampled URLs redirect.

AIR-4.7 Faceted, calendar, and parameterized URLs are controlled PASS
Why we test this

10 of 10 parameterized URLs are held in check by noindex or a canonical back to the unfiltered listing.

AIR-4.8 Sitemap lastmod reflects real content changes PASS
Why we test this

6562 of 6562 sitemap URLs carry a lastmod across 1732 distinct dates; 8% share 2013-05-13.

AIR-4.9 Sitemap index split by type, with media sitemaps PASS
Why we test this

An index with 2 child sitemaps covering 6562 URLs, with no image or video sitemap.

5 · Authorship, Provenance, Freshness 0 0
Scored zero — 3 problems
AIR-5.1 Author entity pages with credentialsNo Person entities appear anywhere in the sample. PROBLEM
What's wrong

No Person entities appear anywhere in the sample.

AIR-5.2 Bylines linked to author entities0 of 30 substantive pages reference an author by @id; 0 carry a bare string; 30 are unsigned. PROBLEM
What's wrong

0 of 30 substantive pages reference an author by @id; 0 carry a bare string; 30 are unsigned.

AIR-5.4 datePublished and dateModified are accurate0 of 32 pages carry a publication or modification date across 0 distinct dateModified values. PROBLEM
What's wrong

0 of 32 pages carry a publication or modification date across 0 distinct dateModified values.

6 · Agent Interfaces 4 50
Full marks — 2 pass
AIR-6.3 Form fields carry label, name, and autocomplete PASS
Why we test this

423 of 424 form fields carry an accessible name, a meaningful name attribute and a valid autocomplete token where one applies.

AIR-6.4 No captchas on browse, search, or filter interactions PASS
Why we test this

No search or filter surface in the sample returned a challenge.

7 · Alternate Representations 2 25
Scored zero — 2 problems
AIR-7.1 Markdown companion for every canonical page0 of 16 sampled pages have a Markdown companion at {path}.md returning a Markdown content type. PROBLEM
What's wrong

0 of 16 sampled pages have a Markdown companion at {path}.md returning a Markdown content type.

AIR-7.3 Accept: text/markdown content negotiation0 of 25 URLs serve Markdown for Accept: text/markdown. PROBLEM
What's wrong

0 of 25 URLs serve Markdown for Accept: text/markdown.

Full marks — 1 pass
AIR-7.4 Alternate representations are edge-cached PASS
Why we test this

1 of 1 generated representations show evidence of an edge cache hit on a repeat request.

What was read

32 pages, sampled from this site's own sitemap and internal links. The cap is 32 — a ceiling, not a certainty: a site with fewer reachable pages yields fewer.

403 https://connect.tenable.com/ Answered 403.
31 other pages, all 200, by template
12× / https://www.tenable.com/
8× /products/* https://www.tenable.com/products/tenable-one
2× /products/tenable-one/* https://www.tenable.com/products/tenable-one/pricing
1× /cyberagents-exchange https://www.tenable.com/cyberagents-exchange
1× /buy https://www.tenable.com/buy
1× /try https://www.tenable.com/try
1× /about-tenable/* https://www.tenable.com/about-tenable/contact-tenable
1× /cloud-security/products/* https://www.tenable.com/cloud-security/products/cnapp
1× /products/tenable-one/capabilities/* https://www.tenable.com/products/tenable-one/capabilities/hexa-ai
1× /products https://www.tenable.com/products
2× /solutions/* https://www.tenable.com/solutions/ai-security

The receipt

Cohort
drupal-100
Source
Tranco top sites list (Tranco (Le Pochat et al., NDSS 2019), 2026-09-06)
Index
11.0, in effect 2026-09-24
Scanner
0.1.0
Scanned
2026-09-20T00:08:10.497478+00:00
Result hash
e02d1d289399c893ec9ecde579ca22d077aa862f046f0c06a517e45976431a4c
Basis
public-interest census: a declared bot with a published policy at https://readinessindex.io/bot, honoring robots.txt addressed to AIRBot, reading public pages only. No per-site permission was sought or given.

The hash is the SHA-256 of the full result.json, recorded when the scan finished rather than computed now. The raw evidence behind every line above — every response, cached — is retained and is a median 1.5 MB per site, so it is not served from here. Ask us for it if you want to check a number against the bytes it came from.

Think this is wrong? It might be. Tell us at hello@readinessindex.io and we will look, correct it if it is, and say so publicly either way.

Is your site ready for AI?

Scan a page, get a number you can verify. Free.

About these numbers. Points are whole numbers everywhere on this page. The arithmetic behind them is not — a test scores its weight times its band divided by four, so a row can earn 1.5 points and print as 2. Scores are computed from the exact figures and rounded once, at the end, never from the rounded rows. That means adding the points column up will not give you the score exactly. The rule is published in the standard.