generated: '2026-07-21' method: searched host: https://watchtowr.com notes: security.txt is published at the root path /security.txt (the /.well-known/ location returns 404). The /.well-known/oauth-authorization-server document is real JSON but appears to be served by the marketing site's WordPress "Royal MCP" plugin (scopes_supported [mcp:full], service_documentation royalplugins.com/support/royal-mcp) — it is NOT the authorization server for the watchTowr Platform Client API, which authenticates with per-tenant bearer API keys. Probed 2026-07-21. hosts: - host: https://watchtowr.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/oauth-authorization-server status: 200 file: watchtowr-oauth-authorization-server.json - path: /.well-known/openid-configuration status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent.