generated: '2026-08-12' method: probed source: >- live probes of mailoptin.io on 2026-08-12 plus https://mailoptin.io/gdpr-compliance/, https://mailoptin.io/privacy-policy/, https://mailoptin.io/terms-conditions/ note: >- Every `conforms: true` below is backed by a document fetched from mailoptin.io, not by a marketing claim. MailOptin publishes no compliance program, no certifications and no trust centre, so no `Compliance` pointer is emitted from this file. standards: - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: url: https://mailoptin.io/.well-known/oauth-authorization-server http_status: 200 detail: >- Valid JSON with issuer, authorization_endpoint, token_endpoint, revocation_endpoint, response_types_supported, grant_types_supported, code_challenge_methods_supported, scopes_supported, token_endpoint_auth_methods_supported. - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true evidence: url: https://mailoptin.io/.well-known/oauth-protected-resource http_status: 200 detail: >- Declares resource, authorization_servers, bearer_methods_supported and scopes_supported, and is linked from the WWW-Authenticate header of the 401 the MCP endpoint returns. - id: oauth2 name: OAuth 2.0 / 2.1 authorization code conforms: true evidence: url: https://mailoptin.io/.well-known/oauth-authorization-server http_status: 200 detail: authorization_code + refresh_token grants, public clients, PKCE required. - id: rfc7636 name: PKCE conforms: true evidence: url: https://mailoptin.io/.well-known/oauth-authorization-server http_status: 200 detail: code_challenge_methods_supported ["S256"] — plain is not offered. - id: mcp name: Model Context Protocol conforms: partial evidence: url: https://mailoptin.io/wp-json/mcp/mcp-oauth-server http_status: 401 detail: >- A live MCP endpoint with a spec-conformant OAuth challenge, but tools/list is gated so protocol conformance beyond the authorization handshake could not be verified. - id: rfc8288 name: Web Linking (pagination) conforms: true evidence: url: https://mailoptin.io/wp-json/wp/v2/posts?per_page=2 http_status: 200 detail: 'Link: <...page=2>; rel="next"' - id: oidc name: OpenID Connect Discovery conforms: false evidence: url: https://mailoptin.io/.well-known/openid-configuration http_status: 404 - id: rfc9457 name: Problem Details for HTTP APIs conforms: false evidence: url: https://mailoptin.io/wp-json/nope/v1/nope http_status: 404 detail: >- Returns the WordPress error object as application/json, not application/problem+json. - id: rfc9116 name: security.txt conforms: false evidence: url: https://mailoptin.io/.well-known/security.txt http_status: 404 - id: rfc8594 name: Sunset HTTP header conforms: false evidence: url: https://mailoptin.io/changelog/ http_status: 200 detail: No deprecation or sunset policy is published; no Sunset/Deprecation headers observed. - id: openapi name: OpenAPI conforms: false evidence: url: https://mailoptin.io/openapi.json http_status: 404 detail: >- No OpenAPI at any probed location on mailoptin.io, my.mailoptin.io, or the GitHub org. The site's REST API is self-describing via its own route index instead. - id: asyncapi name: AsyncAPI conforms: false evidence: url: https://mailoptin.io/article/trigger-webhooks-wordpress-form-submissions/ http_status: 200 detail: A webhook feature is documented in prose; no event specification is published. - id: idempotency name: Idempotency keys conforms: false evidence: url: https://mailoptin.io/wp-json/ http_status: 200 detail: No idempotency key accepted on any surface; the outbound webhook sends none. regulatory: - id: gdpr name: GDPR claim: >- MailOptin publishes a GDPR guide describing plugin features that help a SITE OWNER meet GDPR obligations — consent checkboxes, data minimisation, subscriber erasure and Lead Bank anonymisation on a WordPress erasure request, and export for portability. certified: false evidence: url: https://mailoptin.io/gdpr-compliance/ http_status: 200 note: >- This is customer-enablement guidance, not a compliance attestation. The page itself states "this is not a legal paper". No DPA, sub-processor list, SOC 2, ISO 27001, PCI, HIPAA or FedRAMP claim appears anywhere on the site. certifications: [] trust_center: published: false probed: true note: probe-security-programs.py returned vdp=none trust=none on 2026-08-12.