generated: '2026-09-04' method: probed source: >- openapi/_ae-authored/wow-momo-content-api-openapi.yml plus live requests to www.wowmomo.com and api.wowmomo.com on 2026-09-04 note: >- Reward-only. WOW! Momo makes no compliance or certification claim anywhere public, so no Compliance pointer is emitted. What the surface does declare is the syndication and embedding standards a consumer-brand website is expected to speak, and those are recorded here with the exact location that proves each one. Every `conforms: false` below was probed, not assumed. standards: - id: oembed-1.0 conforms: true domain_standard: true evidence: >- GET https://www.wowmomo.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fwww.wowmomo.com%2F returned HTTP 200 with {"version":"1.0","provider_name":"WOW! Momo","provider_url":"https://www.wowmomo.com", ...} — a conformant oEmbed 1.0 response naming WOW! Momo as the provider. A URL off the domain returns 404 oembed_invalid_url, which is the correct provider behaviour. - id: rss-2.0 conforms: true evidence: >- https://www.wowmomo.com/feed/ returned HTTP 200 with and the content, wfw, dc, atom, sy and slash namespaces declared. note: >- The feed is structurally conformant but carries zero elements, because the install has never published a post. A valid feed with nothing in it. - id: dublin-core conforms: true evidence: xmlns:dc="http://purl.org/dc/elements/1.1/" declared on the RSS channel. - id: sitemaps-0.9 conforms: true evidence: >- https://www.wowmomo.com/sitemap_index.xml returned HTTP 200 with a naming page-sitemap.xml and elementor-hf-sitemap.xml; robots.txt points at it. - id: schema-org conforms: true evidence: >- The home page carries an application/ld+json @graph generated by Yoast SEO 28.4 with Organization, WebSite, WebPage, BreadcrumbList, ImageObject and a SearchAction/EntryPoint. The same graph is served as JSON from GET /wp-json/yoast/v1/get_head?url=..., which answers anonymously. - id: rfc8288-web-linking conforms: true evidence: >- Collection responses return link: <...&page=2>; rel="next" and name Link in access-control-expose-headers. - id: json-schema conforms: true evidence: >- Every route in the discovery document declares its arguments with JSON Schema keywords — type, enum, default, required, items, minimum, maximum — and each collection answers HTTP OPTIONS with a full JSON Schema for its resource. That is what makes a faithful OpenAPI derivable from this surface at all. - id: rfc8615-well-known conforms: false evidence: >- Every named /.well-known path returned 404 on www.wowmomo.com and wowmomo.com. api.wowmomo.com returns 200 for all of them, but so does a control path that cannot exist, and every body is the same NO_AUTH gate. See well-known/wow-momo-well-known.yml. - id: rfc9116-security-txt conforms: false evidence: >- https://www.wowmomo.com/.well-known/security.txt returned HTTP 404, and no responsible-disclosure or security page exists anywhere on the site. This is the cheapest fix available to this provider. - id: rfc9457-problem-details conforms: false evidence: >- Errors return the WordPress envelope {code, message, data.status} as application/json, not application/problem+json. api.wowmomo.com is worse: it returns HTTP 200 for an auth failure. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme exists in the derived contract; /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource 404 on the content host and are gated on the app host. - id: oidc conforms: false evidence: https://www.wowmomo.com/.well-known/openid-configuration returned HTTP 404. - id: apis-json conforms: false evidence: /apis.json, /apis.yml and /.well-known/apis.json all returned HTTP 404 on both WordPress hosts. - id: llms-txt conforms: false evidence: >- https://www.wowmomo.com/llms.txt returned HTTP 404. The llms/ artifact in this repository is generated by API Evangelist, not published by WOW! Momo. - id: rfc9309-robots conforms: true evidence: >- https://www.wowmomo.com/robots.txt returned HTTP 200 with a valid "User-agent: * / Disallow:" record and a Sitemap directive. It declares no AI-crawler rule and no Content Signals policy. - id: schema-org-restaurant conforms: false domain_standard: true evidence: >- Noted because it is the standard this sector would be expected to speak: schema.org Restaurant / Menu / MenuItem / hasMenu markup, which is what makes an outlet, its hours and its menu machine readable for search, delivery aggregators and agents. The site's JSON-LD graph declares Organization and WebSite only, and no menu or outlet data is exposed on any WOW! Momo host. Its absence is not penalised. - id: iso-20022 conforms: false evidence: >- Not applicable — no payment, settlement or financial-messaging surface is exposed. Recorded so the absence is legible rather than untested.