generated: '2026-09-04' method: probed source: openapi/_ae-authored/vice-media-wp-rest-openapi.yml plus live requests to vice.com on 2026-09-04 note: Reward-only. Vice Media makes no compliance or certification claim anywhere public, so no Compliance pointer is emitted. What the surface does declare is the syndication and embedding standards a publisher is expected to speak, and those are recorded here with the exact location that proves each one. standards: - id: oembed-1.0 conforms: true domain_standard: true evidence: GET https://www.vice.com/wp-json/oembed/1.0/embed?url=
returned HTTP 200 with {"version":"1.0","provider_name":"VICE","provider_url":"https://www.vice.com","type":"rich",...} - a conformant oEmbed 1.0 rich response naming VICE as the provider. note: The publishing industry's embed standard; an integrator that speaks oEmbed needs no connector. - id: rss-2.0 conforms: true domain_standard: true evidence: https://www.vice.com/en/feed/ returned HTTP 200 with and the content, wfw, dc, atom, sy, slash and media (Yahoo Media RSS) namespaces declared. - id: dublin-core conforms: true evidence: xmlns:dc="http://purl.org/dc/elements/1.1/" declared on the RSS channel. - id: media-rss conforms: true evidence: xmlns:media="http://search.yahoo.com/mrss/" declared on the RSS channel. - id: sitemaps-0.9 conforms: true evidence: https://www.vice.com/sitemap.xml returned HTTP 200, ~1.0 MB, a with year-partitioned children back to 1970; robots.txt enumerates 30 of them. - id: rfc8288-web-linking conforms: true evidence: 'Collection responses return link: <...&page=2>; rel="next" and expose it through access-control-expose-headers.' - id: rfc8615-well-known conforms: false evidence: Every named /.well-known path returned 404 on vice.com, video.vice.com and vicemedia.com, and 403 on api.vice.com. See well-known/vice-media-well-known.yml. - id: rfc9116-security-txt conforms: false evidence: https://www.vice.com/.well-known/security.txt returned HTTP 404. VICE does publish a responsible-disclosure policy, but as an editorial page rather than as security.txt. - id: rfc9457-problem-details conforms: false evidence: Errors return the WordPress envelope {code, message, data.status} as application/json, not application/problem+json. - id: oauth2 conforms: false evidence: No oauth2 securityScheme in either contract; /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource 404 on both WordPress hosts. - id: oidc conforms: false evidence: https://www.vice.com/.well-known/openid-configuration returned HTTP 404. - id: json-schema conforms: true evidence: Every route in the discovery document declares its arguments with JSON Schema keywords - type, enum, default, required, items, minimum, maximum, format - which is what makes a faithful OpenAPI derivable from it at all. - id: apis-json conforms: false evidence: /apis.json, /apis.yml and /.well-known/apis.json all returned HTTP 404 on every host. - id: iab-adcom-openrtb conforms: false evidence: No bid endpoint, ads.txt-driven programmatic contract or OpenRTB surface is exposed on any host probed. Noted because it is the standard this sector would be expected to speak; its absence is not penalised. - id: schema-org conforms: true evidence: Article pages carry two