Scanners

Kuality offers a comprehensive suite of security scanners. Each kuality targets a specific attack surface, giving you full visibility into your website's security posture. Scanners marked Light+ require a paid plan.

Accessibility & UX

Accessibility (WCAG 2.2)

Free

WCAG 2.2 AA compliance audit. Checks alt text, contrast ratios, ARIA attributes, keyboard navigation, heading hierarchy, and form labels using axe-core.

  • WCAG 2.2 AA compliance
  • axe-core powered
  • ARIA & keyboard navigation

UX State Audit (404/500/empty/loading)

Free

UX state completeness audit. Verify your app handles 404, 500, empty states, and loading states with appropriate UI feedback.

  • 404 / 500 / empty states
  • Loading state coverage
  • Error boundary checks

Color-Blindness Simulation

Free

Color-blindness simulation across protanopia, deuteranopia, and tritanopia. Validates text contrast, icon labeling, and color-only cues.

  • Protanopia / deuteranopia / tritanopia
  • Color-only cue detection
  • Contrast ratio validation

Screen-Reader Reading Order Audit

Free

Screen-reader reading order simulation beyond axe-core. Validates DOM order, live region announcements, and interactive element focus flow.

  • DOM reading order
  • Live region announcements
  • Focus flow validation

Animation & Reduced-Motion Audit

Free

Animation and reduced-motion compliance. Check for prefers-reduced-motion support, excessive motion, and GPU-composited animation usage.

  • prefers-reduced-motion support
  • GPU-composited animations
  • Excessive motion detection

Touch Gesture & Viewport Audit

Free

Simulate touch gestures and validate behavior on mobile viewports. Check swipe, pinch-to-zoom, and scroll event handling.

  • Swipe & pinch-to-zoom
  • Mobile viewport behavior
  • Scroll event handling

Touch Target Size Validation

Free

Validate touch target sizes across all interactive elements. Flags any tap targets smaller than the 48×48px accessibility minimum.

  • 48×48px tap target enforcement
  • Interactive element sizing
  • Spacing between targets

Orientation & Safe Area Audit

Free

Test landscape/portrait orientation transitions and safe area insets for iPhone notch, Dynamic Island, and Android chin.

  • Landscape / portrait transitions
  • Safe area insets
  • Dynamic Island & notch support

Performance

Core Web Vitals & Performance

Free

Core Web Vitals (LCP, CLS, INP), performance score, and page load metrics. Know if your site feels fast to real users on real devices.

  • Core Web Vitals (LCP, CLS, INP)
  • Lighthouse performance score
  • Real-device simulation

Performance Budget Enforcement

Free

Enforce LCP/CLS/INP/FID performance budgets. Fail the build when Core Web Vitals exceed configured thresholds.

  • LCP / CLS / INP / FID budgets
  • CI gate integration
  • Regression alerting

Asset Weight & Render-Blocking Audit

Free

Audit page weight, third-party asset weight, and render-blocking resources. Identify oversized images, undeferred scripts, and slow third-party calls.

  • Page weight & third-party weight
  • Render-blocking resources
  • Undeferred scripts

JS Bundle Size Analysis

Free

Analyze JavaScript bundle sizes and enforce size budgets. Detect unnecessary code splitting opportunities and unused module exports.

  • JS bundle size analysis
  • Code-splitting opportunities
  • Unused module detection

Multi-Region Time-to-First-Byte

Free

Measure Time-to-First-Byte from multiple geographic regions (US East, US West, EU, APAC). Surface regional performance regressions.

  • Multi-region TTFB measurement
  • US East / West / EU / APAC
  • Regional regression detection

Network Throttling Simulation

Free

Simulate 3G and 4G network conditions. Validate that your site remains usable and passes Core Web Vitals targets on constrained connections.

  • 3G / 4G network simulation
  • Core Web Vitals under throttle
  • Constrained connection UX

Memory Leak Detection

Free

Detect JavaScript memory leaks over extended browser sessions. Profiles heap snapshots over repeated navigation cycles.

  • Heap snapshot profiling
  • Extended session simulation
  • Repeated navigation cycles

Mobile Lighthouse Audit

Free

Full Lighthouse audit optimized for mobile simulation — Moto G4 emulation, 4G throttling, and mobile-specific performance benchmarks.

  • Moto G4 emulation
  • 4G throttling
  • Mobile-specific benchmarks

Image & Font Optimization Audit

Free

Image optimization, font loading, and lazy-loading audit. Surface uncompressed images, render-blocking fonts, and missing lazy-load attributes.

  • Image compression audit
  • Font render-blocking
  • Lazy-load coverage

Quality & Links

SEO & Meta Tags

Free

Meta tags, Open Graph, Twitter Cards, structured data, canonical URLs, heading hierarchy, robots.txt, sitemap, and image alt coverage.

  • Meta tags & Open Graph
  • Structured data & canonical
  • robots.txt & sitemap

Form Quality Audit

Free

Audit every form on the page: label associations, required attributes, autocomplete hints, CSRF protection, submit buttons, and placeholder-as-label patterns.

  • Label associations
  • CSRF protection
  • Autocomplete & required attrs

Broken Link Checker

Free

Crawl for dead links, missing images, broken scripts, and mixed HTTP/HTTPS content. Find the 404s before your users do.

  • Dead links & 404s
  • Missing images & scripts
  • Mixed content issues

CMS Health Check

Free

WordPress, Drupal, and CMS health check. Detect outdated core versions, vulnerable plugins, and exposed admin endpoints.

  • WordPress / Drupal health
  • Outdated plugins & themes
  • Exposed admin endpoints

Technology & Version Audit

Free

Identify frameworks, libraries, and server technologies in use. Cross-reference versions against known issues.

  • Framework & library detection
  • CVE cross-referencing
  • Outdated dependency flags

Security

Web

Free

  • XSS & SQL injection
  • OWASP Top 10 vulnerabilities
  • Insecure configurations

HTTP Headers Audit

Free

HTTP header best practices: Content-Security-Policy, HSTS, X-Frame-Options, Permissions-Policy, Referrer-Policy, and more.

  • CSP & X-Frame-Options
  • HSTS & Referrer-Policy
  • Permissions-Policy

Dynamic

Free

  • OWASP ZAP active probing
  • Injection & auth bypass
  • Misconfiguration detection

Content Security Policy Audit

Free

Deep Content Security Policy audit. Parses and grades your CSP header: detects unsafe-inline, unsafe-eval, wildcard hosts, missing directives, and report-uri configuration.

  • CSP header grading
  • unsafe-inline / unsafe-eval detection
  • report-uri configuration

CORS Configuration Audit

Free

CORS configuration audit. Detects permissive `Access-Control-Allow-Origin: *`, missing `Vary: Origin`, credentials with wildcard, and pre-flight misconfiguration that enables cross-origin data theft.

  • Wildcard origin detection
  • Credentials + wildcard check
  • Pre-flight misconfiguration

Privacy & Data Exposure Scan

Free

Privacy and data exposure scan. Detects PII leakage in responses, third-party tracker loading, exposed API keys and tokens in JS, and GDPR/CCPA consent flow gaps.

  • PII leakage detection
  • Third-party tracker audit
  • Exposed API keys in JS

Cookie & Consent Compliance

Free

Cookie compliance for GDPR/CCPA. Detect tracking cookies set before consent, missing Secure/HttpOnly flags, and third-party scripts loading without opt-in.

  • Pre-consent tracking cookies
  • Missing Secure & HttpOnly flags
  • Third-party script audit

JS Dependency Health

Free

Check loaded JavaScript libraries for known vulnerabilities, outdated versions, and exposed package manifests.

  • Known vulnerable JS libraries
  • Outdated npm dependencies
  • Client-side risk scoring

API & Integrations

API Quality Audit

Free

REST and GraphQL endpoint quality: authentication checks, rate limiting, data exposure, and error handling patterns.

  • Broken authentication
  • Rate limiting issues
  • Excessive data exposure

GraphQL Schema Validation

Free

GraphQL schema validation and security audit. Detects introspection exposure, field-level authorization gaps, nested query DoS vectors, and broken object-level access control.

  • Introspection exposure
  • Nested query DoS vectors
  • Field-level auth gaps

OpenAPI Spec Compliance

Free

OpenAPI 3.x / Swagger spec compliance and live API fuzz testing. Validates that live responses conform to the declared schema — surfaces undocumented fields and broken contracts.

  • OpenAPI 3.x spec compliance
  • Live API fuzz testing
  • Undocumented field detection

OpenAPI Contract Testing

Free

OpenAPI contract testing. Validates that your live API responses match the schema defined in your OpenAPI spec.

  • OpenAPI contract validation
  • Response schema conformance
  • Breaking change detection

Synthetic Transaction Monitoring

Free

Synthetic transaction monitoring. Multi-step user flows (login → checkout → confirm) run on a schedule to verify critical paths are working.

  • Multi-step user flows
  • Login → checkout → confirm
  • Scheduled critical-path checks

Cross-Browser & Mobile

Cross-Browser: Firefox Headless

Free

Cross-browser validation using Firefox headless. Catch rendering differences, layout shifts, and behavior inconsistencies specific to the Gecko engine.

  • Gecko engine rendering
  • Layout shift detection
  • JS behavior inconsistencies

Cross-Browser: WebKit/Safari Headless

Free

Cross-browser validation using WebKit/Safari headless. Essential for catching Safari-specific CSS and JS quirks before users report them.

  • Safari-specific CSS quirks
  • WebKit JS bugs
  • Cross-browser validation

PWA Install & Service Worker Audit

Free

PWA audit: service worker registration, offline mode support, install flow, push notifications, and manifest validity.

  • Service worker registration
  • Offline mode support
  • Manifest & install flow

Monitoring

Uptime Monitor

Free

Continuous availability monitoring with alerting. Track response time, status codes, SSL expiry, and keyword presence.

  • 1-minute global pings
  • Keyword + status-code checks
  • SSL / cert expiry alerts

CDN & Cache Header Analysis

Free

CDN & cache header analysis. Inspects Cache-Control, Vary, ETag, CDN provider detection, and cache-busting correctness.

  • Cache-Control & Vary headers
  • CDN provider detection
  • Cache-busting correctness
Version 1.0.65