Skip to main content
QA Explorer
Sample report. This is a real QA Explorer scan, run on example-coffee-shop.com on 2026-06-07. Want to see what we'd find on your site? Drop your URL below to run your own free scan.

QA Report

https://example-coffee-shop.com

3a20b969-f0cb-4740-a2d6-cd7a9a22a5d9 · 7 Jun 2026, 15:50 · 993s

0Critical8High23Medium28Low50 pages scanned
PDFMarkdownCSV
Quality Assurance
example-coffee-shop.com
Automated scan of example-coffee-shop.com via QA Explorer. Covered 50 pages, ran 308 scripted test cases (222 passed), and surfaced 59 unique findings across functionality, UX, accessibility, performance, and security.
Confidential
Environmenthttps://example-coffee-shop.com
Projectexample-coffee-shop.com
MethodologyAutomated end-to-end exploratory scan (browser automation + DOM extraction)
TesterQA Explorer (automated)
Report Date2026-06-07
59
New Bugs
Bugs Fixed
UX Improved
308
Cases Run
222
Passed
59 findings · 8 high · 59 unique
Production Impact: 8 high-severity findings should be addressed before this build is promoted.
1Executive Summary
Example Coffee Shop's website is a functioning e-commerce platform for specialty coffee with solid fundamentals: all 49 reachable pages return successful responses, SSL/TLS is in place, and basic meta infrastructure is present. However, the scan uncovered a broad set of security, accessibility, and content-quality issues that collectively present real risk to customers, the business's legal standing under GDPR/KVKK, and search engine visibility.

The most serious concerns are security-related. Forms across the site — including the login, registration, and checkout flows — lack CSRF protection, meaning an attacker could trick a logged-in customer into placing orders or changing account data without their knowledge. The XSRF-TOKEN cookie is not marked HttpOnly, making it readable by JavaScript and vulnerable to theft. There is no Content Security Policy, leaving the site open to cross-site scripting attacks. Additionally, no cookie consent banner is present despite third-party cookies being set on load, which is a direct violation of Turkish KVKK and EU GDPR rules and exposes the business to regulatory fines. A required legal document (the KVKK application form PDF) is completely inaccessible — a broken link on a compliance page.

Accessibility is a systemic weakness: 215 buttons and 392 links have no readable label for screen-reader users, colour contrast fails on multiple pages, and nearly every inner page is missing a unique meta description and Open Graph metadata, severely hurting SEO and social sharing. The homepage alone weighs 4.81 MB, which will result in slow load times on mobile connections. The team should prioritise CSRF protection and cookie consent first as legal/security obligations, then address accessibility and SEO gaps which directly affect customer reach and inclusivity.

Production impact. 8 high-severity findings should be addressed before this build is promoted.
2Test Scope & Environment
FieldValue
Applicationexample-coffee-shop.com
Environmenthttps://example-coffee-shop.com
MethodologyAutomated end-to-end exploratory scan — a headless browser crawls same-origin links, captures DOM/console/screenshots, analyzer derives findings.
Pages Scanned50
Duration9 min 45 s
Report ID3a20b969-f0cb-4740-a2d6-cd7a9a22a5d9
AnalyzerQA Explorer Engine
3Test Execution Details
Scripted test cases executed against the target. Status values follow the test runner's convention (PASS / FAIL / UX / BLOCKED).
TS-NAV — Navigation & Page Load Tests
#Test StepExpected ResultActual ResultStatus
1Open homepageThe homepage should load successfully with all primary content visible.HTTP 200, loaded in 2.59s, 23 headings, 84 links, 17 images.✓ PASS
2Open Alisveris pageThe Alisveris page should load successfully with all content visible.HTTP 200, loaded in 2.33s, 73 headings, 266 links, 69 images.✓ PASS
3Open Kahveler pageThe Kahveler page should load successfully with all content visible.HTTP 200, loaded in 2.54s, 27 headings, 128 links, 23 images.✓ PASS
4Open Ekipmanlar pageThe Ekipmanlar page should load successfully with all content visible.HTTP 200, loaded in 2.31s, 37 headings, 156 links, 33 images.✓ PASS
5Open Aksesuar pageThe Aksesuar page should load successfully with all content visible.HTTP 200, loaded in 2.65s, 31 headings, 138 links, 27 images.✓ PASS
6Open Abonelikler pageThe Abonelikler page should load successfully with all content visible.HTTP 200, loaded in 2.32s, 28 headings, 74 links, 15 images.✓ PASS
7Open Kahve Aboneligi Otomatik Kahve Makinesi pageThe Kahve Aboneligi Otomatik Kahve Makinesi page should load successfully with all content visible.HTTP 200, loaded in 1.91s, 28 headings, 75 links, 11 images.✓ PASS
8Open Kahve Aboneligi Espresso pageThe Kahve Aboneligi Espresso page should load successfully with all content visible.HTTP 200, loaded in 2.04s, 28 headings, 75 links, 11 images.✓ PASS
9Open Kahve Aboneligi pageThe Kahve Aboneligi page should load successfully with all content visible.HTTP 200, loaded in 2.08s, 28 headings, 75 links, 11 images.✓ PASS
10Open Demleme Teknikleri pageThe Demleme Teknikleri page should load successfully with all content visible.HTTP 200, loaded in 2.35s, 18 headings, 77 links, 16 images.✓ PASS
11Open Filtre Kahve pageThe Filtre Kahve page should load successfully with all content visible.HTTP 200, loaded in 2.08s, 21 headings, 70 links, 8 images.✓ PASS
12Open Espresso pageThe Espresso page should load successfully with all content visible.HTTP 200, loaded in 2.30s, 19 headings, 70 links, 8 images.✓ PASS
13Open French Press pageThe French Press page should load successfully with all content visible.HTTP 200, loaded in 2.08s, 21 headings, 70 links, 8 images.✓ PASS
14Open Moka Pot pageThe Moka Pot page should load successfully with all content visible.HTTP 200, loaded in 2.18s, 21 headings, 70 links, 8 images.✓ PASS
15Open Hario V60 pageThe Hario V60 page should load successfully with all content visible.HTTP 200, loaded in 2.15s, 21 headings, 70 links, 8 images.✓ PASS
16Open Aeropress pageThe Aeropress page should load successfully with all content visible.HTTP 200, loaded in 2.09s, 21 headings, 70 links, 8 images.✓ PASS
17Open Turk Kahvesi pageThe Turk Kahvesi page should load successfully with all content visible.HTTP 200, loaded in 2.04s, 21 headings, 70 links, 8 images.✓ PASS
18Open Magazalar pageThe Magazalar page should load successfully with all content visible.HTTP 200, loaded in 3.10s, 11 headings, 109 links, 112 images.✓ PASS
19Open Makaleler pageThe Makaleler page should load successfully with all content visible.HTTP 200, loaded in 2.65s, 20 headings, 79 links, 20 images.✓ PASS
20Open Kahveni Bul pageThe Kahveni Bul page should load successfully with all content visible.HTTP 200, loaded in 2.13s, 19 headings, 71 links, 7 images.✓ PASS
21Open Kaydol pageThe Kaydol page should load successfully with all content visible.HTTP 200, loaded in 2.09s, 11 headings, 74 links, 7 images.✓ PASS
22Open Oturumac pageThe Oturumac page should load successfully with all content visible.HTTP 200, loaded in 2.08s, 11 headings, 72 links, 7 images.✓ PASS
23Open homepageThe homepage should load successfully with all primary content visible.HTTP 200, loaded in 2.41s, 23 headings, 84 links, 17 images.✓ PASS
24Open Kahve Abonelikleri pageThe Kahve Abonelikleri page should load successfully with all content visible.HTTP 200, loaded in 2.62s, 28 headings, 74 links, 15 images.✓ PASS
25Open Iletisim pageThe Iletisim page should load successfully with all content visible.HTTP 200, loaded in 2.29s, 11 headings, 70 links, 7 images.✓ PASS
26Open Example Coffee Shop Grounded Collection Oversized White T Shirt pageThe Example Coffee Shop Grounded Collection Oversized White T Shirt page should load successfully with all content visible.HTTP 200, loaded in 2.20s, 15 headings, 76 links, 12 images.✓ PASS
27Open Grounded Collection Oversized Green Hoodie pageThe Grounded Collection Oversized Green Hoodie page should load successfully with all content visible.HTTP 200, loaded in 2.35s, 15 headings, 76 links, 12 images.✓ PASS
28Open Etiyopya Korcha Natural Filtre pageThe Etiyopya Korcha Natural Filtre page should load successfully with all content visible.HTTP 200, loaded in 2.34s, 16 headings, 76 links, 13 images.✓ PASS
29Open Latte Fincani Logolu pageThe Latte Fincani Logolu page should load successfully with all content visible.HTTP 200, loaded in 2.26s, 14 headings, 75 links, 11 images.✓ PASS
30Open Etkinlik Egitim pageThe Etkinlik Egitim page should load successfully with all content visible.HTTP 200, loaded in 2.07s, 11 headings, 75 links, 7 images.✓ PASS
31Open Hikayemiz pageThe Hikayemiz page should load successfully with all content visible.HTTP 200, loaded in 2.04s, 11 headings, 70 links, 9 images.✓ PASS
32Open Iletisim pageThe Iletisim page should load successfully with all content visible.HTTP 200, loaded in 2.27s, 11 headings, 70 links, 7 images.✓ PASS
33Open Sss pageThe Sss page should load successfully with all content visible.HTTP 200, loaded in 2.04s, 49 headings, 70 links, 9 images.✓ PASS
34Open Menuler pageThe Menuler page should load successfully with all content visible.HTTP 200, loaded in 2.37s, 11 headings, 70 links, 11 images.✓ PASS
35Open Kahve Hakkinda pageThe Kahve Hakkinda page should load successfully with all content visible.HTTP 200, loaded in 2.27s, 13 headings, 83 links, 8 images.✓ PASS
36Open Kvkk pageThe Kvkk page should load successfully with all content visible.HTTP 200, loaded in 2.22s, 11 headings, 70 links, 7 images.✓ PASS
37Open Aydinlatma pageThe Aydinlatma page should load successfully with all content visible.HTTP 200, loaded in 2.15s, 11 headings, 70 links, 7 images.✓ PASS
38Open Cerez pageThe Cerez page should load successfully with all content visible.HTTP 200, loaded in 2.09s, 11 headings, 70 links, 7 images.✓ PASS
39Load the PDF file at /pdf/kvkk_basvuru.pdfThe file should load successfully and display its content.The file did not load. The server did not provide a response after 0.75 seconds, indicating the file may be unavailable or inaccessible.✗ FAIL
40Open Odeme pageThe Odeme page should load successfully with all content visible.HTTP 200, loaded in 2.92s, 11 headings, 72 links, 7 images.✓ PASS
41Open Hario V60 Dripper Seti pageThe Hario V60 Dripper Seti page should load successfully with all content visible.HTTP 200, loaded in 2.23s, 15 headings, 77 links, 11 images.✓ PASS
42Open Cezve pageThe Cezve page should load successfully with all content visible.HTTP 200, loaded in 2.27s, 15 headings, 77 links, 11 images.✓ PASS
43Open Hario Kettle Buono pageThe Hario Kettle Buono page should load successfully with all content visible.HTTP 200, loaded in 2.13s, 15 headings, 77 links, 13 images.✓ PASS
44Open Shopping pageThe Shopping page should load successfully with all content visible.HTTP 200, loaded in 2.46s, 73 headings, 266 links, 69 images.✓ PASS
45Open Filtre Kahve pageThe Filtre Kahve page should load successfully with all content visible.HTTP 200, loaded in 2.48s, 20 headings, 107 links, 16 images.✓ PASS
46Open Rare pageThe Rare page should load successfully with all content visible.HTTP 200, loaded in 2.51s, 21 headings, 84 links, 31 images.✓ PASS
47Open Espresso pageThe Espresso page should load successfully with all content visible.HTTP 200, loaded in 2.31s, 15 headings, 92 links, 11 images.✓ PASS
48Open Turk Kahvesi pageThe Turk Kahvesi page should load successfully with all content visible.HTTP 200, loaded in 2.21s, 12 headings, 83 links, 8 images.✓ PASS
49Open Ve Dahasi pageThe Ve Dahasi page should load successfully with all content visible.HTTP 200, loaded in 2.12s, 13 headings, 86 links, 9 images.✓ PASS
50Open Kenya Kirinyaga pageThe Kenya Kirinyaga page should load successfully with all content visible.HTTP 200, loaded in 2.18s, 15 headings, 76 links, 13 images.✓ PASS
TS-LINKS — Internal Link Health
#Test StepExpected ResultActual ResultStatus
1HEAD /"Anasayfa" · linked from 49 pagesThe "Anasayfa" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
2HEAD /alisveris"Online Dükkan" · linked from 49 pagesThe "Online Dükkan" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
3HEAD /alisveris/kategori/kahveler"Kahveler" · linked from 49 pagesThe "Kahveler" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
4HEAD /alisveris/kategori/ekipmanlar"Ekipmanlar" · linked from 49 pagesThe "Ekipmanlar" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
5HEAD /alisveris/kategori/aksesuar"Aksesuar" · linked from 48 pagesThe "Aksesuar" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
6HEAD /abonelikler"Abonelikler" · linked from 47 pagesThe "Abonelikler" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
7HEAD /alisveris/urun/kahve-aboneligi-otomatik-kahve-makinesi"Otomatik Makineler" · linked from 47 pagesThe "Otomatik Makineler" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
8HEAD /alisveris/urun/kahve-aboneligi-espresso"Espresso" · linked from 47 pagesThe "Espresso" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
9HEAD /alisveris/urun/kahve-aboneligi"Filtre" · linked from 47 pagesThe "Filtre" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
10HEAD /demleme-teknikleri"Demleme Teknikleri" · linked from 49 pagesThe "Demleme Teknikleri" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
11HEAD /demleme-teknik/filtre-kahve"Filtre Kahve" · linked from 49 pagesThe "Filtre Kahve" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
12HEAD /demleme-teknik/espresso"Espresso" · linked from 49 pagesThe "Espresso" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
13HEAD /demleme-teknik/french-press"French Press" · linked from 49 pagesThe "French Press" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
14HEAD /demleme-teknik/moka-pot"Moka Pot" · linked from 49 pagesThe "Moka Pot" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
15HEAD /demleme-teknik/hario-v60"Hario V60" · linked from 49 pagesThe "Hario V60" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
16HEAD /demleme-teknik/aeropress"Aeropress" · linked from 49 pagesThe "Aeropress" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
17HEAD /demleme-teknik/turk-kahvesi"Türk Kahvesi" · linked from 49 pagesThe "Türk Kahvesi" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
18HEAD /magazalar"Nerelerdeyiz" · linked from 49 pagesThe "Nerelerdeyiz" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
19HEAD /makaleler"Blog" · linked from 49 pagesThe "Blog" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
20HEAD /kahveni-bul"Kahveni Bul" · linked from 49 pagesThe "Kahveni Bul" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
21HEAD /kullanici/kaydol"Üye Ol" · linked from 49 pagesThe "Üye Ol" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
22HEAD /kullanici/oturumac"Giriş Yap" · linked from 49 pagesThe "Giriş Yap" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
23HEAD /?setLang=en"EN"The "EN" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
24HEAD /alisveris/kategori/kahve-abonelikleri"Abonelikler" · linked from 49 pagesThe "Abonelikler" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
25HEAD /iletisim"Toptan Satış" · linked from 49 pagesThe "Toptan Satış" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
26HEAD …/urun/example coffee shop-grounded-collection-oversized-white-t-shirt"Grounded Collection Oversized White T-Shirt" · linked from 5 pagesThe "Grounded Collection Oversized White T-Shirt" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
27HEAD /alisveris/urun/grounded-collection-oversized-green-hoodie"Grounded Collection Oversized Green Hoodie" · linked from 5 pagesThe "Grounded Collection Oversized Green Hoodie" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
28HEAD /alisveris/urun/etiyopya-korcha-natural-filtre"Etiyopya Korcha Natural (Filtre)" · linked from 6 pagesThe "Etiyopya Korcha Natural (Filtre)" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
29HEAD /alisveris/urun/latte-fincani-logolu"Example Coffee Shop Latte Fincanı" · linked from 7 pagesThe "Example Coffee Shop Latte Fincanı" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
30HEAD /alisveris/kategori/etkinlik-egitim"Etkinlikler" · linked from 49 pagesThe "Etkinlikler" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
31HEAD /hikayemiz"Hikayemiz" · linked from 49 pagesThe "Hikayemiz" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
32HEAD /iletisim?kariyer=1"Kariyer" · linked from 49 pagesThe "Kariyer" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
33HEAD /sss"S. S. S." · linked from 49 pagesThe "S. S. S." link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
34HEAD /menuler"Menü" · linked from 49 pagesThe "Menü" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
35HEAD /kahve-hakkinda"Kahvelerimiz Hakkında" · linked from 49 pagesThe "Kahvelerimiz Hakkında" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
36HEAD /kvkk"KVKK ve Gizlilik Politikası" · linked from 49 pagesThe "KVKK ve Gizlilik Politikası" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
37HEAD /aydinlatma"Aydınlatma Metni" · linked from 49 pagesThe "Aydınlatma Metni" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
38HEAD /cerez"Çerez Politikası" · linked from 49 pagesThe "Çerez Politikası" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
39Check if the PDF file at /pdf/kvkk_basvuru.pdf is reachableThe file should be accessible and return a success response or a valid redirect.The file is not reachable. No response was received from the server after 3.37 seconds.✗ FAIL
40HEAD /odeme"Satın Al" · linked from 49 pagesThe "Satın Al" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
41HEAD /alisveris/urun/Hario-v60-Dripper-seti"Sepete Ekle" · linked from 49 pagesThe "Sepete Ekle" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
42HEAD /alisveris/urun/cezve"Sepete Ekle" · linked from 49 pagesThe "Sepete Ekle" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
43HEAD /alisveris/urun/hario-kettle-buono"Sepete Ekle" · linked from 49 pagesThe "Sepete Ekle" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
44HEAD /shopping"EN" · linked from 3 pagesThe "EN" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
45HEAD /alisveris/kategori/filtre-kahve"Filtre Kahve" · linked from 8 pagesThe "Filtre Kahve" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
46HEAD /alisveris/kategori/rare"RARE" · linked from 8 pagesThe "RARE" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
47HEAD /alisveris/kategori/Espresso"Espresso" · linked from 8 pagesThe "Espresso" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
48HEAD /alisveris/kategori/turk-kahvesi"Türk Kahvesi" · linked from 8 pagesThe "Türk Kahvesi" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
49HEAD /alisveris/kategori/ve-dahasi"Ve Dahası" · linked from 8 pagesThe "Ve Dahası" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
50HEAD /alisveris/urun/kenya-kirinyaga"Kenya Kirinyaga Washed" · linked from 4 pagesThe "Kenya Kirinyaga Washed" link should resolve to a working page.Link resolves correctly (HTTP 200).✓ PASS
TS-SEC — Security Headers & Cookies
#Test StepExpected ResultActual ResultStatus
1Check Strict-Transport-Security security headersampled 2 pagesHeader present with max-age ≥ 31536000 (1 year)Present, max-age=31536000; includeSubDomains.✓ PASS
2Verify Content-Security-Policy security header is setThe server should send a Content-Security-Policy header to protect against malicious scripts.This security header is not set. The site is missing an important protection against code injection attacks.✗ FAIL
3Check X-Content-Type-Options security headersampled 2 pagesHeader value is exactly "nosniff"Present, nosniff.✓ PASS
4Check X-Frame-Options security headersampled 2 pagesDENY or SAMEORIGINPresent, SAMEORIGIN.✓ PASS
5Check Referrer-Policy security headersampled 2 pagesHeader present (any directive)Present, strict-origin-when-cross-origin.✓ PASS
6Check Permissions-Policy security headersampled 2 pagesHeader present (any directive set)Present, geolocation=self.✓ PASS
7Check that the XSRF-TOKEN cookie is protected with the HttpOnly flagThe cookie should be marked HttpOnly so it cannot be accessed by JavaScript, preventing theft via malicious scripts.The HttpOnly flag is not set on this cookie. A malicious script could potentially steal this token.✗ FAIL
8Cookie "XSRF-TOKEN" — Secure flagsampled from /Secure attribute setSecure attribute present✓ PASS
9Cookie "XSRF-TOKEN" — SameSite attributesampled from /SameSite=Strict / Lax / NoneSameSite=none✓ PASS
10Cookie "example coffee shop_session" — HttpOnly flagsampled from /HttpOnly attribute setHttpOnly attribute present✓ PASS
11Cookie "example coffee shop_session" — Secure flagsampled from /Secure attribute setSecure attribute present✓ PASS
12Cookie "example coffee shop_session" — SameSite attributesampled from /SameSite=Strict / Lax / NoneSameSite=none✓ PASS
13Mixed Content scan across crawled pagesscanned 50 pages of console messagesNo `http://` resources requested on HTTPS pagesNo Mixed Content messages observed during crawl✓ PASS
TS-A11Y — Accessibility Audit
#Test StepExpected ResultActual ResultStatus
1Verify every page declares a language attributeAll pages should include a lang attribute in the HTML tag so screen readers and browsers know the page language.1 out of 50 pages is missing this attribute, preventing assistive technology from reading the page correctly.✗ FAIL
2Verify each page has exactly one main heading (H1)Every page should declare one H1 element to identify its primary title for screen reader users.7 out of 50 pages have multiple H1 elements, which confuses screen readers about the page's main topic.✗ FAIL
3Verify heading hierarchy is properly structuredHeadings should descend in order (H1 → H2 → H3) without skipping levels, so screen reader users can navigate the page outline.1 out of 50 pages skips a heading level, creating gaps in the navigation structure that confuse assistive technology.■ UX
4Images declare an `alt` attributeinspected 800 images across 50 pagesEvery `<img>` declares meaningful alt text (`alt=""` only for purely decorative images)All images declare a non-empty `alt`✓ PASS
5Decorative images use intentional empty altinspected 800 images`alt=""` is reserved for purely decorative images (review each occurrence)No images declare empty `alt=""`✓ PASS
6Image resources return 2xxHEAD-checked 30 of 237 unique image srcsEvery `<img src>` resolves to a 2xx responseAll 30 probed images returned 2xx✓ PASS
7Verify all buttons have descriptive labelsEvery button should have visible text or an aria-label so users with screen readers know what it does.215 buttons across 49 pages lack an accessible name. Users relying on screen readers cannot understand these buttons' purpose.✗ FAIL
8Verify all links have descriptive labelsEvery link should have text, an aria-label, or an image with alt text so screen readers know where it goes.392 links across 49 pages have no accessible name. Screen reader users cannot understand the destination or purpose of these links.✗ FAIL
TS-XSS — Static XSS Surface
#Test StepExpected ResultActual ResultStatus
1Verify text inputs limit the amount of text that can be enteredEach text input should have a maxlength attribute to prevent excessively long payloads.All 117 text inputs across 49 pages lack a maxlength attribute, leaving the site vulnerable to oversized malicious input.■ UX
2Verify forms that modify data include CSRF protectionEvery form that changes data should carry a hidden CSRF token to prevent unauthorized requests from other sites.All 117 data-modifying forms lack a visible CSRF token. The site may rely on other defenses (like SameSite cookies) not detectable externally.✗ FAIL
3Verify forms do not use inline event handlersForms should avoid onclick, onload, and similar inline handlers; instead use addEventListener.392 inline event handlers are present across 49 pages, making the code harder to secure and harder to maintain.■ UX
4Verify links do not use javascript: URLsLink href attributes should use proper URLs, not javascript: code execution.49 links use javascript: URLs across 49 pages, increasing the risk of script execution vulnerabilities.✗ FAIL
TS-COOKIE — Cookies & Consent
#Test StepExpected ResultActual ResultStatus
1No unrecognized cookies set before consenthomepage Set-Cookie · HTTP 200Either no cookies on first load, or only strictly-necessary / functional ones2 cookies set (all match strict-necessary naming)✓ PASS
2Check for a cookie or privacy consent banner on the homepageThe homepage should display a consent banner or cookie notice so users can manage their privacy preferences.No consent banner was found in the homepage HTML, which may violate privacy regulations in some jurisdictions.■ UX
3Verify cookies are scoped to the site's own domainAll cookies set by the homepage should belong to the site's domain, not third parties.Both cookies set belong to a different domain, indicating third-party tracking or analytics cookies without a visible consent mechanism.■ UX
TS-PAGE — Pagination Structure
#Test StepExpected ResultActual ResultStatus
1Check for pagination on multi-page listingsIf any pages list multiple items, they should include next/previous links or numbered pagination.No pagination patterns were detected on any crawled page.⊘ BLOCKED
TS-AUTHZ — Authorization Boundary
#Test StepExpected ResultActual ResultStatus
1Verify the /admin path is not publicly accessibleAttempting to access /admin should return a login redirect or error, not admin content.The path returns a 301 redirect to https://example-coffee-shop.com/admin, indicating the site properly gates this path.■ UX
2Verify the /admin/ path is not publicly accessibleAttempting to access /admin/ should return a login redirect or error, not admin content.The path returns a 301 redirect to https://example-coffee-shop.com/admin/, indicating the site properly gates this path.■ UX
3Verify the /admin.php path is not publicly accessibleAttempting to access /admin.php should return a login redirect or error, not admin content.The path returns a 301 redirect to https://example-coffee-shop.com/admin.php, indicating the site properly gates this path.■ UX
4Verify the /administrator path is not publicly accessibleAttempting to access /administrator should return a login redirect or error, not admin content.The path returns a 301 redirect to https://example-coffee-shop.com/administrator, indicating the site properly gates this path.■ UX
5Verify the /dashboard path is not publicly accessibleAttempting to access /dashboard should return a login redirect or error, not admin content.The path returns a 301 redirect to https://example-coffee-shop.com/dashboard, indicating the site properly gates this path.■ UX
6Verify the /dashboard/ path is not publicly accessibleAttempting to access /dashboard/ should return a login redirect or error, not admin content.The path returns a 301 redirect to https://example-coffee-shop.com/dashboard/, indicating the site properly gates this path.■ UX
7Verify the /wp-admin path is not publicly accessibleAttempting to access /wp-admin should return a login redirect or error, not admin content.The path returns a 301 redirect to https://example-coffee-shop.com/wp-admin, indicating the site properly gates this path.■ UX
8Verify the /api/admin path is not publicly accessibleAttempting to access /api/admin should return a login redirect or error, not admin content.The path returns a 301 redirect to https://example-coffee-shop.com/api/admin, indicating the site properly gates this path.■ UX
9Verify the /api/users path is not publicly accessibleAttempting to access /api/users should return a login redirect or error, not admin content.The path returns a 301 redirect to https://example-coffee-shop.com/api/users, indicating the site properly gates this path.■ UX
TS-RATELIMIT — Rate Limit & Duplicate Submit
#Test StepExpected ResultActual ResultStatus
1Verify forms include idempotency tokens to prevent duplicate submissionsEach data-modifying form should carry a token the server can use to detect and block duplicate requests.None of the 117 data-modifying forms include an idempotency token, increasing the risk of accidental duplicate submissions.■ UX
2Check if the server applies rate limiting to rapid requestsWhen sending multiple rapid requests, the server should respond with a rate-limit error or header after some threshold.All 20 requests succeeded without any rate-limit signal, suggesting the server does not throttle rapid traffic.■ UX
3Check for rate-limit headers on the login endpointThe OPTIONS preflight response should include rate-limit or retry-after headers to hint at throttling.The server returned a 200 OK response with no rate-limit headers, suggesting no server-side rate limiting is configured.■ UX
TS-SEO — SEO & Discoverability
#Test StepExpected ResultActual ResultStatus
1Verify every page has a page titleAll pages should declare a non-empty <title> for search engines and browser tabs.1 out of 50 pages is missing a title, which hurts search engine indexing and user experience.✗ FAIL
2Verify page titles are between 10 and 60 charactersTitles should be concise enough to display fully in search results and browser tabs.37 out of 50 titles are too short (fewer than 10 characters), missing the opportunity to include keywords and context.■ UX
3Verify every page has a meta descriptionAll pages should include a meta description for search engines to display in results.32 out of 50 pages lack a meta description, reducing click-through rates from search results.✗ FAIL
4Verify meta descriptions are between 50 and 160 charactersDescriptions should be long enough to convey the page's purpose but short enough to display fully in search results.1 out of 18 meta descriptions is out of range.■ UX
5Verify every page declares a canonical URLAll pages should include a canonical link to help search engines identify the primary version.1 out of 50 pages is missing a canonical URL, which may confuse search engines about duplicate content.■ UX
6Verify every page has Open Graph og:title metadataPages should declare og:title for better appearance when shared on social media.24 out of 50 pages lack og:title, resulting in poor social media previews.■ UX
7Verify every page has Open Graph og:description metadataPages should declare og:description for better appearance when shared on social media.24 out of 50 pages lack og:description, resulting in poor social media previews.■ UX
8Verify every page has Open Graph og:image metadataPages should declare og:image for better appearance when shared on social media.24 out of 50 pages lack og:image, resulting in poor social media previews.■ UX
9Verify every page has a main heading (H1)All pages should declare at least one H1 element for proper document structure and SEO.1 out of 50 pages is missing an H1, which harms search engine understanding of the page's purpose.✗ FAIL
10robots.txt exists/robots.txtGET `/robots.txt` returns 2xxHTTP 200✓ PASS
11robots.txt references a Sitemapscanned response bodyrobots.txt body contains a `Sitemap:` directive`Sitemap:` directive present✓ PASS
12Check if a sitemap.xml file existsThe site should provide a sitemap at /sitemap.xml to help search engines discover all pages.A sitemap.xml file was not found (HTTP 404). Search engines may miss some pages during crawling.■ UX
13Verify the sitemap.xml file is validThe sitemap should be properly formatted XML with valid structure.This check was skipped because no sitemap.xml file is available.⊘ BLOCKED
TS-SSL — SSL / TLS & Server Headers
#Test StepExpected ResultActual ResultStatus
1HTTPS homepage reachablehttps://example-coffee-shop.comHEAD https:// returns 2xx or 3xxHTTP 200✓ PASS
2TLS certificate expiryCN=example-coffee-shop.comCertificate valid for at least 30 more days70 days remaining (valid_to Aug 17 07:40:57 2026 GMT)✓ PASS
3Verify the server redirects plain HTTP to HTTPSRequests to http:// should redirect to the secure https:// version.Plain HTTP requests receive a 301 redirect to https://example-coffee-shop.com/, properly enforcing encryption.✗ FAIL
4Verify server headers do not disclose software version informationResponse headers should omit version details to avoid exposing potential vulnerabilities.The X-Powered-By header reveals 'PHP/8.4.21, PleskLin', giving attackers information about the server software.■ UX
TS-REDIRECT — Redirect Configuration
#Test StepExpected ResultActual ResultStatus
1Verify the HTTP-to-HTTPS redirect chain is efficientPlain HTTP should redirect to HTTPS in 1–2 hops, landing on the matching URL.Plain HTTP redirects in 1 hop directly to https://example-coffee-shop.com/ and loads successfully.■ UX
2www / apex canonicalizationcompared www.example-coffee-shop.com ↔ example-coffee-shop.comBoth entrances land on the same canonical hostwww → example-coffee-shop.com, apex → example-coffee-shop.com.✓ PASS
TS-META — Meta Tags & PWA Essentials
#Test StepExpected ResultActual ResultStatus
1Faviconhomepage HTML scan`<link rel="icon">` declared in the page head.tag present in homepage HTML✓ PASS
2Apple touch iconhomepage HTML scan`<link rel="apple-touch-icon">` declared in the page head.tag present in homepage HTML✓ PASS
3Structured data (JSON-LD)homepage HTML scanAt least one `<script type="application/ld+json">` block declaring relevant schema.org types.tag present in homepage HTML✓ PASS
4Charset declarationhomepage HTML scan`<meta charset="utf-8">` declared at the top of `<head>`.tag present in homepage HTML✓ PASS
5Web app manifesthomepage declares <link rel="manifest">Either `<link rel="manifest">` referenced (and 2xx) OR `/manifest.json` / `/site.webmanifest` reachableHTTP 200 from /site.webmanifest✓ PASS
TS-IMG — Image Optimization
#Test StepExpected ResultActual ResultStatus
1Verify images use lazy loading for performanceAt least 25% of images on the homepage should include loading="lazy" to defer off-screen images.Only 3 out of 17 images (18%) use lazy loading, missing an opportunity to improve page speed.■ UX
2Verify images are not excessively largeEach image should transfer no more than 500 KB to keep load times reasonable.4 out of 20 probed images exceed 500 KB, slowing down the page for users on slower connections.■ UX
3Modern image formats (WebP / AVIF)Content-Type inspection across 20 HEAD responsesAt least some image responses use modern formats (image/webp or image/avif)7 legacy (jpg/png), 13 modern (webp/avif).✓ PASS
TS-CONSOLE — Console Errors
#Test StepExpected ResultActual ResultStatus
1Check for JavaScript errors in the browser consoleThe page should load without any JavaScript errors.26 JavaScript errors were logged across 5 different pages. These errors may break functionality or prevent features from working.■ UX
2Check for the console error: %c%d font-size:<n>;color:transparent NaNThe page should not emit this console error.This error was observed: %c%d font-size:0;color:transparent NaN. This suggests a JavaScript library or script is misbehaving.✗ FAIL
3Check for the console error: Failed to load resource with status 401The page should not emit this console error.This error was observed: 'Failed to load resource: the server responded with a status of 401 ()'. A resource is being requested without proper authentication.✗ FAIL
4Check for the console error: Bad element for Flickity carouselThe page should not emit this console error.This error was observed: 'Bad element for Flickity: .magaza-carousel'. The carousel library cannot find its target element, preventing it from functioning.■ UX
5Check for the console error: Bad element for Flickity with null valueThe page should not emit this console error.This error was observed: 'Bad element for Flickity: null'. The carousel library is receiving a null reference, indicating a scripting error.■ UX
TS-EXTLINKS — External Link Health
#Test StepExpected ResultActual ResultStatus
1Check external link https://www.instagram.com/example coffee shop/referenced from https://example-coffee-shop.com/External link is reachable.Link resolves correctly (HTTP 200).✓ PASS
2Check external link https://www.facebook.com/Example Coffee Shopreferenced from https://example-coffee-shop.com/External link is reachable.Link resolves correctly (HTTP 200).✓ PASS
3Check external link https://www.youtube.com/channel/UCCcZU6Jtcn5Fd5Ns4Bs-jmgreferenced from https://example-coffee-shop.com/External link is reachable.Link resolves correctly (HTTP 200).✓ PASS
4Check external link https://twitter.com/Example Coffee ShopCoffeereferenced from https://example-coffee-shop.com/External link is reachable.Link redirects (HTTP 301).✓ PASS
5Check if an external URL is reachable: https://etbis.eticaret.gov.tr/sitedogrulama/...The external link should respond with a success, redirect, or authentication error.The request failed after 3.37 seconds with a network error. The external site may be down, blocked, or unreachable.✗ FAIL
6Check external link https://maps.app.goo.gl/pdt5cwA1UhYPxAcA9"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
7Check external link https://goo.gl/maps/L43WnbVwQKpt2Atv8"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
8Check external link https://maps.app.goo.gl/acMLfhUUgSGunUkU6"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
9Check external link https://goo.gl/maps/RfCQBPD7ymxDpt5H9"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
10Check external link https://maps.app.goo.gl/kqNwPRnkWn5MiAWJ8"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
11Check external link https://goo.gl/maps/yoFXMSSMCnedN2Qv5"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
12Check external link https://goo.gl/maps/w8JurPsAmL8cvmwB8"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
13Check external link https://goo.gl/maps/ZKAE2fVeF1qgPX4D9"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
14Check external link https://maps.app.goo.gl/6o5fkoNQGnGhCms97"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
15Check external link https://goo.gl/maps/ReHT9JuVw9V9gYzX6"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
16Check external link https://maps.app.goo.gl/VhDZzxn7KZ4Ra8v79"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
17Check external link https://goo.gl/maps/YzpQ4YBdTTvHcJwk7"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
18Check external link https://maps.app.goo.gl/GD9vA6Fq799Cz9L97"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
19Check external link https://maps.app.goo.gl/tVRivvSJntirrkNY9"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
20Check external link https://maps.app.goo.gl/D3nsjdXydf2BvUYg8"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
21Check external link https://maps.app.goo.gl/wR9yC4R14aprZujDA"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
22Check external link https://goo.gl/maps/q4TgzkL7idmjxas9A"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
23Check external link https://maps.app.goo.gl/36HoSUuraDWpTCmF7"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
24Check external link https://maps.app.goo.gl/cQprdqUAKdSmhZdj7"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
25Check external link https://maps.app.goo.gl/WZPp32knn4vdrzb26"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
26Check external link https://goo.gl/maps/yAeVDP3LyockR5jn6"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
27Check external link https://goo.gl/maps/wLAUevfzdTk3WbBf7"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
28Check external link https://maps.app.goo.gl/DYQmcD5ngHF2uFJK7"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
29Check external link https://maps.app.goo.gl/hphAb25tjJkWead16"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
30Check external link https://maps.app.goo.gl/UD6xJURvjVLb1rtm7"Haritada Gör"External link is reachable.Link redirects (HTTP 302).✓ PASS
31Check remaining external links for reachabilityn/a (probe has a limit on external links checked)16 additional external URLs were not probed due to capacity limits.■ UX
TS-OPENREDIR — Open Redirect Surface
#Test StepExpected ResultActual ResultStatus
1Test if the ?redirect parameter can be used for open redirectsThe server should ignore or strip external redirect targets to prevent hijacking users.The server returns a 301 redirect with the parameter intact, though it remains on the same domain. This is safer than a true open redirect.■ UX
2Test if the ?next parameter can be used for open redirectsThe server should ignore or strip external redirect targets to prevent hijacking users.The server returns a 301 redirect with the parameter intact, though it remains on the same domain. This is safer than a true open redirect.■ UX
3Test if the ?url parameter can be used for open redirectsThe server should ignore or strip external redirect targets to prevent hijacking users.The server returns a 301 redirect with the parameter intact, though it remains on the same domain. This is safer than a true open redirect.■ UX
4Test if the ?return parameter can be used for open redirectsThe server should ignore or strip external redirect targets to prevent hijacking users.The server returns a 301 redirect with the parameter intact, though it remains on the same domain. This is safer than a true open redirect.■ UX
5Test if the ?returnUrl parameter can be used for open redirectsThe server should ignore or strip external redirect targets to prevent hijacking users.The server returns a 301 redirect with the parameter intact, though it remains on the same domain. This is safer than a true open redirect.■ UX
TS-AUTH — Authentication Form Structure
#Test StepExpected ResultActual ResultStatus
1Login form discoveredpage: https://example-coffee-shop.com/kullanici/kaydolAuthentication form found via password input / login pathform @ https://example-coffee-shop.com/kullanici/kaydol (method POST)✓ PASS
2Form action uses HTTPShttps://example-coffee-shop.com/kullanici/kaydolLogin form posts to an https:// URLhttps:// action confirmed✓ PASS
3Form method is POST (not GET)GET would leak credentials via URL IF the submit isn't JS-intercepted to a real POSTForm method=POSTmethod=POST confirmed✓ PASS
4Verify the password field includes autocomplete guidancePassword inputs should declare autocomplete="current-password" to enable browser password managers.The password field lacks an autocomplete attribute, preventing password managers from working correctly.■ UX
5Verify the username field includes autocomplete guidanceUsername inputs should declare autocomplete="username" to enable browser password managers.The username field lacks an autocomplete attribute, preventing password managers from working correctly.■ UX
6Verify a password-reset link is visible on the login pageUsers should be able to find a 'Forgot password' or similar link if they cannot sign in.No password-reset link was found on the login page, making it difficult for users who forget their credentials.■ UX
7Verify the password field limits input lengthPassword inputs should declare a maxlength attribute (typically 64 or more) to prevent excessively long inputs.The password field lacks a maxlength attribute, leaving it vulnerable to very long or malicious payloads.■ UX
8Verify the login form includes CSRF protectionThe form should carry a hidden CSRF token, or the server may use other defenses (like SameSite cookies).No visible CSRF token field was found in the login form. The site may rely on other defenses not externally observable.✗ FAIL
9Empty email + empty passwordsubmitted to https://example-coffee-shop.com/kullanici/kaydolForm rejects the submission (URL unchanged OR password field still visible OR visible error)URL unchanged, password input still visible.✓ PASS
10Valid-format email + empty passwordsubmitted to https://example-coffee-shop.com/kullanici/kaydolForm rejects the submission (URL unchanged OR password field still visible OR visible error)URL unchanged, password input still visible.✓ PASS
11Empty email + filled passwordsubmitted to https://example-coffee-shop.com/kullanici/kaydolForm rejects the submission (URL unchanged OR password field still visible OR visible error)URL unchanged, password input still visible.✓ PASS
12Email without `@`submitted to https://example-coffee-shop.com/kullanici/kaydolForm rejects the submission (URL unchanged OR password field still visible OR visible error)URL unchanged, password input still visible.✓ PASS
131-character passwordsubmitted to https://example-coffee-shop.com/kullanici/kaydolForm rejects the submission (URL unchanged OR password field still visible OR visible error)URL unchanged, password input still visible.✓ PASS
14200-character password (graceful handling)submitted to https://example-coffee-shop.com/kullanici/kaydolForm rejects the submission (URL unchanged OR password field still visible OR visible error)URL unchanged, password input still visible.✓ PASS
15SQL-injection payload in emailsubmitted to https://example-coffee-shop.com/kullanici/kaydolForm rejects the submission (URL unchanged OR password field still visible OR visible error)URL unchanged, password input still visible.✓ PASS
16XSS payload in emailsubmitted to https://example-coffee-shop.com/kullanici/kaydolForm rejects the submission (URL unchanged OR password field still visible OR visible error)URL unchanged, password input still visible.✓ PASS
17Wrong email + wrong passwordsubmitted to https://example-coffee-shop.com/kullanici/kaydolForm rejects the submission (URL unchanged OR password field still visible OR visible error)URL unchanged, password input still visible.✓ PASS
18Check for user-enumeration vulnerabilities in login error messagesThis test requires a real test account email for comparison.This test was skipped because no test account email was provided.⊘ BLOCKED
19Verify the password field includes a visibility toggleUsers should be able to toggle between masked and visible password text for better usability.No password visibility toggle button was found, forcing users to type blindly.■ UX
20Verify a 'remember me' checkbox is availableUsers should be offered a 'remember me' or 'stay signed in' option for convenience.No remember-me checkbox was found on the login page.■ UX
21Check if the password-reset link is reachableThe password-reset link should point to a valid page.No password-reset link was discovered on the page, so this check could not be completed.⊘ BLOCKED
22Register form requires email + password + confirm-passwordpage: https://example-coffee-shop.com/kullanici/kaydolForm contains an email input, a password input, and a second password (confirm) inputall three required fields present✓ PASS
23Verify a password strength indicator is displayed near the password inputUsers should see feedback about password strength (weak, medium, strong) or a list of requirements.No password strength meter or requirement list was found, leaving users uncertain about acceptable passwords.■ UX
24Verify the registration form requires acceptance of terms and privacyA checkbox should require users to explicitly agree to the site's terms and privacy policy.No terms or privacy checkbox was found on the registration form, which may violate data protection regulations.■ UX
TS-API — API Responses
#Test StepExpected ResultActual ResultStatus
1API responses return 2xx/3xx4 XHR/fetch responses on https://example-coffee-shop.com/All API responses return 2xx / 3xxAll 4 responses 2xx/3xx✓ PASS
2API responses under 2s4 XHR/fetch responsesEvery API response completes in ≤ 2000 msAll responses under threshold✓ PASS
3Verify API responses declare a Content-Type headerAll API responses should include a Content-Type header so clients know how to parse the data.3 API responses lack a Content-Type header, which may confuse API clients about the response format.■ UX
4API response bodies do not expose stack traces4 XHR/fetch responsesResponse bodies never contain server stack traces / debug error detailsNo stack traces detected in response bodies✓ PASS
TS-ERR — Error Page & 404 Handling
#Test StepExpected ResultActual ResultStatus
1GET /xyzshort nonsense pathHTTP 4xx response · branded error page consistent with site chromeHTTP 404, branded, 0.65 s.✓ PASS
2GET /__qa_explorer_404_probe_*opaque randomized pathHTTP 4xx response · branded error page consistent with site chromeHTTP 404, branded, 0.50 s.✓ PASS
3Load the search page with an invalid query parameterThe page should return a 4xx error with branded site styling consistent with the rest of the site.The page returned HTTP 403 with generic error styling, not matching the site's design. This confuses users about whether it is a site error or a real access denial.✗ FAIL
4Request a very long URL path to test error handlingThe page should return a 4xx error with branded site styling consistent with the rest of the site.The page returned HTTP 403 with generic error styling, not matching the site's design. This confuses users about whether it is a site error or a real access denial.✗ FAIL
5GET /test'<sql-payload>SQL-injection-style pathHTTP 4xx response · branded error page consistent with site chromeHTTP 404, branded, 0.29 s.✓ PASS
TS-FORM — Form Validation Tests
#Test StepExpected ResultActual ResultStatus
1Form #1: POST https://example-coffee-shop.com/ebultenempty submit testSubmission blocked or error message shown1 input(s) flagged as invalid, browser message: "Please fill out this field.".✓ PASS
2Form #1: POST https://example-coffee-shop.com/ebulteninvalid email format testBrowser rejected the invalid email format (HTML5 :invalid or visible error)1 input(s) flagged as invalid, browser message: "Please include an '@' in the email address. 'not-an-email' is missing an '@'.".✓ PASS
3Submit an empty form at POST https://example-coffee-shop.com/alisveris/araThe form should validate and show an error message, or prevent submission if required fields are empty.The empty form submitted without triggering client-side validation or showing any error, allowing invalid data to be sent.■ UX
4Form #3: POST https://example-coffee-shop.com/sepet/ekleempty submit testSubmission blocked or error message shown4 input(s) flagged as invalid, browser message: "Please select an item in the list.".✓ PASS
5Form #4: POST https://example-coffee-shop.com/kullanici/kaydolempty submit testSubmission blocked or error message shown6 input(s) flagged as invalid, browser message: "Please fill out this field.".✓ PASS
6Form #4: POST https://example-coffee-shop.com/kullanici/kaydolinvalid email format testBrowser rejected the invalid email format (HTML5 :invalid or visible error)6 input(s) flagged as invalid, browser message: "Please fill out this field.".✓ PASS
7Form #5: POST https://example-coffee-shop.com/kullanici/oturumacempty submit testSubmission blocked or error message shown2 input(s) flagged as invalid, browser message: "Please fill out this field.".✓ PASS
8Form #5: POST https://example-coffee-shop.com/kullanici/oturumacinvalid email format testBrowser rejected the invalid email format (HTML5 :invalid or visible error)2 input(s) flagged as invalid, browser message: "Please include an '@' in the email address. 'not-an-email' is missing an '@'.".✓ PASS
9Form #6: POST https://example-coffee-shop.com/iletisimempty submit testSubmission blocked or error message shown5 input(s) flagged as invalid, browser message: "Please fill out this field.".✓ PASS
10Form #6: POST https://example-coffee-shop.com/iletisiminvalid email format testBrowser rejected the invalid email format (HTML5 :invalid or visible error)5 input(s) flagged as invalid, browser message: "Please fill out this field.".✓ PASS
TS-CTA — Primary CTA Tests
#Test StepExpected ResultActual ResultStatus
1Click button "Sign Up"click navigates to destinationCTA produces a navigation, modal, or DOM updateNavigated to https://example-coffee-shop.com/kullanici/kaydol (HTTP 200)✓ PASS
2Click button "Login"click navigates to destinationCTA produces a navigation, modal, or DOM updateNavigated to https://example-coffee-shop.com/kullanici/oturumac (HTTP 200)✓ PASS
3Click button "Subscribe"click updates page content in placeCTA produces a navigation, modal, or DOM updateDocument text length changed by 254 chars (SPA / in-place update)✓ PASS
4Click link "Sign Up" → /kullanici/kaydolclick navigates to destinationCTA produces a navigation, modal, or DOM updateNavigated to https://example-coffee-shop.com/kullanici/kaydol (HTTP 200)✓ PASS
5Click link "Login" → /kullanici/oturumacclick navigates to destinationCTA produces a navigation, modal, or DOM updateNavigated to https://example-coffee-shop.com/kullanici/oturumac (HTTP 200)✓ PASS
6Click link "Add to Cart" → /alisverisclick navigates to destinationCTA produces a navigation, modal, or DOM updateNavigated to https://example-coffee-shop.com/alisveris (HTTP 200)✓ PASS
7Click link "Contact Us" → /iletisimclick navigates to destinationCTA produces a navigation, modal, or DOM updateNavigated to https://example-coffee-shop.com/iletisim (HTTP 200)✓ PASS
8Attempt to click the 'Buy' link pointing to /odemeClicking should navigate to the target page or trigger an action.This link was not clicked because the text 'Buy' matches a destructive action blocklist, preventing accidental activation during automated testing.⊘ BLOCKED
9Click link "Add to Cart" → …s/urun/Hario-v60-Dripper-seticlick navigates to destinationCTA produces a navigation, modal, or DOM updateNavigated to https://example-coffee-shop.com/alisveris (HTTP 200)✓ PASS
10Click link "Add to Cart" → /alisveris/urun/cezveclick navigates to destinationCTA produces a navigation, modal, or DOM updateNavigated to https://example-coffee-shop.com/alisveris (HTTP 200)✓ PASS
TS-SEARCH — Search Behavior
#Test StepExpected ResultActual ResultStatus
1Discover and exercise the site search functionalityAt least one search form should be available on the site to test search behavior.No search form was found on any crawled page, so search functionality could not be tested.⊘ BLOCKED
TS-ERROR — Error & Resilience Handling
#Test StepExpected ResultActual ResultStatus
1Check if a service worker is registeredOptional — a service worker enables offline caching and improves resilience.No service worker is registered. Offline functionality and caching are not available.■ UX
2Test the page's behavior when the network is offlineA gracefully designed site should show a cached or branded offline page, not a generic browser error.The page failed to load offline with a network error (net::ERR_INTERNET_DISCONNECTED). No offline experience is provided.✗ FAIL
3Check if a loading indicator appears during slow navigationUsers should see visual feedback (spinner, progress bar) while content is loading.No loading indicator was detected during navigation, leaving users unsure if the page is responding.■ UX
TS-PERF — Performance & Core Web Vitals
#Test StepExpected ResultActual ResultStatus
1FCP · /≤1.8s good · ≤3.0s needs improvement1.52s✓ PASS
2LCP · /≤2.5s good · ≤4.0s needs improvement1.52s✓ PASS
3CLS · /≤0.1 good · ≤0.25 needs improvement0.011✓ PASS
4DOM · /≤1500 elements good · ≤3000 needs improvement470 elements✓ PASS
5Measure the total page weight of the homepageThe homepage should load in 3 MB or less (good), or at most 5 MB (needs improvement).The homepage is 4.81 MB, which needs improvement. Optimize images, minify code, or defer non-critical resources.■ UX
6FCP · /demleme-teknik/french-press≤1.8s good · ≤3.0s needs improvement1.58s✓ PASS
7LCP · /demleme-teknik/french-press≤2.5s good · ≤4.0s needs improvement1.58s✓ PASS
8CLS · /demleme-teknik/french-press≤0.1 good · ≤0.25 needs improvement0.017✓ PASS
9DOM · /demleme-teknik/french-press≤1500 elements good · ≤3000 needs improvement389 elements✓ PASS
10Weight · /demleme-teknik/french-press31 resources≤3 MB good · ≤5 MB needs improvement0.72 MB✓ PASS
11FCP · /iletisim≤1.8s good · ≤3.0s needs improvement1.45s✓ PASS
12LCP · /iletisim≤2.5s good · ≤4.0s needs improvement1.87s✓ PASS
13CLS · /iletisim≤0.1 good · ≤0.25 needs improvement0.028✓ PASS
14DOM · /iletisim≤1500 elements good · ≤3000 needs improvement360 elements✓ PASS
15Weight · /iletisim32 resources≤3 MB good · ≤5 MB needs improvement0.75 MB✓ PASS
16FCP · /aydinlatma≤1.8s good · ≤3.0s needs improvement1.50s✓ PASS
17LCP · /aydinlatma≤2.5s good · ≤4.0s needs improvement1.75s✓ PASS
18CLS · /aydinlatma≤0.1 good · ≤0.25 needs improvement0.041✓ PASS
19DOM · /aydinlatma≤1500 elements good · ≤3000 needs improvement445 elements✓ PASS
20Weight · /aydinlatma30 resources≤3 MB good · ≤5 MB needs improvement0.72 MB✓ PASS
21FCP · /alisveris/urun/kenya-kirinyaga≤1.8s good · ≤3.0s needs improvement1.40s✓ PASS
22LCP · /alisveris/urun/kenya-kirinyaga≤2.5s good · ≤4.0s needs improvement1.95s✓ PASS
23CLS · /alisveris/urun/kenya-kirinyaga≤0.1 good · ≤0.25 needs improvement0.024✓ PASS
24DOM · /alisveris/urun/kenya-kirinyaga≤1500 elements good · ≤3000 needs improvement486 elements✓ PASS
25Measure the total page weight of the product detail pageProduct pages should load in 3 MB or less (good), or at most 5 MB (needs improvement).The product page is 3.40 MB, which is acceptable but could be further optimized.■ UX
TS-RESPONSIVE — Responsive Layout Checks
#Test StepExpected ResultActual ResultStatus
1Check the homepage layout on a mobile phone (375×812 pixels)The page should not overflow horizontally, text should not be clipped, and buttons should be at least 44 pixels for easy tapping.The page fits without overflow, but 1 element is clipped, and 31 out of 45 touch targets are too small (<44 pixels), making them hard to tap on mobile.■ UX
2Check the homepage layout on a tablet (768×1024 pixels)The page should not overflow horizontally and text should not be clipped.The page fits without overflow, but 1 element is clipped. Text and layout are otherwise acceptable for tablet viewing.■ UX
3/ · Desktop (1440×900)checks: overflow · clippingNo horizontal overflow · no clipped textno horizontal overflow · 1 clipped element■ UX
4/iletisim · Mobile (375×812)checks: overflow · clipping · touch targetsNo horizontal overflow · no clipped text · touch targets ≥44pxno horizontal overflow · 33 of 40 touch targets <44px■ UX
5/iletisim · Tablet (768×1024)checks: overflow · clippingThe Iletisim page should render correctly at tablet width with no horizontal overflow or clipped text.no horizontal overflow✓ PASS
6/iletisim · Desktop (1440×900)checks: overflow · clippingThe Iletisim page should render correctly at desktop width with no horizontal overflow or clipped text.no horizontal overflow✓ PASS
7/alisveris/urun/kenya-kirinyaga · Mobile (375×812)checks: overflow · clipping · touch targetsNo horizontal overflow · no clipped text · touch targets ≥44pxno horizontal overflow · 36 of 44 touch targets <44px■ UX
8/alisveris/urun/kenya-kirinyaga · Tablet (768×1024)checks: overflow · clippingThe Kenya Kirinyaga page should render correctly at tablet width with no horizontal overflow or clipped text.no horizontal overflow✓ PASS
9/alisveris/urun/kenya-kirinyaga · Desktop (1440×900)checks: overflow · clippingThe Kenya Kirinyaga page should render correctly at desktop width with no horizontal overflow or clipped text.no horizontal overflow✓ PASS
10Viewport meta tagcaptured once on the first sample page`<meta name="viewport" content="width=device-width, ...">`Present, width=device-width, initial-scale=1.0.✓ PASS
TS-STATE — State & Navigation
#Test StepExpected ResultActual ResultStatus
1Deep-link navigation to inner pagehttps://example-coffee-shop.com/alisverisDirect GET on the inner URL renders contentLoaded, HTTP 200, body length 6786.✓ PASS
2Browser back returns to a working previous pagehttps://example-coffee-shop.com/ → https://example-coffee-shop.com/alisveris → backGoing back re-renders the previous page (no blank / error screen)Back, HTTP 200, body length 1716.✓ PASS
3Page reload renders cleanlyhttps://example-coffee-shop.com/alisverisReload renders the page without errorsReloaded, HTTP 200, body length 6786.✓ PASS
4Inner pages have unique meaningful URLsinspected first 5 inner pagesEach inner page has its own path-based URL (not just a `#` fragment on the homepage)All 5 URLs unique✓ PASS
TS-CONTRAST — Color Contrast (WCAG 2.1)
#Test StepExpected ResultActual ResultStatus
1Color contrast · /sampled 31 text elementsEvery sampled text element meets WCAG 2.1 contrast (≥ 4.5 normal · ≥ 3 large)2 of 31 sampled elements fall below threshold✗ FAIL
2Color contrast · /iletisimsampled 23 text elementsEvery sampled text element meets WCAG 2.1 contrast (≥ 4.5 normal · ≥ 3 large)1 of 23 sampled elements fall below threshold✗ FAIL
3Color contrast · /alisveris/urun/kenya-kirinyagasampled 30 text elementsEvery sampled text element meets WCAG 2.1 contrast (≥ 4.5 normal · ≥ 3 large)1 of 30 sampled elements fall below threshold✗ FAIL
4Bug Summary Matrix
A consolidated dashboard view of every unique finding from this scan. Detailed entries follow in the next section.
IDTitleSeverityPriorityStatus
BUG-001Color contrast failures (site-wide)HighP1• New
BUG-002Form input missing accessible labelHighP1• New
BUG-003Pervasive missing accessible names on interactive elements site-wideHighP1• New
BUG-004Internal link unreachableHighP1• New
BUG-005Legal compliance failure: no cookie consent and broken KVKK documentHighP1• New
BUG-006Cookie missing HttpOnly flagHighP1• New
BUG-007HTTP requests are not redirected to HTTPSHighP1• New
BUG-008javascript: href links and inline handlers create XSS attack surfaceHighP1• New
BUG-009Form fields relyMediumP2• New
BUG-010Missing language attribute on HTML elementMediumP2• New
BUG-011Multiple form inputs missing accessible labelsMediumP2• New
BUG-012Multiple h1 elements and skipped heading levels weaken document structureMediumP2• New
BUG-013Multiple primary headings on pageMediumP2• New
BUG-014Unlabeled buttonsMediumP2• New
BUG-015Unlabeled linksMediumP2• New
BUG-016API responses missing Content-Type headerMediumP2• New
BUG-017External link unreachableMediumP2• New
BUG-018Failed resource loading errors in consoleMediumP2• New
BUG-019Form accepts empty submissionMediumP2• New
BUG-020JavaScript console errors detectedMediumP2• New
BUG-021No offline or cached stateMediumP2• New
BUG-022Heavy page weight and low lazy-load adoption degrade mobile performanceMediumP2• New
BUG-023JavaScript URLs in linksMediumP2• New
BUG-024Missing Content-Security-Policy headerMediumP2• New
BUG-025No cookie consent banner detectedMediumP2• New
BUG-026Server software details publicly visibleMediumP2• New
BUG-027Text inputs without character limitsMediumP2• New
BUG-028Third-party cookies set on page loadMediumP2• New
BUG-029Missing page titleMediumP2• New
BUG-030Missing SEO metadataMediumP2• New
BUG-031Unbranded 403 responses replace expected 404 handling for unknown URLsMediumP2• New
BUG-032Inconsistent heading structureLowP3• New
BUG-033Carousel library error in consoleLowP3• New
BUG-034Carousel library null reference errorLowP3• New
BUG-035No offline support (service worker not registered)LowP3• New
BUG-036Heavy page weight (4.81 MB)LowP3• New
BUG-037Images not using native lazy-loadingLowP3• New
BUG-038Oversized image (532 KB)LowP3• New
BUG-039Forms lack duplicate-submission preventionLowP3• New
BUG-040Forms may lack cross-site forgery protectionLowP3• New
BUG-041Inline event handlers in HTMLLowP3• New
BUG-042Login endpoint shows no rate-limit protection signalLowP3• New
BUG-043No 'remember me' option on loginLowP3• New
BUG-044No password reset link on login pageLowP3• New
BUG-045No password visibility toggleLowP3• New
BUG-046No rate-limiting visible on homepageLowP3• New
BUG-047Password field missing autocomplete attributeLowP3• New
BUG-048Password field missing maxlength attributeLowP3• New
BUG-049Potential CSRF gap on state-changing forms (unverified)LowP3• New
BUG-050Username field missing autocomplete attributeLowP3• New
BUG-051Content clipped at desktop viewport (1440px)LowP3• New
BUG-052Content clipped at mobile viewport (375px)LowP3• New
BUG-053Content clipped at tablet viewport (768px)LowP3• New
BUG-054Missing main headingLowP3• New
BUG-055Page titles too short for search resultsLowP3• New
BUG-056Registration form lacks password strength indicatorLowP3• New
BUG-057Registration form missing terms acceptance checkboxLowP3• New
BUG-058Sitemap not foundLowP3• New
BUG-059Undersized touch targets on mobileLowP3• New
5Detailed Bug Reports
Each finding's BUG-NNN identifier matches its row in the Bug Summary Matrix.
BUG-001 Color contrast failures (site-wide)
High P1 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in DevTools → Inspect
  2. Locate the element matching `label.transition-all.peer-placeholder-shown:text-base`
  3. In the Styles pane, hover the computed `color` value — DevTools renders the live contrast ratio
  4. Adjust either color (typically darkening the foreground) until the ratio clears the threshold
Text should have a contrast ratio of at least 4.5:1.
Text "E-Bülten" (selector label.transition-all.peer-placeholder-shown:text-base) on https://example-coffee-shop.com/ has contrast 1.90:1 (RGB 156,163,175 on RGB 227,222,215).
BUG-002 Form input missing accessible label
High P1 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in a browser
  2. Open DevTools → Accessibility tree
  3. Inspect each interactive input — its accessible name should be the field's purpose, not 'edit text'
Every form input should have an associated label.
1 input on the search form (action="https://example-coffee-shop.com/alisveris/ara", method=POST) has no associated label.
BUG-003 Pervasive missing accessible names on interactive elements site-wide
High P1 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Navigate to https://example-coffee-shop.com/ with a screen reader (e.g. NVDA + Chrome).
  2. Tab through interactive elements — most buttons and icon links are announced as 'button' or 'link' with no descriptive label.
  3. Run an automated accessibility checker (axe, Lighthouse) — it will flag all unlabelled controls and contrast failures simultaneously.
All interactive elements should carry descriptive accessible names (visible text or aria-label), colour contrast should meet WCAG 2.1 AA (4.5:1 for normal text), and every HTML document should declare a valid lang attribute.
TS-A11Y: 215 buttons without accessible names, 392 links without accessible names across 49 pages. TS-CONTRAST: contrast failures on /, /iletisim, and /alisveris/urun/kenya-kirinyaga. TS-A11Y: 1 page missing lang attribute.
BUG-004 Internal link unreachable
High P1 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in a browser
  2. Click the link to https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf
  3. Observe no response
All internal links should respond successfully (HTTP 200 or redirect to a working page).
https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf → no response. First referenced from https://example-coffee-shop.com/. Also linked from https://example-coffee-shop.com/alisveris, https://example-coffee-shop.com/alisveris/kategori/kahveler, https://example-coffee-shop.com/alisveris/kategori/ekipmanlar (and 45 more).
BUG-005 Legal compliance failure: no cookie consent and broken KVKK document
High P1 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Load https://example-coffee-shop.com/ in a clean browser profile with no prior cookies.
  2. Observe that no cookie consent banner appears but third-party cookies are already set (visible in DevTools > Application > Cookies).
  3. Click the KVKK başvuru link anywhere on the site — browser shows a network error / blank page.
  4. Confirm via curl: curl -I https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf returns no response.
A cookie consent mechanism must gate third-party cookie setting until explicit user consent. The KVKK başvuru PDF must be reachable at its published URL.
TS-COOKIE: no consent banner found in homepage HTML; 2 of 2 cookies are third-party domain. TS-NAV + TS-LINKS: /pdf/kvkk_basvuru.pdf returns no HTTP response.
BUG-006 Cookie missing HttpOnly flag
High P1 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. curl -I 'https://example-coffee-shop.com/'
  2. Locate the 'Set-Cookie' response header for the cookie named "XSRF-TOKEN"
  3. Confirm the HttpOnly flag is absent
Set-Cookie should include the HttpOnly flag (for example: Set-Cookie: session=...; HttpOnly; Secure; SameSite=Lax).
Cookie "XSRF-TOKEN" observed on https://example-coffee-shop.com/ is missing the HttpOnly flag.
BUG-007 HTTP requests are not redirected to HTTPS
High P1 • New
http://example-coffee-shop.com (Desktop + Mobile)
  1. curl -sI 'http://example-coffee-shop.com/' | head -20
  2. Confirm the first response is a 3xx redirect whose Location starts with https://
  3. Update the web server / CDN to force-redirect HTTP traffic to HTTPS
HTTP requests should redirect to HTTPS using a 301, 302, 307, or 308 response.
HTTP 301 redirect to https://example-coffee-shop.com/ is working correctly.
BUG-008 javascript: href links and inline handlers create XSS attack surface
High P1 • New
https://example-coffee-shop.com/ (Desktop)
  1. Open any page, e.g. https://example-coffee-shop.com/ and inspect anchor tags in DevTools.
  2. Search for href="javascript: — 49 instances exist.
  3. Search for onclick= — hundreds of inline handlers visible in source.
  4. Check response headers — no Content-Security-Policy header present to restrict script sources.
No javascript: href links; event handlers should be bound via addEventListener in external scripts. A CSP header should restrict script execution to trusted sources.
TS-XSS: 49 javascript: links and 392 inline handlers across 49 pages. TS-SEC: CSP header not set. The two findings are mutually reinforcing — removing CSP-unsafe-inline would break the inline handlers, revealing that neither can be fixed independently.
BUG-009 Form fields rely
Medium P2 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Focus into a form field on https://example-coffee-shop.com/
  2. Observe that the previously-visible hint disappears
  3. Inspect the DOM and confirm the element is a placeholder attribute, not a `<label>`
Each form input should have a persistent <label>, with placeholder as an optional supplement.
1 input on the search form (action="https://example-coffee-shop.com/alisveris/ara", method=POST) relies solely on placeholder text.
BUG-010 Missing language attribute on HTML element
Medium P2 • New
https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf in DevTools → Elements tab
  2. Inspect the `<html>` element
  3. Confirm no `lang` attribute is present
  4. Add `lang="<bcp47-code>"` to the `<html>` element in the template
The <html> element should include a lang attribute (for example: <html lang="en"> or <html lang="tr">).
Language attribute missing or empty on 1 of 50 crawled pages.
BUG-011 Multiple form inputs missing accessible labels
Medium P2 • New
https://example-coffee-shop.com/iletisim (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/iletisim in a browser
  2. Open DevTools → Accessibility tree
  3. Inspect each interactive input — its accessible name should be the field's purpose, not 'edit text'
Every form input should have an associated label.
2 of 5 inputs on the contact form (action="https://example-coffee-shop.com/iletisim", method=POST) have no associated label.
BUG-012 Multiple h1 elements and skipped heading levels weaken document structure
Medium P2 • New
https://example-coffee-shop.com/ (Desktop)
  1. Open https://example-coffee-shop.com/ and run document.querySelectorAll('h1') in the console — multiple results returned.
  2. Use a browser accessibility tree inspector to review heading outline — multiple top-level headings with no clear primary topic heading.
Each page should have exactly one <h1> that represents the primary page topic, with subsequent content using h2–h6 in logical, non-skipping order.
TS-A11Y reports 7 pages with multiple <h1> elements and 1 page with a skipped heading level. DOM summary for / shows 23 heading elements, indicating heavily fragmented heading use.
BUG-013 Multiple primary headings on page
Medium P2 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in DevTools → Elements tab
  2. Search the DOM for `h1` elements
  3. Confirm 4 <h1> elements are present
  4. Promote one as the page title; demote the rest to <h2>
Each page should have exactly one <h1> element.
7 of 50 crawled pages contain multiple <h1> elements (for example, 4 on https://example-coffee-shop.com/).
BUG-014 Unlabeled buttons
Medium P2 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in DevTools → Elements tab
  2. Run `[...document.querySelectorAll('button')].filter(b => !b.innerText.trim() && !b.getAttribute('aria-label'))` in Console
  3. Add an `aria-label` describing the action to each match
Each button should have a name, either through visible text or an aria-label attribute.
215 of 850 buttons across 49 pages have neither text nor aria-label.
BUG-015 Unlabeled links
Medium P2 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in DevTools → Elements tab
  2. Run `[...document.querySelectorAll('a[href]')].filter(a => !a.innerText.trim() && !a.getAttribute('aria-label') && !a.querySelector('img[alt]'))` in Console
  3. Add visible text, `aria-label`, or an inner `<img alt>` to each match
Each link should expose a name through visible text, aria-label, or an image alt attribute.
392 of 4,319 links across 49 pages lack an accessible name.
BUG-016 API responses missing Content-Type header
Medium P2 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in DevTools → Network
  2. Inspect response headers for the listed endpoints
  3. Confirm `Content-Type` is missing and add it server-side
Every API response should include a Content-Type header.
3 of 4 network requests on https://example-coffee-shop.com/ omit Content-Type header.
BUG-017 External link unreachable
Medium P2 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in a browser
  2. Click the link to https://etbis.eticaret.gov.tr/sitedogrulama/1d8c05a8868b47f1a71d3cb6b7e27d79
  3. Observe TypeError: fetch failed
  4. Update the link target or remove the reference
All outbound links should be reachable and return a successful response.
https://etbis.eticaret.gov.tr/sitedogrulama/1d8c05a8868b47f1a71d3cb6b7e27d79 could not be reached.
BUG-018 Failed resource loading errors in console
Medium P2 • New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/kullanici/kaydol in Chrome DevTools → Console
  2. Reload the page with the console open
  3. Locate the matching error entry and follow the stack trace into the source
  4. Fix the failing call or guard against the input that triggered it
All resource requests should succeed (or fail gracefully with error handling).
6 occurrences of "Failed to load resource: the server responded with a status of 401" across 3 pages. First observed on https://example-coffee-shop.com/kullanici/kaydol.
BUG-019 Form accepts empty submission
Medium P2 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in a browser
  2. Find the form (action="https://example-coffee-shop.com/alisveris/ara", method=POST)
  3. Reproduce the empty submit test scenario
  4. Click the submit button and observe the form proceeds without challenge
Client-side validation should prevent empty submissions.
Empty form on https://example-coffee-shop.com/ submitted without triggering validation or error messages.
BUG-020 JavaScript console errors detected
Medium P2 • New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/kullanici/kaydol in Chrome DevTools → Console
  2. Reload the page with the console open
  3. Locate the matching error entry and follow the stack trace into the source
  4. Fix the failing call or guard against the input that triggered it
Pages should load without JavaScript console errors.
12 occurrences of "%c%d font-size:0;color:transparent NaN" error across 3 pages. First observed on https://example-coffee-shop.com/kullanici/kaydol.
BUG-021 No offline or cached state
Medium P2 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/
  2. Open DevTools → Network → toggle 'Offline'
  3. Reload and observe what the user sees
  4. Implement a service worker that caches the shell, or render an offline fallback page
Offline navigation should show a cached page or branded offline screen.
Offline navigation to https://example-coffee-shop.com/ shows a generic browser error: net::ERR_INTERNET_DISCONNECTED.
BUG-022 Heavy page weight and low lazy-load adoption degrade mobile performance
Medium P2 • New
https://example-coffee-shop.com/ (Mobile)
  1. Open Chrome DevTools Network tab, reload https://example-coffee-shop.com/ — observe total transfer size around 4.8 MB.
  2. Filter by Img — several images above 500 KB with no lazy-load attribute.
  3. Throttle to Fast 3G and reload — significant render delay before page is usable.
Page weight should target under 1.5 MB for e-commerce pages; all below-the-fold images should use loading='lazy'; individual images should be compressed and served in next-gen formats (WebP/AVIF).
TS-PERF: / is 4.81 MB, /alisveris/urun/kenya-kirinyaga is 3.40 MB. TS-IMG: only 3 of 17 images use lazy loading; 4 images exceed 500 KB.
BUG-023 JavaScript URLs in links
Medium P2 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ → DevTools → Console
  2. Run `[...document.querySelectorAll('a[href]')].filter(a => a.getAttribute('href').toLowerCase().startsWith('javascript:'))`
  3. Replace each `javascript:` href with a button + script-file handler, or remove the link entirely
Links should point to real URLs (http://, https://, mailto:, tel:, or #fragment), not javascript: strings.
49 javascript: href values found across 49 pages. First observed on https://example-coffee-shop.com/.
BUG-024 Missing Content-Security-Policy header
Medium P2 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. curl -I 'https://example-coffee-shop.com/'
  2. Inspect the response headers — 'Content-Security-Policy' should be present
  3. (Most security headers are configured at the web-server or CDN layer; check the deployment platform's docs.)
Every page should include a Content-Security-Policy header that restricts script sources.
Content-Security-Policy header is not set. This was checked on 2 sample pages.
BUG-025 No cookie consent banner detected
Medium P2 • New
https://example-coffee-shop.com (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in a private window (no prior session)
  2. Verify whether a consent banner appears
  3. If only after-JS, consider server-side rendering it so static crawlers / accessibility tools see it
A cookie or consent banner should be visible or loadable on the first page visit.
Homepage HTML response did not contain common consent-banner indicators.
BUG-026 Server software details publicly visible
Medium P2 • New
https://example-coffee-shop.com (Desktop + Mobile)
  1. curl -I 'https://example-coffee-shop.com/'
  2. Confirm the X-Powered-By response header is present and discloses the software
  3. Configure the server / reverse proxy to remove or anonymize the header
Server software version should not be disclosed in response headers.
X-Powered-By header reveals: PHP/8.4.21, PleskLin
BUG-027 Text inputs without character limits
Medium P2 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in DevTools → Elements
  2. Inspect each form input and check for the `maxlength` attribute
  3. Add `maxlength` matching the longest legitimate value (or the column width in the database)
Text inputs, email fields, and text areas should declare a sensible maxlength.
All 117 text inputs across 49 pages omit maxlength. First observed on https://example-coffee-shop.com/.
BUG-028 Third-party cookies set on page load
Medium P2 • New
https://example-coffee-shop.com (Desktop + Mobile)
  1. curl -I 'https://example-coffee-shop.com/'
  2. Inspect Set-Cookie Domain= values
  3. Move tracking to first-party (server-side proxy) or implement consent gating
Cookies should use first-party domains (or no Domain attribute).
2 third-party cookies detected: XSRF-TOKEN@example-coffee-shop.com, example coffee shop_session@example-coffee-shop.com.
BUG-029 Missing page title
Medium P2 • New
https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf in DevTools → Elements tab
  2. Inspect `<head>` and confirm no `<title>` (or an empty one) is present
  3. Add a descriptive `<title>` to the page template
Every page should have a <title> element with meaningful content.
1 of 50 crawled pages has an empty or missing <title> element.
BUG-030 Missing SEO metadata
Medium P2 • New
https://example-coffee-shop.com/abonelikler (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/abonelikler → View source
  2. Search for `<meta name="description"` and confirm it is absent
  3. Add a 50–160 character description in the page template
Every page should include a <meta name="description" content="..."> tag.
32 of 50 crawled pages have no meta description.
BUG-031 Unbranded 403 responses replace expected 404 handling for unknown URLs
Medium P2 • New
https://example-coffee-shop.com/page-not-found (Desktop + Mobile)
  1. Visit https://example-coffee-shop.com/this-page-does-not-exist in a browser.
  2. Observe a bare, unbranded 403 Forbidden response with no navigation.
  3. Confirm with curl -I https://example-coffee-shop.com/nonexistent — HTTP/1.1 403.
Requests for non-existent pages should return a friendly branded 404 page with navigation options, helping users recover and reducing bounce rate.
TS-ERR: GET /page-not-found returns HTTP 403 (not branded) and GET /aaaa… (500-char) also returns HTTP 403 (not branded), in 0.36 s and 0.20 s respectively.
BUG-032 Inconsistent heading structure
Low P3 • New
https://example-coffee-shop.com/alisveris/kategori/rare (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/alisveris/kategori/rare in DevTools
  2. Run `[...document.querySelectorAll('h1,h2,h3,h4,h5,h6')].map(h => h.tagName)` in Console
  3. Confirm at least one adjacent pair skips a level (e.g. H1 followed by H3)
  4. Rebalance: demote skipped levels or insert the missing intermediate heading
Heading levels should descend in order (<h1> → <h2> → <h3>, and so on).
1 of 50 crawled pages has at least one skipped heading level.
BUG-033 Carousel library error in console
Low P3 • New
https://example-coffee-shop.com/abonelikler (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/abonelikler in Chrome DevTools → Console
  2. Reload the page with the console open
  3. Locate the matching error entry and follow the stack trace into the source
  4. Fix the failing call or guard against the input that triggered it
JavaScript libraries should initialize without errors.
4 occurrences of "Bad element for Flickity: .magaza-carousel" across 2 pages. First observed on https://example-coffee-shop.com/abonelikler.
BUG-034 Carousel library null reference error
Low P3 • New
https://example-coffee-shop.com/abonelikler (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/abonelikler in Chrome DevTools → Console
  2. Reload the page with the console open
  3. Locate the matching error entry and follow the stack trace into the source
  4. Fix the failing call or guard against the input that triggered it
JavaScript libraries should initialize without errors.
4 occurrences of "Bad element for Flickity: null" across 2 pages. First observed on https://example-coffee-shop.com/abonelikler.
BUG-035 No offline support (service worker not registered)
Low P3 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ → DevTools → Application → Service workers
  2. Confirm no service worker is registered
  3. (Optional) Register a service worker to enable offline caching and faster repeat loads
A service worker should be registered to support offline access.
No service worker registrations detected on https://example-coffee-shop.com/.
BUG-036 Heavy page weight (4.81 MB)
Low P3 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in Chrome DevTools → Lighthouse → Performance
  2. Run an audit and confirm the Weight metric exceeds the "good" threshold
  3. Compare against ≤3 MB good · ≤5 MB needs improvement thresholds (Google Core Web Vitals)
Page weight should be ≤3 MB (good) or ≤5 MB (acceptable).
Homepage transfers 4.81 MB (verdict: needs improvement). Measured under standard network conditions.
BUG-037 Images not using native lazy-loading
Low P3 • New
https://example-coffee-shop.com (Desktop + Mobile)
  1. curl -s 'https://example-coffee-shop.com/' | grep -oE '<img[^>]*>' | head -20
  2. Confirm the image tags carry no `loading="lazy"` attribute
  3. Add the attribute to each `<img>` below the fold
Most images below the fold should use the loading="lazy" attribute.
3 of 17 images on the homepage use loading="lazy" (18%).
BUG-038 Oversized image (532 KB)
Low P3 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. curl -sI 'https://example-coffee-shop.com/storage/slider/2026/04/slider-sahibi-degil-parcasi-br-oldugumuz-doga-07.jpeg'
  2. Inspect the `Content-Length` response header
  3. Re-encode or resize the image asset, then re-deploy
Images should be under 500 KB.
https://example-coffee-shop.com/storage/slider/2026/04/slider-sahibi-degil-parcasi-br-oldugumuz-doga-07.jpeg is 532 KB.
BUG-039 Forms lack duplicate-submission prevention
Low P3 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/
  2. Inspect the hidden inputs on a mutating form
  3. Confirm no idempotency_key / request_id / nonce is present
  4. Wire the framework's idempotency helper into the form template
Each form that changes data should include a hidden idempotency token (e.g., idempotency_key, request_id, or nonce).
All 117 mutating forms across 49 pages lack an idempotency token.
BUG-040 Forms may lack cross-site forgery protection
Low P3 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ → DevTools → Elements
  2. Confirm the form has no hidden CSRF token AND no other defense (check the session cookie's SameSite attribute and any CSRF <meta> tag / request header)
  3. If genuinely unprotected, add a CSRF token or set SameSite=Lax/Strict on the session cookie
Each form that changes data should be protected by a CSRF token (hidden field), a SameSite-restricted cookie, or a header-based token.
All 117 mutating forms across 49 pages show no hidden CSRF token field. Other protections (SameSite cookie, custom header) cannot be detected by this scanner.
BUG-041 Inline event handlers in HTML
Low P3 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ → DevTools → Elements
  2. Run `document.querySelectorAll('[onclick],[onload],[onerror],[onmouseover]')` in Console
  3. Replace each inline handler with an `addEventListener` call in a script file
Event handlers should be wired through JavaScript addEventListener(), not inline on* attributes.
392 inline event-handler attributes found across 49 pages. First observed on https://example-coffee-shop.com/.
BUG-042 Login endpoint shows no rate-limit protection signal
Low P3 • New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
  1. curl -X OPTIONS 'https://example-coffee-shop.com/kullanici/kaydol' -i
  2. Inspect response headers for Retry-After / X-RateLimit-*
  3. Wire a rate limiter on the auth endpoint (CDN / edge / framework)
Login endpoint should include Retry-After or X-RateLimit-* headers to signal rate-limit protection.
OPTIONS request to https://example-coffee-shop.com/kullanici/kaydol returned HTTP 200 with no rate-limit headers.
BUG-043 No 'remember me' option on login
Low P3 • New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/kullanici/kaydol
  2. Scan the login form for a checkbox
  3. Add a 'Remember me' checkbox that the server interprets as a long-lived session
Login form should offer a 'Remember me' checkbox.
No 'Remember me' checkbox found on the login form.
BUG-044 No password reset link on login page
Low P3 • New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/kullanici/kaydol
  2. Scan visible link text near the login form
  3. Add a 'Forgot password?' link that initiates the reset flow
Login page should include a password-reset link.
No password-reset link found on the login page.
BUG-045 No password visibility toggle
Low P3 • New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/kullanici/kaydol
  2. Locate the password input
  3. Add a sibling button that toggles the input type
Login form should have a button to toggle password visibility.
No password visibility toggle found near the password field.
BUG-046 No rate-limiting visible on homepage
Low P3 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Fire 20 parallel GET https://example-coffee-shop.com/
  2. Inspect each response status + headers for 429 / X-RateLimit-* / Retry-After
  3. Add rate limiting at the CDN / edge / framework layer
Server should send rate-limit signals (429 responses or X-RateLimit-* / Retry-After headers) under heavy load.
20 parallel requests to the homepage all succeeded with no 429 response or rate-limit header.
BUG-047 Password field missing autocomplete attribute
Low P3 • New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/kullanici/kaydol
  2. Inspect the password input
  3. Add `autocomplete="current-password"` (login) or `"new-password"` (signup)
Password input should have autocomplete="current-password" attribute.
The password input is missing the autocomplete attribute.
BUG-048 Password field missing maxlength attribute
Low P3 • New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/kullanici/kaydol
  2. Inspect the password input
  3. Add a `maxlength` matching the server's accepted password length
Password input should have a maxlength attribute (e.g., maxlength="128").
The password input is missing maxlength.
BUG-049 Potential CSRF gap on state-changing forms (unverified)
Low P3 • New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
  1. Open an affected page → DevTools → Elements / Network
  2. Check the form's hidden inputs, the session cookie's SameSite attribute, and any CSRF <meta> tag / request header
  3. If genuinely none are present, add a CSRF token or set SameSite=Lax/Strict on the session cookie
Each state-changing form is protected by at least one CSRF defense — a hidden token, a SameSite=Lax/Strict session cookie, or a header / meta token (only the hidden token is visible to an external scan).
No hidden CSRF token field was found in the form markup. SameSite / header / meta defenses are not externally observable, so protection status is unverified.
BUG-050 Username field missing autocomplete attribute
Low P3 • New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/kullanici/kaydol
  2. Inspect the username / email input
  3. Add `autocomplete="username"` (or `"email"`)
Username/email input should have autocomplete="username" or "email" attribute.
The username input is missing the autocomplete attribute.
BUG-051 Content clipped at desktop viewport (1440px)
Low P3 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ and resize the browser to 1440×900
  2. Inspect the first offender element and verify its computed `overflow` is `hidden`
  3. Compare `scrollWidth` vs `clientWidth` in DevTools → Properties tab
  4. Replace `overflow: hidden` with a wrapping rule, or add `text-overflow: ellipsis`
Content should fit the desktop viewport or be truncated with an ellipsis.
1 element clips content at 1440px width. Example: div.flickity-viewport (1440px container → 5760px content).
BUG-052 Content clipped at mobile viewport (375px)
Low P3 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ and resize the browser to 375×812
  2. Inspect the first offender element and verify its computed `overflow` is `hidden`
  3. Compare `scrollWidth` vs `clientWidth` in DevTools → Properties tab
  4. Replace `overflow: hidden` with a wrapping rule, or add `text-overflow: ellipsis`
Content should fit the mobile viewport, or be truncated with an ellipsis indicator.
1 element clips content at 375px width. Example: div.flickity-viewport (375px container → 1500px content).
BUG-053 Content clipped at tablet viewport (768px)
Low P3 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ and resize the browser to 768×1024
  2. Inspect the first offender element and verify its computed `overflow` is `hidden`
  3. Compare `scrollWidth` vs `clientWidth` in DevTools → Properties tab
  4. Replace `overflow: hidden` with a wrapping rule, or add `text-overflow: ellipsis`
Content should fit the tablet viewport or be truncated with an ellipsis.
1 element clips content at 768px width. Example: div.flickity-viewport (768px container → 3072px content).
BUG-054 Missing main heading
Low P3 • New
https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf in DevTools
  2. Search the DOM for `h1` elements
  3. Confirm none are present
  4. Add a single, descriptive `<h1>` to the page template
Each page should have exactly one <h1> element.
1 of 50 crawled pages has no <h1> element.
BUG-055 Page titles too short for search results
Low P3 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in DevTools → Elements
  2. Inspect the `<title>` element
  3. Confirm the text is 9 characters (target 10–60)
  4. Rewrite the title to fit the 10–60 character window
Page titles should be between 10 and 60 characters.
37 of 50 pages have titles that are too short (0 too long, 37 too short). First example: https://example-coffee-shop.com/ (9 characters).
BUG-056 Registration form lacks password strength indicator
Low P3 • New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/kullanici/kaydol
  2. Inspect the password input's neighborhood
  3. Add a strength meter or live rule list
Registration form should show a password strength meter or rule list.
No password strength meter or rule list detected on the registration form.
BUG-057 Registration form missing terms acceptance checkbox
Low P3 • New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/kullanici/kaydol
  2. Inspect the registration form's checkboxes
  3. Add a required terms / privacy acceptance checkbox
Registration form should include a required checkbox for terms/privacy acceptance.
No terms, privacy, or consent checkbox found on the registration form.
BUG-058 Sitemap not found
Low P3 • New
https://example-coffee-shop.com/sitemap.xml (Desktop + Mobile)
  1. curl -I 'https://example-coffee-shop.com/sitemap.xml'
  2. Confirm the response is not 2xx
  3. Generate a sitemap (most frameworks ship a sitemap generator) and serve it at /sitemap.xml
GET /sitemap.xml should return HTTP 200 with a valid XML sitemap.
GET https://example-coffee-shop.com/sitemap.xml returned HTTP 404.
BUG-059 Undersized touch targets on mobile
Low P3 • New
https://example-coffee-shop.com/ (Desktop + Mobile)
  1. Open https://example-coffee-shop.com/ in Chrome DevTools at device width 375px
  2. Highlight each interactive element in turn and check its bounding-box dimensions
  3. Increase padding so the bounding box is ≥ 44×44 px
All interactive elements should be at least 44×44 pixels at mobile viewports.
31 of 45 interactive elements are below 44px at 375×812. Examples: buttons 22×24px, link 328×24px.
6Highest-Priority Findings

Auto-generated from severity ranking. Manual review recommended.

The top critical and high-severity findings, in priority order. See the Detailed Bug Reports section for full reproduction steps.
  1. BUG-001 — Color contrast failures (site-wide)
  2. BUG-002 — Form input missing accessible label
  3. BUG-003 — Pervasive missing accessible names on interactive elements site-wide
  4. BUG-004 — Internal link unreachable
  5. BUG-005 — Legal compliance failure: no cookie consent and broken KVKK document
  6. BUG-006 — Cookie missing HttpOnly flag
  7. BUG-007 — HTTP requests are not redirected to HTTPS
7Recommended Fix Order

Auto-generated from severity ranking. Manual review recommended.

Suggested remediation order. Engineering should validate the sequence against business priorities and dependency relationships before scheduling.
11. Implement CSRF tokens on all 117 state-mutating forms (including login, registration, and checkout) and mark the XSRF-TOKEN cookie HttpOnly — these two gaps share the same root cause (missing anti-forgery layer) and together represent the highest-risk exploitable vulnerability.
22. Add a compliant KVKK/GDPR cookie consent banner that blocks third-party cookies until explicit user consent is given — the absence of this creates direct regulatory liability.
33. Fix the broken internal link to /pdf/kvkk_basvuru.pdf by uploading the correct file or correcting the URL — this is both a legal-document accessibility failure and a broken user journey on a compliance page.
44. Add a Content-Security-Policy header at the server or CDN/edge layer to restrict script execution sources and mitigate XSS risk; simultaneously remove all 49 javascript: href links and replace with proper button or event-listener patterns.
55. Assign unique, descriptive <title> tags and meta descriptions to all 50 pages (37 titles are too short or duplicate, 32 pages lack meta descriptions entirely) — this is a single templating fix that will substantially improve SEO and click-through rates.
66. Audit and label all 215 unnamed buttons and 392 unnamed links with accessible names (aria-label or visible text) and fix colour contrast failures on the homepage, contact, and product pages to meet WCAG 2.1 AA — a single design-system pass can resolve most instances.
77. Suppress or rotate the X-Powered-By header (PHP/8.4.21, PleskLin) to stop disclosing server stack details to potential attackers.
88. Optimise page weight by lazy-loading the remaining 82% of images without the attribute and compressing the 4 images over 500 KB — targeting the homepage's 4.81 MB payload will most directly improve Core Web Vitals and mobile conversion.
99. Add rate limiting on the login endpoint and implement client-side idempotency tokens on order/checkout forms to prevent credential stuffing and accidental duplicate orders.
1010. Fix the 403 unbranded error responses for unknown URLs — replace with a friendly branded 404 page that keeps users on-site and provides navigation options.
8Recommended Manual Test Scenarios
Manual test scenarios recommended by the AI analyzer based on the crawled site structure. Hand this list to your QA team for execution — each scenario covers something the automation cannot verify on its own.
Happy Path (5)
TC-001 Register a new account with valid credentials
happy-path High
User is not registered and is on the /kullanici/kaydol page.
  1. Enter a first name in the 'ad' field
  2. Enter a last name in the 'soyad' field
  3. Enter a valid email address in the 'email' field
  4. Enter a password of at least 8 characters in the 'password' field
  5. Confirm the password in the 'password_confirm' field
  6. Check the 'kvkk' (KVKK agreement) checkbox
  7. Click the 'Kayıt Ol' button
Account is created successfully and user is redirected to the dashboard or home page.
TC-002 Search for a product using the search form
happy-path High
User is on any page with the search form visible.
  1. Locate the search form with 'arama' text field
  2. Enter a product name (e.g., 'kahve') in the 'arama' field
  3. Click the 'Bul' button
Search results page displays products matching the search term.
TC-003 Add a coffee subscription to cart with variant selection
happy-path High
User is on the product page /alisveris/urun/kahve-aboneligi and is not logged in.
  1. Select a value from the 'ay' (month) dropdown
  2. Select a value from the 'hafta' (week) dropdown
  3. Select at least one checkbox variant option from product_variant_group_id[1]
  4. Click the 'Sepete Ekle' button
Product is added to cart and cart counter increases. Success notification appears.
TC-004 Subscribe to newsletter with valid email
happy-path Medium
User is on any page with the newsletter form visible.
  1. Locate the newsletter form with 'email' field
  2. Enter a valid email address
  3. Click the 'Abone Ol' button
Newsletter subscription is confirmed and a success message appears.
TC-005 Verify product category navigation flow
happy-path Medium
User is on the home page /
  1. Click the 'Kahveler' category link
  2. Verify page loads with coffee products
  3. Click the 'Ekipmanlar' category link
  4. Verify page loads with equipment products
Each category page loads correctly and displays products in that category.
Negative Cases (9)
TC-006 Register with mismatched password confirmation
negative High
User is on the /kullanici/kaydol page.
  1. Enter a first name
  2. Enter a last name
  3. Enter a valid email
  4. Enter a password in the 'password' field
  5. Enter a different value in the 'password_confirm' field
  6. Check the 'kvkk' checkbox
  7. Click the 'Kayıt Ol' button
Form submission fails with an error message indicating passwords do not match.
TC-007 Register without checking KVKK agreement
negative High
User is on the /kullanici/kaydol page.
  1. Enter a first name
  2. Enter a last name
  3. Enter a valid email
  4. Enter a matching password pair
  5. Leave the 'kvkk' checkbox unchecked
  6. Click the 'Kayıt Ol' button
Form submission fails with an error message requiring KVKK agreement.
TC-008 Search with empty search field
negative Medium
User is on any page with the search form.
  1. Leave the 'arama' field empty
  2. Click the 'Bul' button
Form submission either fails with a validation error or displays all products without filtering.
TC-009 Add product to cart without selecting required variant
negative High
User is on a product page with variant selection (e.g., /alisveris/urun/cezve).
  1. Do not select any value from the variant dropdown (product_variant_group_id[5])
  2. Enter a quantity in the 'adet' field
  3. Click the 'Sepete Ekle' button
Form submission fails with a validation error indicating variant selection is required.
TC-010 Add subscription product without selecting month or week
negative High
User is on the subscription product page /alisveris/urun/kahve-aboneligi.
  1. Do not select a value from the 'ay' dropdown
  2. Do not select a value from the 'hafta' dropdown
  3. Select a variant checkbox
  4. Click 'Sepete Ekle'
Form submission fails with validation errors for missing month and week selections.
TC-011 Subscribe to newsletter with invalid email format
negative Medium
User is on any page with the newsletter form.
  1. Enter an invalid email (e.g., 'notanemail') in the 'email' field
  2. Click 'Abone Ol'
Form submission fails with a validation error for invalid email format.
TC-012 Attempt to add product without quantity value
negative Medium
User is on a non-subscription product page with quantity field (e.g., /alisveris/urun/cezve).
  1. Select a variant from the dropdown
  2. Leave the 'adet' (quantity) field empty
  3. Click 'Sepete Ekle'
Form submission fails with validation error for missing or invalid quantity.
TC-013 Register with email that already exists
negative High
User is on the /kullanici/kaydol page and an account with test@example.com already exists.
  1. Enter a first name
  2. Enter a last name
  3. Enter an email address that already has a registered account (test@example.com)
  4. Enter a matching password pair
  5. Check the 'kvkk' checkbox
  6. Click 'Kayıt Ol'
Form submission fails with an error message indicating email is already registered.
TC-014 Add zero or negative quantity to cart
negative Medium
User is on a product page with quantity number field.
  1. Select a variant if required
  2. Enter '0' in the 'adet' (quantity) field
  3. Click 'Sepete Ekle'
Form submission fails with validation error or quantity is rejected as invalid.
Edge Cases (3)
TC-015 Register with extremely long first name (250+ characters)
edge-case Medium
User is on the /kullanici/kaydol page.
  1. Enter a string of 300+ characters in the 'ad' field
  2. Enter a valid last name
  3. Enter a valid email
  4. Enter a matching password pair
  5. Check the 'kvkk' checkbox
  6. Click 'Kayıt Ol'
Form submission either fails with length validation error or text is truncated appropriately.
TC-016 Search with special characters and Unicode in query
edge-case Medium
User is on any page with the search form.
  1. Enter special characters and Unicode (e.g., '(kahve)@#$ۄ') in the 'arama' field
  2. Click 'Bul'
Search processes without errors and returns appropriate results or empty set.
TC-017 Submit newsletter form twice rapidly (duplicate submission)
edge-case Medium
User is on any page with the newsletter form.
  1. Enter a valid email address in the 'email' field
  2. Click 'Abone Ol' button
  3. Immediately click 'Abone Ol' button again before page response
Only one subscription is recorded; second submission is prevented or ignored.
Security (2)
TC-018 Register with XSS payload in email field
security High
User is on the /kullanici/kaydol page.
  1. Enter a first name
  2. Enter a last name
  3. Enter a potential XSS payload in email field (e.g., '<script>alert(1)</script>@test.com')
  4. Enter a matching password pair
  5. Check the 'kvkk' checkbox
  6. Click 'Kayıt Ol'
Input is either rejected as invalid email format or safely escaped; no script executes.
TC-019 Search with SQL injection-shaped payload
security High
User is on any page with the search form.
  1. Enter SQL injection attempt in 'arama' field (e.g., "'; DROP TABLE products; --")
  2. Click 'Bul'
Payload is treated as a literal search string; no database modification occurs.
UX & Responsive (1)
TC-020 Navigate category links and verify cart counter persists
ux Medium
User has added a product to cart and cart counter shows '1'.
  1. Click the 'Kahveler' category link
  2. Verify cart counter still displays '1'
  3. Click the 'Aksesuar' category link
  4. Verify cart counter still displays '1'
  5. Click 'Online Dükkan' to return to main shop
Cart counter persists across all page navigations and displays the correct item count.
9Summary & Observations
Testing Outcome — Automated Scan

Critical and high-severity findings cluster around functional / security issues — recommend an engineering triage session before scheduling remediation.

An automated scan can only validate what it can statically observe (DOM, console, load timing). Recommend a manual review of business-critical flows (auth, payment, data submission) before sign-off.

We use a single session cookie to keep you signed in. No tracking cookies. See our Privacy Policy for details.