DEV Community

Auditready
Auditready

Posted on

I built an accessibility scanner that's honest about what it can't see

I built an accessibility scanner that's honest about what it can't see

I build AuditReady, an accessibility scanner that runs 12 deterministic checks on a page's HTML and turns the findings into a report an agency can hand a client. This is a maker post, so the disclosure goes first: it's my product, and you should read the rest with that in mind. Most of what follows is about what it can't do, because that's the part worth getting right.

The gap isn't detection, it's the deliverable

Agencies keep asking for "an accessibility report". What the free tools hand back is a list aimed at whoever will fix the issue: rule names, DOM nodes, a count, sometimes a score. That's the right output for a developer mid-sprint, and WAVE, Lighthouse, axe, Accessibility Insights and Pa11y are all good at it — and free. The gap is the document. A bare count of issues isn't something a client can act on or sign off, and it doesn't say what was tested, what was found, or what still needs a person.

What it does

You paste one page address. The server fetches that page's HTML as a public visitor would and runs 12 checks over it: missing alt text; form fields with no label; heading structure (exactly one h1, no skipped levels); a missing or empty page title; a missing lang attribute; link text like "click here" or "read more"; pinch-zoom switched off in the viewport meta tag; icon buttons and links with no accessible name; iframes with no title; duplicate id values; positive tabindex; and data tables with no header cells.

Every finding carries the WCAG 2.2 success criterion it maps to, the number of instances, the offending elements with their position in the document, and a copy-paste fix. The checks are deterministic code: the same HTML always produces the same findings, nothing is model-generated.

The free scan shows the top five finding groups. The full report — one-off $29 per site, no subscription, no account — shows every finding with up to five examples each, grouped by severity, plus a coverage table (each check that ran, how many elements it examined, and whether it found failures) and a 13-item manual-review checklist. Your agency's name goes at the top as "Prepared by …", and the report prints or saves to PDF from the browser. Nothing is emailed anywhere; the file you save is the deliverable. Nothing about the visitor is stored.

What it cannot see

No JavaScript runs. There is no browser — the page is fetched and parsed as HTML — so anything rendered on the client (React, Vue, cookie walls, JS-built menus) is invisible, and a client-rendered page shows fewer findings here than it actually has. Document-level checks still work (title, lang, viewport meta, iframe titles), because those arrive in the server HTML.

The checks can't judge quality. They can prove an alt attribute exists; they can't tell you whether it describes the image usefully. Same for link text and error messages. Contrast, keyboard operation, focus order, keyboard traps, screen-reader announcements and timing all need a person, as does anything behind a login or inside a third-party widget. And one page is a snapshot, not a crawl: you get the address you pasted, as it was a moment ago, not the rest of the site and not a history.

The sentence on the site, verbatim: "Automated tools catch only a minority of WCAG issues. AuditReady is not a compliance guarantee and not legal advice — a manual review by a person is still required." If your stack renders on the client, use axe or Lighthouse with JS rendering. I'd rather say that than take $29 for a thin result.

Why not an overlay, why not a crawler

An overlay injects a script into the site and promises to make it accessible. That's a claim no automated scan can support, and it's the one thing the accessibility community has spent years arguing against. AuditReady doesn't touch the scanned page at all: no snippet, no script, no change its visitors ever see. A crawler is the other tempting direction, and whole-site monitoring is a real need — but it's a different product. If you want coverage over time, or proof that forty things got fixed last month, use a monitoring platform. This is for the page you're about to ship or hand over.

Because the scanner fetches arbitrary URLs, the fetcher is guarded: the hostname is resolved before any connection and non-public addresses are refused, redirects are re-checked on every hop, and there's a 15-second deadline with a 3 MB cap enforced while streaming.

A real example

There's a live report for python.org — produced by an actual scan of that page and served from the capture, findings untidied: a real AuditReady report for python.org. The agency name on it, Northline Studio, is explicitly labelled a placeholder that implies no client relationship. Re-scan python.org yourself and compare.

Tell me what the checks miss

If you have five minutes, run a page you know well through the free scan and tell me what's wrong with it. The false negatives are already listed above; the interesting ones are the false positives, and the checks that should exist and don't. Comments here are the best place — the scan is free, rate-limited to 5 scans per rolling minute per IP, and nothing about you is kept.

Top comments (0)