HTTPS surface reachable (robots ✓, sitemap ✓, title ✓)
Why it matters: Public files — robots.txt, sitemap.xml, head meta — are what attackers see first during reconnaissance. Misadvertised paths, stale sitemaps, and verbose generators leak more than intended (ISO 27001 A.8.9).
robots.txt
present
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites like Yahoo!
# and Google. By telling these "robots" where not to go on your site,
# you save bandwidth and server resources.
#
# This file will be ignored unless it is at the root of your host:
# Used: http://example.com/robots.txt
# Ignored: http://example.com/site/robots.txt
#
# For more information about the robots.txt standard, see:
# http://www.robotstxt.org/robotstxt.html
User-agent: *
# CSS, JS, Images
Allow: /core/*.css$
Allow: /core/*.css?
Allow: /core/*.js$
Allow: /core/*.js?
Allow: /core/*.gif
Allow: /core/*.jpg
Allow: /core/*.jpeg
Allow: /core/*.png
Allow: /core/*.svg
Allow: /profiles/*.css$
Allow: /profiles/*.css?
Allow: /profiles/*.js$
Allow: /profiles/*.js?
Allow: /profiles/*.gif
Allow: /profiles/*.jpg
Allow: /profiles/*.jpeg
Allow: /profiles/*.png
Allow: /profiles/*.svg
# Directories
Disallow: /core/
Disallow: /profiles/
# Files
Disallow: /README.txt
Disallow: /web.config
# Paths (clean URLs)
Disallow: /admin/
Disallow: /comment/reply/
Disallow: /filter/tips
Disallow: /node/add/
Disallow: /search/
Disallow: /user/register/
Disallow: /user/password/
Disallow: /user/login/
Disallow: /user/logout/
# Paths (no clean URLs)
Disallow: /index.php/admin/
Disallow: /index.php/comment/reply/
Disallow: /index.php/filter/tips
Disallow: /index.php/node/add/
Disallow: /index.php/search/
Disallow: /index.php/user/password/
Disallow: /index.php/user/register/
Disallow: /index.php/user/login/
Disallow: /index.php/user/logout/
# Search pages per EPAD8-2542
Disallow: /newsreleases/search/
Disallow: /faqs/search/
Disallow: /perspectives/search/
Disallow: /publicnotices/notices-search/
Disallow: /speeches/search/
# Theme artifacts (including pattern lab):
Disallow: /themes/
Allow: /themes/*.css$
Allow: /themes/*.css?
Allow: /themes/*.js$
Allow: /themes/*.js?
Allow: /themes/*.gif
Allow: /themes/*.jpg
Allow: /themes/*.jpeg
Allow: /themes/*.png
Allow: /themes/*.svg
sitemap.xml
present — 38 url(s)
head
- title
- U.S. Environmental Protection Agency | US EPA
- description
- Website of the U.S. Environmental Protection Agency (EPA). EPA's mission is to protect human health and the environment.
social
- og:site_name
- US EPA
- og:type
- Web Area Homepage
- og:url
- https://www.epa.gov/home
- og:title
- U.S. Environmental Protection Agency | US EPA
- og:description
- Website of the U.S. Environmental Protection Agency (EPA). EPA's mission is to protect human health and the environment.
- og:image
- https://www.epa.gov/system/files/images/2022-03/epa-standard-twitter.jpg
- og:image:width
- 1200
- og:image:height
- 630
- og:image:alt
- U.S. Environmental Protection Agency
- og:updated_time
- 2026-04-27
- og:country_name
- United States of America
- twitter:card
- summary_large_image
- twitter:title
- U.S. Environmental Protection Agency | US EPA
- twitter:description
- Website of the U.S. Environmental Protection Agency (EPA). EPA's mission is to protect human health and the environment.
- twitter:image:alt
- U.S. Environmental Protection Agency
- twitter:image
- https://www.epa.gov/system/files/images/2022-03/epa-standard-twitter.jpg