<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Auditready</title>
    <description>The latest articles on DEV Community by Auditready (@auditready).</description>
    <link>https://dev.to/auditready</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4150759%2F0954b31a-327c-44b5-a76a-db37be957faa.png</url>
      <title>DEV Community: Auditready</title>
      <link>https://dev.to/auditready</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/auditready"/>
    <language>en</language>
    <item>
      <title>I built an accessibility scanner that's honest about what it can't see</title>
      <dc:creator>Auditready</dc:creator>
      <pubDate>Tue, 29 Sep 2026 18:15:49 +0000</pubDate>
      <link>https://dev.to/auditready/i-built-an-accessibility-scanner-thats-honest-about-what-it-cant-see-jpo</link>
      <guid>https://dev.to/auditready/i-built-an-accessibility-scanner-thats-honest-about-what-it-cant-see-jpo</guid>
      <description>&lt;h1&gt;
  
  
  I built an accessibility scanner that's honest about what it can't see
&lt;/h1&gt;

&lt;p&gt;I build AuditReady, an accessibility scanner that runs 12 deterministic checks on a page's HTML and turns the findings into a report an agency can hand a client. This is a maker post, so the disclosure goes first: it's my product, and you should read the rest with that in mind. Most of what follows is about what it can't do, because that's the part worth getting right.&lt;/p&gt;

&lt;h2&gt;
  
  
  The gap isn't detection, it's the deliverable
&lt;/h2&gt;

&lt;p&gt;Agencies keep asking for "an accessibility report". What the free tools hand back is a list aimed at whoever will fix the issue: rule names, DOM nodes, a count, sometimes a score. That's the right output for a developer mid-sprint, and WAVE, Lighthouse, axe, Accessibility Insights and Pa11y are all good at it — and free. The gap is the document. A bare count of issues isn't something a client can act on or sign off, and it doesn't say what was tested, what was found, or what still needs a person.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it does
&lt;/h2&gt;

&lt;p&gt;You paste one page address. The server fetches that page's HTML as a public visitor would and runs 12 checks over it: missing alt text; form fields with no label; heading structure (exactly one &lt;code&gt;h1&lt;/code&gt;, no skipped levels); a missing or empty page title; a missing &lt;code&gt;lang&lt;/code&gt; attribute; link text like "click here" or "read more"; pinch-zoom switched off in the viewport meta tag; icon buttons and links with no accessible name; iframes with no title; duplicate &lt;code&gt;id&lt;/code&gt; values; positive &lt;code&gt;tabindex&lt;/code&gt;; and data tables with no header cells.&lt;/p&gt;

&lt;p&gt;Every finding carries the WCAG 2.2 success criterion it maps to, the number of instances, the offending elements with their position in the document, and a copy-paste fix. The checks are deterministic code: the same HTML always produces the same findings, nothing is model-generated.&lt;/p&gt;

&lt;p&gt;The free scan shows the top five finding groups. The full report — one-off $29 per site, no subscription, no account — shows every finding with up to five examples each, grouped by severity, plus a coverage table (each check that ran, how many elements it examined, and whether it found failures) and a 13-item manual-review checklist. Your agency's name goes at the top as "Prepared by …", and the report prints or saves to PDF from the browser. Nothing is emailed anywhere; the file you save is the deliverable. Nothing about the visitor is stored.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it cannot see
&lt;/h2&gt;

&lt;p&gt;No JavaScript runs. There is no browser — the page is fetched and parsed as HTML — so anything rendered on the client (React, Vue, cookie walls, JS-built menus) is invisible, and a client-rendered page shows fewer findings here than it actually has. Document-level checks still work (title, &lt;code&gt;lang&lt;/code&gt;, viewport meta, iframe titles), because those arrive in the server HTML.&lt;/p&gt;

&lt;p&gt;The checks can't judge quality. They can prove an &lt;code&gt;alt&lt;/code&gt; attribute exists; they can't tell you whether it describes the image usefully. Same for link text and error messages. Contrast, keyboard operation, focus order, keyboard traps, screen-reader announcements and timing all need a person, as does anything behind a login or inside a third-party widget. And one page is a snapshot, not a crawl: you get the address you pasted, as it was a moment ago, not the rest of the site and not a history.&lt;/p&gt;

&lt;p&gt;The sentence on the site, verbatim: "Automated tools catch only a minority of WCAG issues. AuditReady is not a compliance guarantee and not legal advice — a manual review by a person is still required." If your stack renders on the client, use axe or Lighthouse with JS rendering. I'd rather say that than take $29 for a thin result.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why not an overlay, why not a crawler
&lt;/h2&gt;

&lt;p&gt;An overlay injects a script into the site and promises to make it accessible. That's a claim no automated scan can support, and it's the one thing the accessibility community has spent years arguing against. AuditReady doesn't touch the scanned page at all: no snippet, no script, no change its visitors ever see. A crawler is the other tempting direction, and whole-site monitoring is a real need — but it's a different product. If you want coverage over time, or proof that forty things got fixed last month, use a monitoring platform. This is for the page you're about to ship or hand over.&lt;/p&gt;

&lt;p&gt;Because the scanner fetches arbitrary URLs, the fetcher is guarded: the hostname is resolved before any connection and non-public addresses are refused, redirects are re-checked on every hop, and there's a 15-second deadline with a 3 MB cap enforced while streaming.&lt;/p&gt;

&lt;h2&gt;
  
  
  A real example
&lt;/h2&gt;

&lt;p&gt;There's a live report for python.org — produced by an actual scan of that page and served from the capture, findings untidied: &lt;a href="https://feaefe371424d0725b266468856c9101.ctonew.app/report?domain=https%3A%2F%2Fwww.python.org%2F&amp;amp;agency=Northline%20Studio" rel="noopener noreferrer"&gt;a real AuditReady report for python.org&lt;/a&gt;. The agency name on it, Northline Studio, is explicitly labelled a placeholder that implies no client relationship. Re-scan python.org yourself and compare.&lt;/p&gt;

&lt;h2&gt;
  
  
  Tell me what the checks miss
&lt;/h2&gt;

&lt;p&gt;If you have five minutes, run a page you know well through the free scan and tell me what's wrong with it. The false negatives are already listed above; the interesting ones are the false positives, and the checks that should exist and don't. Comments here are the best place — the scan is free, rate-limited to 5 scans per rolling minute per IP, and nothing about you is kept.&lt;/p&gt;

</description>
      <category>a11y</category>
      <category>webdev</category>
      <category>tooling</category>
    </item>
  </channel>
</rss>
