generated: '2026-08-04' method: probed source: live probes of /.well-known/ and root discovery paths on cresilon.com hosts: - host: https://cresilon.com note: >- Also the API host — the WordPress REST surface is served from the same origin at /wp-json/. No api./developer./docs./status./trust. subdomain exists (none resolve), so there is no second host to probe. vetigel.com resolves and serves a separate product site; it publishes no /.well-known/ documents and no API. documents: - path: /.well-known/security.txt spec: RFC 9116 status: 404 - path: /.well-known/openid-configuration spec: OpenID Connect Discovery status: 404 - path: /.well-known/oauth-authorization-server spec: RFC 8414 status: 404 - path: /.well-known/oauth-protected-resource spec: RFC 9728 status: 404 - path: /.well-known/api-catalog spec: RFC 9727 status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json spec: A2A 1.0.0 status: 404 - path: /.well-known/agent.json spec: A2A pre-0.3 legacy status: 404 - path: /.well-known/change-password spec: W3C change-password URL status: 404 - path: /.well-known/dnt-policy.txt status: 404 - path: /llms.txt status: 404 - path: /openapi.json status: 404 - path: /openapi.yaml status: 404 - path: /swagger.json status: 404 - path: /v1/openapi.json status: 404 - path: /api-docs status: 404 - path: /docs status: 404 - path: /redoc status: 404 - path: /graphql status: 404 - path: /wp-json/graphql status: 404 - path: /asyncapi.yaml status: 404 - path: /robots.txt status: 200 file: cresilon-robots.txt note: >- Allows all user agents with an empty Disallow and no Crawl-delay. Declares three sitemaps. Carries no AI/agent directives — no GPTBot, ClaudeBot, CCBot or Google-Extended rule of any kind, so the site takes no stated position on agent crawling. - path: /sitemap.xml status: 200 note: Jetpack sitemap index — page, image and video sitemaps. lastmod 2026-07-31 at capture. - path: /sitemap_index.xml status: 200 note: Yoast SEO sitemap index, declared in robots.txt. - path: /news-sitemap.xml status: 200 note: Google News sitemap, declared in robots.txt. - path: /feed/ status: 200 note: RSS 2.0 feed of the same 36 posts exposed by /wp-json/wp/v2/posts. - path: /wp-json/ status: 200 note: >- The one real machine-readable discovery document on this host — the WordPress REST root index, advertising 45 namespaces and 1,021 routes with per-route methods and argument schemas, plus an `authentication` block naming Application Passwords. Described in openapi/cresilon-discovery-api-openapi.yml (getRouteIndex). notes: >- cresilon.com publishes no /.well-known/ discovery documents at all, and no A2A agent card at either the canonical or the legacy path. Note the false-positive hazard on this host: the WordPress 404 handler returns a full HTML page (~277 KB) for unknown /.well-known/* paths, so a naive probe that only checks for a non-empty body would mis-read every one of these as a hit. Each 404 above is the observed HTTP status, and every 404 body was text/html, not JSON. The only discovery surface that exists is the WordPress route index at /wp-json/, which is why the contract-discovery pass treated it as the provider's machine-readable contract. x-evidence: fetched: '2026-08-04' host: https://cresilon.com probe_method: HTTP GET following redirects, status recorded from the final response false_positive_guard: >- All 404 responses returned content-type text/html with a body size of ~277 KB; none parsed as JSON. No 200 was accepted on the strength of a body alone.