Sample report. This is a real QA Explorer scan, run on example-coffee-shop.com on 2026-06-07. Want to see what we'd find on your site? Drop your URL below to run your own free scan.
Quality Assurance
example-coffee-shop.com
Automated scan of example-coffee-shop.com via QA Explorer. Covered 50 pages, ran 308 scripted test cases (222 passed), and surfaced 59 unique findings across functionality, UX, accessibility, performance, and security.
Confidential
59
New Bugs
—
Bugs Fixed
—
UX Improved
308
Cases Run
222
Passed
59 findings · 8 high · 59 unique
1Executive Summary
Example Coffee Shop's website is a functioning e-commerce platform for specialty coffee with solid fundamentals: all 49 reachable pages return successful responses, SSL/TLS is in place, and basic meta infrastructure is present. However, the scan uncovered a broad set of security, accessibility, and content-quality issues that collectively present real risk to customers, the business's legal standing under GDPR/KVKK, and search engine visibility.
The most serious concerns are security-related. Forms across the site — including the login, registration, and checkout flows — lack CSRF protection, meaning an attacker could trick a logged-in customer into placing orders or changing account data without their knowledge. The XSRF-TOKEN cookie is not marked HttpOnly, making it readable by JavaScript and vulnerable to theft. There is no Content Security Policy, leaving the site open to cross-site scripting attacks. Additionally, no cookie consent banner is present despite third-party cookies being set on load, which is a direct violation of Turkish KVKK and EU GDPR rules and exposes the business to regulatory fines. A required legal document (the KVKK application form PDF) is completely inaccessible — a broken link on a compliance page.
Accessibility is a systemic weakness: 215 buttons and 392 links have no readable label for screen-reader users, colour contrast fails on multiple pages, and nearly every inner page is missing a unique meta description and Open Graph metadata, severely hurting SEO and social sharing. The homepage alone weighs 4.81 MB, which will result in slow load times on mobile connections. The team should prioritise CSRF protection and cookie consent first as legal/security obligations, then address accessibility and SEO gaps which directly affect customer reach and inclusivity.
Production impact. 8 high-severity findings should be addressed before this build is promoted.
The most serious concerns are security-related. Forms across the site — including the login, registration, and checkout flows — lack CSRF protection, meaning an attacker could trick a logged-in customer into placing orders or changing account data without their knowledge. The XSRF-TOKEN cookie is not marked HttpOnly, making it readable by JavaScript and vulnerable to theft. There is no Content Security Policy, leaving the site open to cross-site scripting attacks. Additionally, no cookie consent banner is present despite third-party cookies being set on load, which is a direct violation of Turkish KVKK and EU GDPR rules and exposes the business to regulatory fines. A required legal document (the KVKK application form PDF) is completely inaccessible — a broken link on a compliance page.
Accessibility is a systemic weakness: 215 buttons and 392 links have no readable label for screen-reader users, colour contrast fails on multiple pages, and nearly every inner page is missing a unique meta description and Open Graph metadata, severely hurting SEO and social sharing. The homepage alone weighs 4.81 MB, which will result in slow load times on mobile connections. The team should prioritise CSRF protection and cookie consent first as legal/security obligations, then address accessibility and SEO gaps which directly affect customer reach and inclusivity.
Production impact. 8 high-severity findings should be addressed before this build is promoted.
2Test Scope & Environment
| Field | Value |
|---|---|
| Application | example-coffee-shop.com |
| Environment | https://example-coffee-shop.com |
| Methodology | Automated end-to-end exploratory scan — a headless browser crawls same-origin links, captures DOM/console/screenshots, analyzer derives findings. |
| Pages Scanned | 50 |
| Duration | 9 min 45 s |
| Report ID | 3a20b969-f0cb-4740-a2d6-cd7a9a22a5d9 |
| Analyzer | QA Explorer Engine |
3Test Execution Details
Scripted test cases executed against the target. Status values follow the test runner's convention (PASS / FAIL / UX / BLOCKED).
TS-NAV — Navigation & Page Load Tests
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Open homepage | The homepage should load successfully with all primary content visible. | HTTP 200, loaded in 2.59s, 23 headings, 84 links, 17 images. | ✓ PASS |
| 2 | Open Alisveris page | The Alisveris page should load successfully with all content visible. | HTTP 200, loaded in 2.33s, 73 headings, 266 links, 69 images. | ✓ PASS |
| 3 | Open Kahveler page | The Kahveler page should load successfully with all content visible. | HTTP 200, loaded in 2.54s, 27 headings, 128 links, 23 images. | ✓ PASS |
| 4 | Open Ekipmanlar page | The Ekipmanlar page should load successfully with all content visible. | HTTP 200, loaded in 2.31s, 37 headings, 156 links, 33 images. | ✓ PASS |
| 5 | Open Aksesuar page | The Aksesuar page should load successfully with all content visible. | HTTP 200, loaded in 2.65s, 31 headings, 138 links, 27 images. | ✓ PASS |
| 6 | Open Abonelikler page | The Abonelikler page should load successfully with all content visible. | HTTP 200, loaded in 2.32s, 28 headings, 74 links, 15 images. | ✓ PASS |
| 7 | Open Kahve Aboneligi Otomatik Kahve Makinesi page | The Kahve Aboneligi Otomatik Kahve Makinesi page should load successfully with all content visible. | HTTP 200, loaded in 1.91s, 28 headings, 75 links, 11 images. | ✓ PASS |
| 8 | Open Kahve Aboneligi Espresso page | The Kahve Aboneligi Espresso page should load successfully with all content visible. | HTTP 200, loaded in 2.04s, 28 headings, 75 links, 11 images. | ✓ PASS |
| 9 | Open Kahve Aboneligi page | The Kahve Aboneligi page should load successfully with all content visible. | HTTP 200, loaded in 2.08s, 28 headings, 75 links, 11 images. | ✓ PASS |
| 10 | Open Demleme Teknikleri page | The Demleme Teknikleri page should load successfully with all content visible. | HTTP 200, loaded in 2.35s, 18 headings, 77 links, 16 images. | ✓ PASS |
| 11 | Open Filtre Kahve page | The Filtre Kahve page should load successfully with all content visible. | HTTP 200, loaded in 2.08s, 21 headings, 70 links, 8 images. | ✓ PASS |
| 12 | Open Espresso page | The Espresso page should load successfully with all content visible. | HTTP 200, loaded in 2.30s, 19 headings, 70 links, 8 images. | ✓ PASS |
| 13 | Open French Press page | The French Press page should load successfully with all content visible. | HTTP 200, loaded in 2.08s, 21 headings, 70 links, 8 images. | ✓ PASS |
| 14 | Open Moka Pot page | The Moka Pot page should load successfully with all content visible. | HTTP 200, loaded in 2.18s, 21 headings, 70 links, 8 images. | ✓ PASS |
| 15 | Open Hario V60 page | The Hario V60 page should load successfully with all content visible. | HTTP 200, loaded in 2.15s, 21 headings, 70 links, 8 images. | ✓ PASS |
| 16 | Open Aeropress page | The Aeropress page should load successfully with all content visible. | HTTP 200, loaded in 2.09s, 21 headings, 70 links, 8 images. | ✓ PASS |
| 17 | Open Turk Kahvesi page | The Turk Kahvesi page should load successfully with all content visible. | HTTP 200, loaded in 2.04s, 21 headings, 70 links, 8 images. | ✓ PASS |
| 18 | Open Magazalar page | The Magazalar page should load successfully with all content visible. | HTTP 200, loaded in 3.10s, 11 headings, 109 links, 112 images. | ✓ PASS |
| 19 | Open Makaleler page | The Makaleler page should load successfully with all content visible. | HTTP 200, loaded in 2.65s, 20 headings, 79 links, 20 images. | ✓ PASS |
| 20 | Open Kahveni Bul page | The Kahveni Bul page should load successfully with all content visible. | HTTP 200, loaded in 2.13s, 19 headings, 71 links, 7 images. | ✓ PASS |
| 21 | Open Kaydol page | The Kaydol page should load successfully with all content visible. | HTTP 200, loaded in 2.09s, 11 headings, 74 links, 7 images. | ✓ PASS |
| 22 | Open Oturumac page | The Oturumac page should load successfully with all content visible. | HTTP 200, loaded in 2.08s, 11 headings, 72 links, 7 images. | ✓ PASS |
| 23 | Open homepage | The homepage should load successfully with all primary content visible. | HTTP 200, loaded in 2.41s, 23 headings, 84 links, 17 images. | ✓ PASS |
| 24 | Open Kahve Abonelikleri page | The Kahve Abonelikleri page should load successfully with all content visible. | HTTP 200, loaded in 2.62s, 28 headings, 74 links, 15 images. | ✓ PASS |
| 25 | Open Iletisim page | The Iletisim page should load successfully with all content visible. | HTTP 200, loaded in 2.29s, 11 headings, 70 links, 7 images. | ✓ PASS |
| 26 | Open Example Coffee Shop Grounded Collection Oversized White T Shirt page | The Example Coffee Shop Grounded Collection Oversized White T Shirt page should load successfully with all content visible. | HTTP 200, loaded in 2.20s, 15 headings, 76 links, 12 images. | ✓ PASS |
| 27 | Open Grounded Collection Oversized Green Hoodie page | The Grounded Collection Oversized Green Hoodie page should load successfully with all content visible. | HTTP 200, loaded in 2.35s, 15 headings, 76 links, 12 images. | ✓ PASS |
| 28 | Open Etiyopya Korcha Natural Filtre page | The Etiyopya Korcha Natural Filtre page should load successfully with all content visible. | HTTP 200, loaded in 2.34s, 16 headings, 76 links, 13 images. | ✓ PASS |
| 29 | Open Latte Fincani Logolu page | The Latte Fincani Logolu page should load successfully with all content visible. | HTTP 200, loaded in 2.26s, 14 headings, 75 links, 11 images. | ✓ PASS |
| 30 | Open Etkinlik Egitim page | The Etkinlik Egitim page should load successfully with all content visible. | HTTP 200, loaded in 2.07s, 11 headings, 75 links, 7 images. | ✓ PASS |
| 31 | Open Hikayemiz page | The Hikayemiz page should load successfully with all content visible. | HTTP 200, loaded in 2.04s, 11 headings, 70 links, 9 images. | ✓ PASS |
| 32 | Open Iletisim page | The Iletisim page should load successfully with all content visible. | HTTP 200, loaded in 2.27s, 11 headings, 70 links, 7 images. | ✓ PASS |
| 33 | Open Sss page | The Sss page should load successfully with all content visible. | HTTP 200, loaded in 2.04s, 49 headings, 70 links, 9 images. | ✓ PASS |
| 34 | Open Menuler page | The Menuler page should load successfully with all content visible. | HTTP 200, loaded in 2.37s, 11 headings, 70 links, 11 images. | ✓ PASS |
| 35 | Open Kahve Hakkinda page | The Kahve Hakkinda page should load successfully with all content visible. | HTTP 200, loaded in 2.27s, 13 headings, 83 links, 8 images. | ✓ PASS |
| 36 | Open Kvkk page | The Kvkk page should load successfully with all content visible. | HTTP 200, loaded in 2.22s, 11 headings, 70 links, 7 images. | ✓ PASS |
| 37 | Open Aydinlatma page | The Aydinlatma page should load successfully with all content visible. | HTTP 200, loaded in 2.15s, 11 headings, 70 links, 7 images. | ✓ PASS |
| 38 | Open Cerez page | The Cerez page should load successfully with all content visible. | HTTP 200, loaded in 2.09s, 11 headings, 70 links, 7 images. | ✓ PASS |
| 39 | Load the PDF file at /pdf/kvkk_basvuru.pdf | The file should load successfully and display its content. | The file did not load. The server did not provide a response after 0.75 seconds, indicating the file may be unavailable or inaccessible. | ✗ FAIL |
| 40 | Open Odeme page | The Odeme page should load successfully with all content visible. | HTTP 200, loaded in 2.92s, 11 headings, 72 links, 7 images. | ✓ PASS |
| 41 | Open Hario V60 Dripper Seti page | The Hario V60 Dripper Seti page should load successfully with all content visible. | HTTP 200, loaded in 2.23s, 15 headings, 77 links, 11 images. | ✓ PASS |
| 42 | Open Cezve page | The Cezve page should load successfully with all content visible. | HTTP 200, loaded in 2.27s, 15 headings, 77 links, 11 images. | ✓ PASS |
| 43 | Open Hario Kettle Buono page | The Hario Kettle Buono page should load successfully with all content visible. | HTTP 200, loaded in 2.13s, 15 headings, 77 links, 13 images. | ✓ PASS |
| 44 | Open Shopping page | The Shopping page should load successfully with all content visible. | HTTP 200, loaded in 2.46s, 73 headings, 266 links, 69 images. | ✓ PASS |
| 45 | Open Filtre Kahve page | The Filtre Kahve page should load successfully with all content visible. | HTTP 200, loaded in 2.48s, 20 headings, 107 links, 16 images. | ✓ PASS |
| 46 | Open Rare page | The Rare page should load successfully with all content visible. | HTTP 200, loaded in 2.51s, 21 headings, 84 links, 31 images. | ✓ PASS |
| 47 | Open Espresso page | The Espresso page should load successfully with all content visible. | HTTP 200, loaded in 2.31s, 15 headings, 92 links, 11 images. | ✓ PASS |
| 48 | Open Turk Kahvesi page | The Turk Kahvesi page should load successfully with all content visible. | HTTP 200, loaded in 2.21s, 12 headings, 83 links, 8 images. | ✓ PASS |
| 49 | Open Ve Dahasi page | The Ve Dahasi page should load successfully with all content visible. | HTTP 200, loaded in 2.12s, 13 headings, 86 links, 9 images. | ✓ PASS |
| 50 | Open Kenya Kirinyaga page | The Kenya Kirinyaga page should load successfully with all content visible. | HTTP 200, loaded in 2.18s, 15 headings, 76 links, 13 images. | ✓ PASS |
TS-LINKS — Internal Link Health
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | HEAD /"Anasayfa" · linked from 49 pages | The "Anasayfa" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 2 | HEAD /alisveris"Online Dükkan" · linked from 49 pages | The "Online Dükkan" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 3 | HEAD /alisveris/kategori/kahveler"Kahveler" · linked from 49 pages | The "Kahveler" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 4 | HEAD /alisveris/kategori/ekipmanlar"Ekipmanlar" · linked from 49 pages | The "Ekipmanlar" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 5 | HEAD /alisveris/kategori/aksesuar"Aksesuar" · linked from 48 pages | The "Aksesuar" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 6 | HEAD /abonelikler"Abonelikler" · linked from 47 pages | The "Abonelikler" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 7 | HEAD /alisveris/urun/kahve-aboneligi-otomatik-kahve-makinesi"Otomatik Makineler" · linked from 47 pages | The "Otomatik Makineler" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 8 | HEAD /alisveris/urun/kahve-aboneligi-espresso"Espresso" · linked from 47 pages | The "Espresso" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 9 | HEAD /alisveris/urun/kahve-aboneligi"Filtre" · linked from 47 pages | The "Filtre" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 10 | HEAD /demleme-teknikleri"Demleme Teknikleri" · linked from 49 pages | The "Demleme Teknikleri" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 11 | HEAD /demleme-teknik/filtre-kahve"Filtre Kahve" · linked from 49 pages | The "Filtre Kahve" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 12 | HEAD /demleme-teknik/espresso"Espresso" · linked from 49 pages | The "Espresso" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 13 | HEAD /demleme-teknik/french-press"French Press" · linked from 49 pages | The "French Press" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 14 | HEAD /demleme-teknik/moka-pot"Moka Pot" · linked from 49 pages | The "Moka Pot" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 15 | HEAD /demleme-teknik/hario-v60"Hario V60" · linked from 49 pages | The "Hario V60" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 16 | HEAD /demleme-teknik/aeropress"Aeropress" · linked from 49 pages | The "Aeropress" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 17 | HEAD /demleme-teknik/turk-kahvesi"Türk Kahvesi" · linked from 49 pages | The "Türk Kahvesi" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 18 | HEAD /magazalar"Nerelerdeyiz" · linked from 49 pages | The "Nerelerdeyiz" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 19 | HEAD /makaleler"Blog" · linked from 49 pages | The "Blog" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 20 | HEAD /kahveni-bul"Kahveni Bul" · linked from 49 pages | The "Kahveni Bul" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 21 | HEAD /kullanici/kaydol"Üye Ol" · linked from 49 pages | The "Üye Ol" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 22 | HEAD /kullanici/oturumac"Giriş Yap" · linked from 49 pages | The "Giriş Yap" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 23 | HEAD /?setLang=en"EN" | The "EN" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 24 | HEAD /alisveris/kategori/kahve-abonelikleri"Abonelikler" · linked from 49 pages | The "Abonelikler" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 25 | HEAD /iletisim"Toptan Satış" · linked from 49 pages | The "Toptan Satış" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 26 | HEAD …/urun/example coffee shop-grounded-collection-oversized-white-t-shirt"Grounded Collection Oversized White T-Shirt" · linked from 5 pages | The "Grounded Collection Oversized White T-Shirt" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 27 | HEAD /alisveris/urun/grounded-collection-oversized-green-hoodie"Grounded Collection Oversized Green Hoodie" · linked from 5 pages | The "Grounded Collection Oversized Green Hoodie" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 28 | HEAD /alisveris/urun/etiyopya-korcha-natural-filtre"Etiyopya Korcha Natural (Filtre)" · linked from 6 pages | The "Etiyopya Korcha Natural (Filtre)" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 29 | HEAD /alisveris/urun/latte-fincani-logolu"Example Coffee Shop Latte Fincanı" · linked from 7 pages | The "Example Coffee Shop Latte Fincanı" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 30 | HEAD /alisveris/kategori/etkinlik-egitim"Etkinlikler" · linked from 49 pages | The "Etkinlikler" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 31 | HEAD /hikayemiz"Hikayemiz" · linked from 49 pages | The "Hikayemiz" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 32 | HEAD /iletisim?kariyer=1"Kariyer" · linked from 49 pages | The "Kariyer" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 33 | HEAD /sss"S. S. S." · linked from 49 pages | The "S. S. S." link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 34 | HEAD /menuler"Menü" · linked from 49 pages | The "Menü" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 35 | HEAD /kahve-hakkinda"Kahvelerimiz Hakkında" · linked from 49 pages | The "Kahvelerimiz Hakkında" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 36 | HEAD /kvkk"KVKK ve Gizlilik Politikası" · linked from 49 pages | The "KVKK ve Gizlilik Politikası" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 37 | HEAD /aydinlatma"Aydınlatma Metni" · linked from 49 pages | The "Aydınlatma Metni" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 38 | HEAD /cerez"Çerez Politikası" · linked from 49 pages | The "Çerez Politikası" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 39 | Check if the PDF file at /pdf/kvkk_basvuru.pdf is reachable | The file should be accessible and return a success response or a valid redirect. | The file is not reachable. No response was received from the server after 3.37 seconds. | ✗ FAIL |
| 40 | HEAD /odeme"Satın Al" · linked from 49 pages | The "Satın Al" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 41 | HEAD /alisveris/urun/Hario-v60-Dripper-seti"Sepete Ekle" · linked from 49 pages | The "Sepete Ekle" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 42 | HEAD /alisveris/urun/cezve"Sepete Ekle" · linked from 49 pages | The "Sepete Ekle" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 43 | HEAD /alisveris/urun/hario-kettle-buono"Sepete Ekle" · linked from 49 pages | The "Sepete Ekle" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 44 | HEAD /shopping"EN" · linked from 3 pages | The "EN" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 45 | HEAD /alisveris/kategori/filtre-kahve"Filtre Kahve" · linked from 8 pages | The "Filtre Kahve" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 46 | HEAD /alisveris/kategori/rare"RARE" · linked from 8 pages | The "RARE" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 47 | HEAD /alisveris/kategori/Espresso"Espresso" · linked from 8 pages | The "Espresso" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 48 | HEAD /alisveris/kategori/turk-kahvesi"Türk Kahvesi" · linked from 8 pages | The "Türk Kahvesi" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 49 | HEAD /alisveris/kategori/ve-dahasi"Ve Dahası" · linked from 8 pages | The "Ve Dahası" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 50 | HEAD /alisveris/urun/kenya-kirinyaga"Kenya Kirinyaga Washed" · linked from 4 pages | The "Kenya Kirinyaga Washed" link should resolve to a working page. | Link resolves correctly (HTTP 200). | ✓ PASS |
TS-SEC — Security Headers & Cookies
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Check Strict-Transport-Security security headersampled 2 pages | Header present with max-age ≥ 31536000 (1 year) | Present, max-age=31536000; includeSubDomains. | ✓ PASS |
| 2 | Verify Content-Security-Policy security header is set | The server should send a Content-Security-Policy header to protect against malicious scripts. | This security header is not set. The site is missing an important protection against code injection attacks. | ✗ FAIL |
| 3 | Check X-Content-Type-Options security headersampled 2 pages | Header value is exactly "nosniff" | Present, nosniff. | ✓ PASS |
| 4 | Check X-Frame-Options security headersampled 2 pages | DENY or SAMEORIGIN | Present, SAMEORIGIN. | ✓ PASS |
| 5 | Check Referrer-Policy security headersampled 2 pages | Header present (any directive) | Present, strict-origin-when-cross-origin. | ✓ PASS |
| 6 | Check Permissions-Policy security headersampled 2 pages | Header present (any directive set) | Present, geolocation=self. | ✓ PASS |
| 7 | Check that the XSRF-TOKEN cookie is protected with the HttpOnly flag | The cookie should be marked HttpOnly so it cannot be accessed by JavaScript, preventing theft via malicious scripts. | The HttpOnly flag is not set on this cookie. A malicious script could potentially steal this token. | ✗ FAIL |
| 8 | Cookie "XSRF-TOKEN" — Secure flagsampled from / | Secure attribute set | Secure attribute present | ✓ PASS |
| 9 | Cookie "XSRF-TOKEN" — SameSite attributesampled from / | SameSite=Strict / Lax / None | SameSite=none | ✓ PASS |
| 10 | Cookie "example coffee shop_session" — HttpOnly flagsampled from / | HttpOnly attribute set | HttpOnly attribute present | ✓ PASS |
| 11 | Cookie "example coffee shop_session" — Secure flagsampled from / | Secure attribute set | Secure attribute present | ✓ PASS |
| 12 | Cookie "example coffee shop_session" — SameSite attributesampled from / | SameSite=Strict / Lax / None | SameSite=none | ✓ PASS |
| 13 | Mixed Content scan across crawled pagesscanned 50 pages of console messages | No `http://` resources requested on HTTPS pages | No Mixed Content messages observed during crawl | ✓ PASS |
TS-A11Y — Accessibility Audit
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Verify every page declares a language attribute | All pages should include a lang attribute in the HTML tag so screen readers and browsers know the page language. | 1 out of 50 pages is missing this attribute, preventing assistive technology from reading the page correctly. | ✗ FAIL |
| 2 | Verify each page has exactly one main heading (H1) | Every page should declare one H1 element to identify its primary title for screen reader users. | 7 out of 50 pages have multiple H1 elements, which confuses screen readers about the page's main topic. | ✗ FAIL |
| 3 | Verify heading hierarchy is properly structured | Headings should descend in order (H1 → H2 → H3) without skipping levels, so screen reader users can navigate the page outline. | 1 out of 50 pages skips a heading level, creating gaps in the navigation structure that confuse assistive technology. | ■ UX |
| 4 | Images declare an `alt` attributeinspected 800 images across 50 pages | Every `<img>` declares meaningful alt text (`alt=""` only for purely decorative images) | All images declare a non-empty `alt` | ✓ PASS |
| 5 | Decorative images use intentional empty altinspected 800 images | `alt=""` is reserved for purely decorative images (review each occurrence) | No images declare empty `alt=""` | ✓ PASS |
| 6 | Image resources return 2xxHEAD-checked 30 of 237 unique image srcs | Every `<img src>` resolves to a 2xx response | All 30 probed images returned 2xx | ✓ PASS |
| 7 | Verify all buttons have descriptive labels | Every button should have visible text or an aria-label so users with screen readers know what it does. | 215 buttons across 49 pages lack an accessible name. Users relying on screen readers cannot understand these buttons' purpose. | ✗ FAIL |
| 8 | Verify all links have descriptive labels | Every link should have text, an aria-label, or an image with alt text so screen readers know where it goes. | 392 links across 49 pages have no accessible name. Screen reader users cannot understand the destination or purpose of these links. | ✗ FAIL |
TS-XSS — Static XSS Surface
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Verify text inputs limit the amount of text that can be entered | Each text input should have a maxlength attribute to prevent excessively long payloads. | All 117 text inputs across 49 pages lack a maxlength attribute, leaving the site vulnerable to oversized malicious input. | ■ UX |
| 2 | Verify forms that modify data include CSRF protection | Every form that changes data should carry a hidden CSRF token to prevent unauthorized requests from other sites. | All 117 data-modifying forms lack a visible CSRF token. The site may rely on other defenses (like SameSite cookies) not detectable externally. | ✗ FAIL |
| 3 | Verify forms do not use inline event handlers | Forms should avoid onclick, onload, and similar inline handlers; instead use addEventListener. | 392 inline event handlers are present across 49 pages, making the code harder to secure and harder to maintain. | ■ UX |
| 4 | Verify links do not use javascript: URLs | Link href attributes should use proper URLs, not javascript: code execution. | 49 links use javascript: URLs across 49 pages, increasing the risk of script execution vulnerabilities. | ✗ FAIL |
TS-COOKIE — Cookies & Consent
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | No unrecognized cookies set before consenthomepage Set-Cookie · HTTP 200 | Either no cookies on first load, or only strictly-necessary / functional ones | 2 cookies set (all match strict-necessary naming) | ✓ PASS |
| 2 | Check for a cookie or privacy consent banner on the homepage | The homepage should display a consent banner or cookie notice so users can manage their privacy preferences. | No consent banner was found in the homepage HTML, which may violate privacy regulations in some jurisdictions. | ■ UX |
| 3 | Verify cookies are scoped to the site's own domain | All cookies set by the homepage should belong to the site's domain, not third parties. | Both cookies set belong to a different domain, indicating third-party tracking or analytics cookies without a visible consent mechanism. | ■ UX |
TS-PAGE — Pagination Structure
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Check for pagination on multi-page listings | If any pages list multiple items, they should include next/previous links or numbered pagination. | No pagination patterns were detected on any crawled page. | ⊘ BLOCKED |
TS-AUTHZ — Authorization Boundary
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Verify the /admin path is not publicly accessible | Attempting to access /admin should return a login redirect or error, not admin content. | The path returns a 301 redirect to https://example-coffee-shop.com/admin, indicating the site properly gates this path. | ■ UX |
| 2 | Verify the /admin/ path is not publicly accessible | Attempting to access /admin/ should return a login redirect or error, not admin content. | The path returns a 301 redirect to https://example-coffee-shop.com/admin/, indicating the site properly gates this path. | ■ UX |
| 3 | Verify the /admin.php path is not publicly accessible | Attempting to access /admin.php should return a login redirect or error, not admin content. | The path returns a 301 redirect to https://example-coffee-shop.com/admin.php, indicating the site properly gates this path. | ■ UX |
| 4 | Verify the /administrator path is not publicly accessible | Attempting to access /administrator should return a login redirect or error, not admin content. | The path returns a 301 redirect to https://example-coffee-shop.com/administrator, indicating the site properly gates this path. | ■ UX |
| 5 | Verify the /dashboard path is not publicly accessible | Attempting to access /dashboard should return a login redirect or error, not admin content. | The path returns a 301 redirect to https://example-coffee-shop.com/dashboard, indicating the site properly gates this path. | ■ UX |
| 6 | Verify the /dashboard/ path is not publicly accessible | Attempting to access /dashboard/ should return a login redirect or error, not admin content. | The path returns a 301 redirect to https://example-coffee-shop.com/dashboard/, indicating the site properly gates this path. | ■ UX |
| 7 | Verify the /wp-admin path is not publicly accessible | Attempting to access /wp-admin should return a login redirect or error, not admin content. | The path returns a 301 redirect to https://example-coffee-shop.com/wp-admin, indicating the site properly gates this path. | ■ UX |
| 8 | Verify the /api/admin path is not publicly accessible | Attempting to access /api/admin should return a login redirect or error, not admin content. | The path returns a 301 redirect to https://example-coffee-shop.com/api/admin, indicating the site properly gates this path. | ■ UX |
| 9 | Verify the /api/users path is not publicly accessible | Attempting to access /api/users should return a login redirect or error, not admin content. | The path returns a 301 redirect to https://example-coffee-shop.com/api/users, indicating the site properly gates this path. | ■ UX |
TS-RATELIMIT — Rate Limit & Duplicate Submit
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Verify forms include idempotency tokens to prevent duplicate submissions | Each data-modifying form should carry a token the server can use to detect and block duplicate requests. | None of the 117 data-modifying forms include an idempotency token, increasing the risk of accidental duplicate submissions. | ■ UX |
| 2 | Check if the server applies rate limiting to rapid requests | When sending multiple rapid requests, the server should respond with a rate-limit error or header after some threshold. | All 20 requests succeeded without any rate-limit signal, suggesting the server does not throttle rapid traffic. | ■ UX |
| 3 | Check for rate-limit headers on the login endpoint | The OPTIONS preflight response should include rate-limit or retry-after headers to hint at throttling. | The server returned a 200 OK response with no rate-limit headers, suggesting no server-side rate limiting is configured. | ■ UX |
TS-SEO — SEO & Discoverability
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Verify every page has a page title | All pages should declare a non-empty <title> for search engines and browser tabs. | 1 out of 50 pages is missing a title, which hurts search engine indexing and user experience. | ✗ FAIL |
| 2 | Verify page titles are between 10 and 60 characters | Titles should be concise enough to display fully in search results and browser tabs. | 37 out of 50 titles are too short (fewer than 10 characters), missing the opportunity to include keywords and context. | ■ UX |
| 3 | Verify every page has a meta description | All pages should include a meta description for search engines to display in results. | 32 out of 50 pages lack a meta description, reducing click-through rates from search results. | ✗ FAIL |
| 4 | Verify meta descriptions are between 50 and 160 characters | Descriptions should be long enough to convey the page's purpose but short enough to display fully in search results. | 1 out of 18 meta descriptions is out of range. | ■ UX |
| 5 | Verify every page declares a canonical URL | All pages should include a canonical link to help search engines identify the primary version. | 1 out of 50 pages is missing a canonical URL, which may confuse search engines about duplicate content. | ■ UX |
| 6 | Verify every page has Open Graph og:title metadata | Pages should declare og:title for better appearance when shared on social media. | 24 out of 50 pages lack og:title, resulting in poor social media previews. | ■ UX |
| 7 | Verify every page has Open Graph og:description metadata | Pages should declare og:description for better appearance when shared on social media. | 24 out of 50 pages lack og:description, resulting in poor social media previews. | ■ UX |
| 8 | Verify every page has Open Graph og:image metadata | Pages should declare og:image for better appearance when shared on social media. | 24 out of 50 pages lack og:image, resulting in poor social media previews. | ■ UX |
| 9 | Verify every page has a main heading (H1) | All pages should declare at least one H1 element for proper document structure and SEO. | 1 out of 50 pages is missing an H1, which harms search engine understanding of the page's purpose. | ✗ FAIL |
| 10 | robots.txt exists/robots.txt | GET `/robots.txt` returns 2xx | HTTP 200 | ✓ PASS |
| 11 | robots.txt references a Sitemapscanned response body | robots.txt body contains a `Sitemap:` directive | `Sitemap:` directive present | ✓ PASS |
| 12 | Check if a sitemap.xml file exists | The site should provide a sitemap at /sitemap.xml to help search engines discover all pages. | A sitemap.xml file was not found (HTTP 404). Search engines may miss some pages during crawling. | ■ UX |
| 13 | Verify the sitemap.xml file is valid | The sitemap should be properly formatted XML with valid structure. | This check was skipped because no sitemap.xml file is available. | ⊘ BLOCKED |
TS-SSL — SSL / TLS & Server Headers
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | HTTPS homepage reachablehttps://example-coffee-shop.com | HEAD https:// returns 2xx or 3xx | HTTP 200 | ✓ PASS |
| 2 | TLS certificate expiryCN=example-coffee-shop.com | Certificate valid for at least 30 more days | 70 days remaining (valid_to Aug 17 07:40:57 2026 GMT) | ✓ PASS |
| 3 | Verify the server redirects plain HTTP to HTTPS | Requests to http:// should redirect to the secure https:// version. | Plain HTTP requests receive a 301 redirect to https://example-coffee-shop.com/, properly enforcing encryption. | ✗ FAIL |
| 4 | Verify server headers do not disclose software version information | Response headers should omit version details to avoid exposing potential vulnerabilities. | The X-Powered-By header reveals 'PHP/8.4.21, PleskLin', giving attackers information about the server software. | ■ UX |
TS-REDIRECT — Redirect Configuration
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Verify the HTTP-to-HTTPS redirect chain is efficient | Plain HTTP should redirect to HTTPS in 1–2 hops, landing on the matching URL. | Plain HTTP redirects in 1 hop directly to https://example-coffee-shop.com/ and loads successfully. | ■ UX |
| 2 | www / apex canonicalizationcompared www.example-coffee-shop.com ↔ example-coffee-shop.com | Both entrances land on the same canonical host | www → example-coffee-shop.com, apex → example-coffee-shop.com. | ✓ PASS |
TS-META — Meta Tags & PWA Essentials
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Faviconhomepage HTML scan | `<link rel="icon">` declared in the page head. | tag present in homepage HTML | ✓ PASS |
| 2 | Apple touch iconhomepage HTML scan | `<link rel="apple-touch-icon">` declared in the page head. | tag present in homepage HTML | ✓ PASS |
| 3 | Structured data (JSON-LD)homepage HTML scan | At least one `<script type="application/ld+json">` block declaring relevant schema.org types. | tag present in homepage HTML | ✓ PASS |
| 4 | Charset declarationhomepage HTML scan | `<meta charset="utf-8">` declared at the top of `<head>`. | tag present in homepage HTML | ✓ PASS |
| 5 | Web app manifesthomepage declares <link rel="manifest"> | Either `<link rel="manifest">` referenced (and 2xx) OR `/manifest.json` / `/site.webmanifest` reachable | HTTP 200 from /site.webmanifest | ✓ PASS |
TS-IMG — Image Optimization
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Verify images use lazy loading for performance | At least 25% of images on the homepage should include loading="lazy" to defer off-screen images. | Only 3 out of 17 images (18%) use lazy loading, missing an opportunity to improve page speed. | ■ UX |
| 2 | Verify images are not excessively large | Each image should transfer no more than 500 KB to keep load times reasonable. | 4 out of 20 probed images exceed 500 KB, slowing down the page for users on slower connections. | ■ UX |
| 3 | Modern image formats (WebP / AVIF)Content-Type inspection across 20 HEAD responses | At least some image responses use modern formats (image/webp or image/avif) | 7 legacy (jpg/png), 13 modern (webp/avif). | ✓ PASS |
TS-CONSOLE — Console Errors
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Check for JavaScript errors in the browser console | The page should load without any JavaScript errors. | 26 JavaScript errors were logged across 5 different pages. These errors may break functionality or prevent features from working. | ■ UX |
| 2 | Check for the console error: %c%d font-size:<n>;color:transparent NaN | The page should not emit this console error. | This error was observed: %c%d font-size:0;color:transparent NaN. This suggests a JavaScript library or script is misbehaving. | ✗ FAIL |
| 3 | Check for the console error: Failed to load resource with status 401 | The page should not emit this console error. | This error was observed: 'Failed to load resource: the server responded with a status of 401 ()'. A resource is being requested without proper authentication. | ✗ FAIL |
| 4 | Check for the console error: Bad element for Flickity carousel | The page should not emit this console error. | This error was observed: 'Bad element for Flickity: .magaza-carousel'. The carousel library cannot find its target element, preventing it from functioning. | ■ UX |
| 5 | Check for the console error: Bad element for Flickity with null value | The page should not emit this console error. | This error was observed: 'Bad element for Flickity: null'. The carousel library is receiving a null reference, indicating a scripting error. | ■ UX |
TS-EXTLINKS — External Link Health
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Check external link https://www.instagram.com/example coffee shop/referenced from https://example-coffee-shop.com/ | External link is reachable. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 2 | Check external link https://www.facebook.com/Example Coffee Shopreferenced from https://example-coffee-shop.com/ | External link is reachable. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 3 | Check external link https://www.youtube.com/channel/UCCcZU6Jtcn5Fd5Ns4Bs-jmgreferenced from https://example-coffee-shop.com/ | External link is reachable. | Link resolves correctly (HTTP 200). | ✓ PASS |
| 4 | Check external link https://twitter.com/Example Coffee ShopCoffeereferenced from https://example-coffee-shop.com/ | External link is reachable. | Link redirects (HTTP 301). | ✓ PASS |
| 5 | Check if an external URL is reachable: https://etbis.eticaret.gov.tr/sitedogrulama/... | The external link should respond with a success, redirect, or authentication error. | The request failed after 3.37 seconds with a network error. The external site may be down, blocked, or unreachable. | ✗ FAIL |
| 6 | Check external link https://maps.app.goo.gl/pdt5cwA1UhYPxAcA9"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 7 | Check external link https://goo.gl/maps/L43WnbVwQKpt2Atv8"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 8 | Check external link https://maps.app.goo.gl/acMLfhUUgSGunUkU6"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 9 | Check external link https://goo.gl/maps/RfCQBPD7ymxDpt5H9"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 10 | Check external link https://maps.app.goo.gl/kqNwPRnkWn5MiAWJ8"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 11 | Check external link https://goo.gl/maps/yoFXMSSMCnedN2Qv5"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 12 | Check external link https://goo.gl/maps/w8JurPsAmL8cvmwB8"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 13 | Check external link https://goo.gl/maps/ZKAE2fVeF1qgPX4D9"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 14 | Check external link https://maps.app.goo.gl/6o5fkoNQGnGhCms97"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 15 | Check external link https://goo.gl/maps/ReHT9JuVw9V9gYzX6"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 16 | Check external link https://maps.app.goo.gl/VhDZzxn7KZ4Ra8v79"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 17 | Check external link https://goo.gl/maps/YzpQ4YBdTTvHcJwk7"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 18 | Check external link https://maps.app.goo.gl/GD9vA6Fq799Cz9L97"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 19 | Check external link https://maps.app.goo.gl/tVRivvSJntirrkNY9"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 20 | Check external link https://maps.app.goo.gl/D3nsjdXydf2BvUYg8"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 21 | Check external link https://maps.app.goo.gl/wR9yC4R14aprZujDA"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 22 | Check external link https://goo.gl/maps/q4TgzkL7idmjxas9A"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 23 | Check external link https://maps.app.goo.gl/36HoSUuraDWpTCmF7"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 24 | Check external link https://maps.app.goo.gl/cQprdqUAKdSmhZdj7"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 25 | Check external link https://maps.app.goo.gl/WZPp32knn4vdrzb26"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 26 | Check external link https://goo.gl/maps/yAeVDP3LyockR5jn6"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 27 | Check external link https://goo.gl/maps/wLAUevfzdTk3WbBf7"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 28 | Check external link https://maps.app.goo.gl/DYQmcD5ngHF2uFJK7"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 29 | Check external link https://maps.app.goo.gl/hphAb25tjJkWead16"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 30 | Check external link https://maps.app.goo.gl/UD6xJURvjVLb1rtm7"Haritada Gör" | External link is reachable. | Link redirects (HTTP 302). | ✓ PASS |
| 31 | Check remaining external links for reachability | n/a (probe has a limit on external links checked) | 16 additional external URLs were not probed due to capacity limits. | ■ UX |
TS-OPENREDIR — Open Redirect Surface
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Test if the ?redirect parameter can be used for open redirects | The server should ignore or strip external redirect targets to prevent hijacking users. | The server returns a 301 redirect with the parameter intact, though it remains on the same domain. This is safer than a true open redirect. | ■ UX |
| 2 | Test if the ?next parameter can be used for open redirects | The server should ignore or strip external redirect targets to prevent hijacking users. | The server returns a 301 redirect with the parameter intact, though it remains on the same domain. This is safer than a true open redirect. | ■ UX |
| 3 | Test if the ?url parameter can be used for open redirects | The server should ignore or strip external redirect targets to prevent hijacking users. | The server returns a 301 redirect with the parameter intact, though it remains on the same domain. This is safer than a true open redirect. | ■ UX |
| 4 | Test if the ?return parameter can be used for open redirects | The server should ignore or strip external redirect targets to prevent hijacking users. | The server returns a 301 redirect with the parameter intact, though it remains on the same domain. This is safer than a true open redirect. | ■ UX |
| 5 | Test if the ?returnUrl parameter can be used for open redirects | The server should ignore or strip external redirect targets to prevent hijacking users. | The server returns a 301 redirect with the parameter intact, though it remains on the same domain. This is safer than a true open redirect. | ■ UX |
TS-AUTH — Authentication Form Structure
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Login form discoveredpage: https://example-coffee-shop.com/kullanici/kaydol | Authentication form found via password input / login path | form @ https://example-coffee-shop.com/kullanici/kaydol (method POST) | ✓ PASS |
| 2 | Form action uses HTTPShttps://example-coffee-shop.com/kullanici/kaydol | Login form posts to an https:// URL | https:// action confirmed | ✓ PASS |
| 3 | Form method is POST (not GET)GET would leak credentials via URL IF the submit isn't JS-intercepted to a real POST | Form method=POST | method=POST confirmed | ✓ PASS |
| 4 | Verify the password field includes autocomplete guidance | Password inputs should declare autocomplete="current-password" to enable browser password managers. | The password field lacks an autocomplete attribute, preventing password managers from working correctly. | ■ UX |
| 5 | Verify the username field includes autocomplete guidance | Username inputs should declare autocomplete="username" to enable browser password managers. | The username field lacks an autocomplete attribute, preventing password managers from working correctly. | ■ UX |
| 6 | Verify a password-reset link is visible on the login page | Users should be able to find a 'Forgot password' or similar link if they cannot sign in. | No password-reset link was found on the login page, making it difficult for users who forget their credentials. | ■ UX |
| 7 | Verify the password field limits input length | Password inputs should declare a maxlength attribute (typically 64 or more) to prevent excessively long inputs. | The password field lacks a maxlength attribute, leaving it vulnerable to very long or malicious payloads. | ■ UX |
| 8 | Verify the login form includes CSRF protection | The form should carry a hidden CSRF token, or the server may use other defenses (like SameSite cookies). | No visible CSRF token field was found in the login form. The site may rely on other defenses not externally observable. | ✗ FAIL |
| 9 | Empty email + empty passwordsubmitted to https://example-coffee-shop.com/kullanici/kaydol | Form rejects the submission (URL unchanged OR password field still visible OR visible error) | URL unchanged, password input still visible. | ✓ PASS |
| 10 | Valid-format email + empty passwordsubmitted to https://example-coffee-shop.com/kullanici/kaydol | Form rejects the submission (URL unchanged OR password field still visible OR visible error) | URL unchanged, password input still visible. | ✓ PASS |
| 11 | Empty email + filled passwordsubmitted to https://example-coffee-shop.com/kullanici/kaydol | Form rejects the submission (URL unchanged OR password field still visible OR visible error) | URL unchanged, password input still visible. | ✓ PASS |
| 12 | Email without `@`submitted to https://example-coffee-shop.com/kullanici/kaydol | Form rejects the submission (URL unchanged OR password field still visible OR visible error) | URL unchanged, password input still visible. | ✓ PASS |
| 13 | 1-character passwordsubmitted to https://example-coffee-shop.com/kullanici/kaydol | Form rejects the submission (URL unchanged OR password field still visible OR visible error) | URL unchanged, password input still visible. | ✓ PASS |
| 14 | 200-character password (graceful handling)submitted to https://example-coffee-shop.com/kullanici/kaydol | Form rejects the submission (URL unchanged OR password field still visible OR visible error) | URL unchanged, password input still visible. | ✓ PASS |
| 15 | SQL-injection payload in emailsubmitted to https://example-coffee-shop.com/kullanici/kaydol | Form rejects the submission (URL unchanged OR password field still visible OR visible error) | URL unchanged, password input still visible. | ✓ PASS |
| 16 | XSS payload in emailsubmitted to https://example-coffee-shop.com/kullanici/kaydol | Form rejects the submission (URL unchanged OR password field still visible OR visible error) | URL unchanged, password input still visible. | ✓ PASS |
| 17 | Wrong email + wrong passwordsubmitted to https://example-coffee-shop.com/kullanici/kaydol | Form rejects the submission (URL unchanged OR password field still visible OR visible error) | URL unchanged, password input still visible. | ✓ PASS |
| 18 | Check for user-enumeration vulnerabilities in login error messages | This test requires a real test account email for comparison. | This test was skipped because no test account email was provided. | ⊘ BLOCKED |
| 19 | Verify the password field includes a visibility toggle | Users should be able to toggle between masked and visible password text for better usability. | No password visibility toggle button was found, forcing users to type blindly. | ■ UX |
| 20 | Verify a 'remember me' checkbox is available | Users should be offered a 'remember me' or 'stay signed in' option for convenience. | No remember-me checkbox was found on the login page. | ■ UX |
| 21 | Check if the password-reset link is reachable | The password-reset link should point to a valid page. | No password-reset link was discovered on the page, so this check could not be completed. | ⊘ BLOCKED |
| 22 | Register form requires email + password + confirm-passwordpage: https://example-coffee-shop.com/kullanici/kaydol | Form contains an email input, a password input, and a second password (confirm) input | all three required fields present | ✓ PASS |
| 23 | Verify a password strength indicator is displayed near the password input | Users should see feedback about password strength (weak, medium, strong) or a list of requirements. | No password strength meter or requirement list was found, leaving users uncertain about acceptable passwords. | ■ UX |
| 24 | Verify the registration form requires acceptance of terms and privacy | A checkbox should require users to explicitly agree to the site's terms and privacy policy. | No terms or privacy checkbox was found on the registration form, which may violate data protection regulations. | ■ UX |
TS-API — API Responses
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | API responses return 2xx/3xx4 XHR/fetch responses on https://example-coffee-shop.com/ | All API responses return 2xx / 3xx | All 4 responses 2xx/3xx | ✓ PASS |
| 2 | API responses under 2s4 XHR/fetch responses | Every API response completes in ≤ 2000 ms | All responses under threshold | ✓ PASS |
| 3 | Verify API responses declare a Content-Type header | All API responses should include a Content-Type header so clients know how to parse the data. | 3 API responses lack a Content-Type header, which may confuse API clients about the response format. | ■ UX |
| 4 | API response bodies do not expose stack traces4 XHR/fetch responses | Response bodies never contain server stack traces / debug error details | No stack traces detected in response bodies | ✓ PASS |
TS-ERR — Error Page & 404 Handling
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | GET /xyzshort nonsense path | HTTP 4xx response · branded error page consistent with site chrome | HTTP 404, branded, 0.65 s. | ✓ PASS |
| 2 | GET /__qa_explorer_404_probe_*opaque randomized path | HTTP 4xx response · branded error page consistent with site chrome | HTTP 404, branded, 0.50 s. | ✓ PASS |
| 3 | Load the search page with an invalid query parameter | The page should return a 4xx error with branded site styling consistent with the rest of the site. | The page returned HTTP 403 with generic error styling, not matching the site's design. This confuses users about whether it is a site error or a real access denial. | ✗ FAIL |
| 4 | Request a very long URL path to test error handling | The page should return a 4xx error with branded site styling consistent with the rest of the site. | The page returned HTTP 403 with generic error styling, not matching the site's design. This confuses users about whether it is a site error or a real access denial. | ✗ FAIL |
| 5 | GET /test'<sql-payload>SQL-injection-style path | HTTP 4xx response · branded error page consistent with site chrome | HTTP 404, branded, 0.29 s. | ✓ PASS |
TS-FORM — Form Validation Tests
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Form #1: POST https://example-coffee-shop.com/ebultenempty submit test | Submission blocked or error message shown | 1 input(s) flagged as invalid, browser message: "Please fill out this field.". | ✓ PASS |
| 2 | Form #1: POST https://example-coffee-shop.com/ebulteninvalid email format test | Browser rejected the invalid email format (HTML5 :invalid or visible error) | 1 input(s) flagged as invalid, browser message: "Please include an '@' in the email address. 'not-an-email' is missing an '@'.". | ✓ PASS |
| 3 | Submit an empty form at POST https://example-coffee-shop.com/alisveris/ara | The form should validate and show an error message, or prevent submission if required fields are empty. | The empty form submitted without triggering client-side validation or showing any error, allowing invalid data to be sent. | ■ UX |
| 4 | Form #3: POST https://example-coffee-shop.com/sepet/ekleempty submit test | Submission blocked or error message shown | 4 input(s) flagged as invalid, browser message: "Please select an item in the list.". | ✓ PASS |
| 5 | Form #4: POST https://example-coffee-shop.com/kullanici/kaydolempty submit test | Submission blocked or error message shown | 6 input(s) flagged as invalid, browser message: "Please fill out this field.". | ✓ PASS |
| 6 | Form #4: POST https://example-coffee-shop.com/kullanici/kaydolinvalid email format test | Browser rejected the invalid email format (HTML5 :invalid or visible error) | 6 input(s) flagged as invalid, browser message: "Please fill out this field.". | ✓ PASS |
| 7 | Form #5: POST https://example-coffee-shop.com/kullanici/oturumacempty submit test | Submission blocked or error message shown | 2 input(s) flagged as invalid, browser message: "Please fill out this field.". | ✓ PASS |
| 8 | Form #5: POST https://example-coffee-shop.com/kullanici/oturumacinvalid email format test | Browser rejected the invalid email format (HTML5 :invalid or visible error) | 2 input(s) flagged as invalid, browser message: "Please include an '@' in the email address. 'not-an-email' is missing an '@'.". | ✓ PASS |
| 9 | Form #6: POST https://example-coffee-shop.com/iletisimempty submit test | Submission blocked or error message shown | 5 input(s) flagged as invalid, browser message: "Please fill out this field.". | ✓ PASS |
| 10 | Form #6: POST https://example-coffee-shop.com/iletisiminvalid email format test | Browser rejected the invalid email format (HTML5 :invalid or visible error) | 5 input(s) flagged as invalid, browser message: "Please fill out this field.". | ✓ PASS |
TS-CTA — Primary CTA Tests
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Click button "Sign Up"click navigates to destination | CTA produces a navigation, modal, or DOM update | Navigated to https://example-coffee-shop.com/kullanici/kaydol (HTTP 200) | ✓ PASS |
| 2 | Click button "Login"click navigates to destination | CTA produces a navigation, modal, or DOM update | Navigated to https://example-coffee-shop.com/kullanici/oturumac (HTTP 200) | ✓ PASS |
| 3 | Click button "Subscribe"click updates page content in place | CTA produces a navigation, modal, or DOM update | Document text length changed by 254 chars (SPA / in-place update) | ✓ PASS |
| 4 | Click link "Sign Up" → /kullanici/kaydolclick navigates to destination | CTA produces a navigation, modal, or DOM update | Navigated to https://example-coffee-shop.com/kullanici/kaydol (HTTP 200) | ✓ PASS |
| 5 | Click link "Login" → /kullanici/oturumacclick navigates to destination | CTA produces a navigation, modal, or DOM update | Navigated to https://example-coffee-shop.com/kullanici/oturumac (HTTP 200) | ✓ PASS |
| 6 | Click link "Add to Cart" → /alisverisclick navigates to destination | CTA produces a navigation, modal, or DOM update | Navigated to https://example-coffee-shop.com/alisveris (HTTP 200) | ✓ PASS |
| 7 | Click link "Contact Us" → /iletisimclick navigates to destination | CTA produces a navigation, modal, or DOM update | Navigated to https://example-coffee-shop.com/iletisim (HTTP 200) | ✓ PASS |
| 8 | Attempt to click the 'Buy' link pointing to /odeme | Clicking should navigate to the target page or trigger an action. | This link was not clicked because the text 'Buy' matches a destructive action blocklist, preventing accidental activation during automated testing. | ⊘ BLOCKED |
| 9 | Click link "Add to Cart" → …s/urun/Hario-v60-Dripper-seticlick navigates to destination | CTA produces a navigation, modal, or DOM update | Navigated to https://example-coffee-shop.com/alisveris (HTTP 200) | ✓ PASS |
| 10 | Click link "Add to Cart" → /alisveris/urun/cezveclick navigates to destination | CTA produces a navigation, modal, or DOM update | Navigated to https://example-coffee-shop.com/alisveris (HTTP 200) | ✓ PASS |
TS-SEARCH — Search Behavior
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Discover and exercise the site search functionality | At least one search form should be available on the site to test search behavior. | No search form was found on any crawled page, so search functionality could not be tested. | ⊘ BLOCKED |
TS-ERROR — Error & Resilience Handling
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Check if a service worker is registered | Optional — a service worker enables offline caching and improves resilience. | No service worker is registered. Offline functionality and caching are not available. | ■ UX |
| 2 | Test the page's behavior when the network is offline | A gracefully designed site should show a cached or branded offline page, not a generic browser error. | The page failed to load offline with a network error (net::ERR_INTERNET_DISCONNECTED). No offline experience is provided. | ✗ FAIL |
| 3 | Check if a loading indicator appears during slow navigation | Users should see visual feedback (spinner, progress bar) while content is loading. | No loading indicator was detected during navigation, leaving users unsure if the page is responding. | ■ UX |
TS-PERF — Performance & Core Web Vitals
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | FCP · / | ≤1.8s good · ≤3.0s needs improvement | 1.52s | ✓ PASS |
| 2 | LCP · / | ≤2.5s good · ≤4.0s needs improvement | 1.52s | ✓ PASS |
| 3 | CLS · / | ≤0.1 good · ≤0.25 needs improvement | 0.011 | ✓ PASS |
| 4 | DOM · / | ≤1500 elements good · ≤3000 needs improvement | 470 elements | ✓ PASS |
| 5 | Measure the total page weight of the homepage | The homepage should load in 3 MB or less (good), or at most 5 MB (needs improvement). | The homepage is 4.81 MB, which needs improvement. Optimize images, minify code, or defer non-critical resources. | ■ UX |
| 6 | FCP · /demleme-teknik/french-press | ≤1.8s good · ≤3.0s needs improvement | 1.58s | ✓ PASS |
| 7 | LCP · /demleme-teknik/french-press | ≤2.5s good · ≤4.0s needs improvement | 1.58s | ✓ PASS |
| 8 | CLS · /demleme-teknik/french-press | ≤0.1 good · ≤0.25 needs improvement | 0.017 | ✓ PASS |
| 9 | DOM · /demleme-teknik/french-press | ≤1500 elements good · ≤3000 needs improvement | 389 elements | ✓ PASS |
| 10 | Weight · /demleme-teknik/french-press31 resources | ≤3 MB good · ≤5 MB needs improvement | 0.72 MB | ✓ PASS |
| 11 | FCP · /iletisim | ≤1.8s good · ≤3.0s needs improvement | 1.45s | ✓ PASS |
| 12 | LCP · /iletisim | ≤2.5s good · ≤4.0s needs improvement | 1.87s | ✓ PASS |
| 13 | CLS · /iletisim | ≤0.1 good · ≤0.25 needs improvement | 0.028 | ✓ PASS |
| 14 | DOM · /iletisim | ≤1500 elements good · ≤3000 needs improvement | 360 elements | ✓ PASS |
| 15 | Weight · /iletisim32 resources | ≤3 MB good · ≤5 MB needs improvement | 0.75 MB | ✓ PASS |
| 16 | FCP · /aydinlatma | ≤1.8s good · ≤3.0s needs improvement | 1.50s | ✓ PASS |
| 17 | LCP · /aydinlatma | ≤2.5s good · ≤4.0s needs improvement | 1.75s | ✓ PASS |
| 18 | CLS · /aydinlatma | ≤0.1 good · ≤0.25 needs improvement | 0.041 | ✓ PASS |
| 19 | DOM · /aydinlatma | ≤1500 elements good · ≤3000 needs improvement | 445 elements | ✓ PASS |
| 20 | Weight · /aydinlatma30 resources | ≤3 MB good · ≤5 MB needs improvement | 0.72 MB | ✓ PASS |
| 21 | FCP · /alisveris/urun/kenya-kirinyaga | ≤1.8s good · ≤3.0s needs improvement | 1.40s | ✓ PASS |
| 22 | LCP · /alisveris/urun/kenya-kirinyaga | ≤2.5s good · ≤4.0s needs improvement | 1.95s | ✓ PASS |
| 23 | CLS · /alisveris/urun/kenya-kirinyaga | ≤0.1 good · ≤0.25 needs improvement | 0.024 | ✓ PASS |
| 24 | DOM · /alisveris/urun/kenya-kirinyaga | ≤1500 elements good · ≤3000 needs improvement | 486 elements | ✓ PASS |
| 25 | Measure the total page weight of the product detail page | Product pages should load in 3 MB or less (good), or at most 5 MB (needs improvement). | The product page is 3.40 MB, which is acceptable but could be further optimized. | ■ UX |
TS-RESPONSIVE — Responsive Layout Checks
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Check the homepage layout on a mobile phone (375×812 pixels) | The page should not overflow horizontally, text should not be clipped, and buttons should be at least 44 pixels for easy tapping. | The page fits without overflow, but 1 element is clipped, and 31 out of 45 touch targets are too small (<44 pixels), making them hard to tap on mobile. | ■ UX |
| 2 | Check the homepage layout on a tablet (768×1024 pixels) | The page should not overflow horizontally and text should not be clipped. | The page fits without overflow, but 1 element is clipped. Text and layout are otherwise acceptable for tablet viewing. | ■ UX |
| 3 | / · Desktop (1440×900)checks: overflow · clipping | No horizontal overflow · no clipped text | no horizontal overflow · 1 clipped element | ■ UX |
| 4 | /iletisim · Mobile (375×812)checks: overflow · clipping · touch targets | No horizontal overflow · no clipped text · touch targets ≥44px | no horizontal overflow · 33 of 40 touch targets <44px | ■ UX |
| 5 | /iletisim · Tablet (768×1024)checks: overflow · clipping | The Iletisim page should render correctly at tablet width with no horizontal overflow or clipped text. | no horizontal overflow | ✓ PASS |
| 6 | /iletisim · Desktop (1440×900)checks: overflow · clipping | The Iletisim page should render correctly at desktop width with no horizontal overflow or clipped text. | no horizontal overflow | ✓ PASS |
| 7 | /alisveris/urun/kenya-kirinyaga · Mobile (375×812)checks: overflow · clipping · touch targets | No horizontal overflow · no clipped text · touch targets ≥44px | no horizontal overflow · 36 of 44 touch targets <44px | ■ UX |
| 8 | /alisveris/urun/kenya-kirinyaga · Tablet (768×1024)checks: overflow · clipping | The Kenya Kirinyaga page should render correctly at tablet width with no horizontal overflow or clipped text. | no horizontal overflow | ✓ PASS |
| 9 | /alisveris/urun/kenya-kirinyaga · Desktop (1440×900)checks: overflow · clipping | The Kenya Kirinyaga page should render correctly at desktop width with no horizontal overflow or clipped text. | no horizontal overflow | ✓ PASS |
| 10 | Viewport meta tagcaptured once on the first sample page | `<meta name="viewport" content="width=device-width, ...">` | Present, width=device-width, initial-scale=1.0. | ✓ PASS |
TS-STATE — State & Navigation
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Deep-link navigation to inner pagehttps://example-coffee-shop.com/alisveris | Direct GET on the inner URL renders content | Loaded, HTTP 200, body length 6786. | ✓ PASS |
| 2 | Browser back returns to a working previous pagehttps://example-coffee-shop.com/ → https://example-coffee-shop.com/alisveris → back | Going back re-renders the previous page (no blank / error screen) | Back, HTTP 200, body length 1716. | ✓ PASS |
| 3 | Page reload renders cleanlyhttps://example-coffee-shop.com/alisveris | Reload renders the page without errors | Reloaded, HTTP 200, body length 6786. | ✓ PASS |
| 4 | Inner pages have unique meaningful URLsinspected first 5 inner pages | Each inner page has its own path-based URL (not just a `#` fragment on the homepage) | All 5 URLs unique | ✓ PASS |
TS-CONTRAST — Color Contrast (WCAG 2.1)
| # | Test Step | Expected Result | Actual Result | Status |
|---|---|---|---|---|
| 1 | Color contrast · /sampled 31 text elements | Every sampled text element meets WCAG 2.1 contrast (≥ 4.5 normal · ≥ 3 large) | 2 of 31 sampled elements fall below threshold | ✗ FAIL |
| 2 | Color contrast · /iletisimsampled 23 text elements | Every sampled text element meets WCAG 2.1 contrast (≥ 4.5 normal · ≥ 3 large) | 1 of 23 sampled elements fall below threshold | ✗ FAIL |
| 3 | Color contrast · /alisveris/urun/kenya-kirinyagasampled 30 text elements | Every sampled text element meets WCAG 2.1 contrast (≥ 4.5 normal · ≥ 3 large) | 1 of 30 sampled elements fall below threshold | ✗ FAIL |
4Bug Summary Matrix
A consolidated dashboard view of every unique finding from this scan. Detailed entries follow in the next section.
| ID | Title | Severity | Priority | Status |
|---|---|---|---|---|
| BUG-001 | Color contrast failures (site-wide) | High | P1 | • New |
| BUG-002 | Form input missing accessible label | High | P1 | • New |
| BUG-003 | Pervasive missing accessible names on interactive elements site-wide | High | P1 | • New |
| BUG-004 | Internal link unreachable | High | P1 | • New |
| BUG-005 | Legal compliance failure: no cookie consent and broken KVKK document | High | P1 | • New |
| BUG-006 | Cookie missing HttpOnly flag | High | P1 | • New |
| BUG-007 | HTTP requests are not redirected to HTTPS | High | P1 | • New |
| BUG-008 | javascript: href links and inline handlers create XSS attack surface | High | P1 | • New |
| BUG-009 | Form fields rely | Medium | P2 | • New |
| BUG-010 | Missing language attribute on HTML element | Medium | P2 | • New |
| BUG-011 | Multiple form inputs missing accessible labels | Medium | P2 | • New |
| BUG-012 | Multiple h1 elements and skipped heading levels weaken document structure | Medium | P2 | • New |
| BUG-013 | Multiple primary headings on page | Medium | P2 | • New |
| BUG-014 | Unlabeled buttons | Medium | P2 | • New |
| BUG-015 | Unlabeled links | Medium | P2 | • New |
| BUG-016 | API responses missing Content-Type header | Medium | P2 | • New |
| BUG-017 | External link unreachable | Medium | P2 | • New |
| BUG-018 | Failed resource loading errors in console | Medium | P2 | • New |
| BUG-019 | Form accepts empty submission | Medium | P2 | • New |
| BUG-020 | JavaScript console errors detected | Medium | P2 | • New |
| BUG-021 | No offline or cached state | Medium | P2 | • New |
| BUG-022 | Heavy page weight and low lazy-load adoption degrade mobile performance | Medium | P2 | • New |
| BUG-023 | JavaScript URLs in links | Medium | P2 | • New |
| BUG-024 | Missing Content-Security-Policy header | Medium | P2 | • New |
| BUG-025 | No cookie consent banner detected | Medium | P2 | • New |
| BUG-026 | Server software details publicly visible | Medium | P2 | • New |
| BUG-027 | Text inputs without character limits | Medium | P2 | • New |
| BUG-028 | Third-party cookies set on page load | Medium | P2 | • New |
| BUG-029 | Missing page title | Medium | P2 | • New |
| BUG-030 | Missing SEO metadata | Medium | P2 | • New |
| BUG-031 | Unbranded 403 responses replace expected 404 handling for unknown URLs | Medium | P2 | • New |
| BUG-032 | Inconsistent heading structure | Low | P3 | • New |
| BUG-033 | Carousel library error in console | Low | P3 | • New |
| BUG-034 | Carousel library null reference error | Low | P3 | • New |
| BUG-035 | No offline support (service worker not registered) | Low | P3 | • New |
| BUG-036 | Heavy page weight (4.81 MB) | Low | P3 | • New |
| BUG-037 | Images not using native lazy-loading | Low | P3 | • New |
| BUG-038 | Oversized image (532 KB) | Low | P3 | • New |
| BUG-039 | Forms lack duplicate-submission prevention | Low | P3 | • New |
| BUG-040 | Forms may lack cross-site forgery protection | Low | P3 | • New |
| BUG-041 | Inline event handlers in HTML | Low | P3 | • New |
| BUG-042 | Login endpoint shows no rate-limit protection signal | Low | P3 | • New |
| BUG-043 | No 'remember me' option on login | Low | P3 | • New |
| BUG-044 | No password reset link on login page | Low | P3 | • New |
| BUG-045 | No password visibility toggle | Low | P3 | • New |
| BUG-046 | No rate-limiting visible on homepage | Low | P3 | • New |
| BUG-047 | Password field missing autocomplete attribute | Low | P3 | • New |
| BUG-048 | Password field missing maxlength attribute | Low | P3 | • New |
| BUG-049 | Potential CSRF gap on state-changing forms (unverified) | Low | P3 | • New |
| BUG-050 | Username field missing autocomplete attribute | Low | P3 | • New |
| BUG-051 | Content clipped at desktop viewport (1440px) | Low | P3 | • New |
| BUG-052 | Content clipped at mobile viewport (375px) | Low | P3 | • New |
| BUG-053 | Content clipped at tablet viewport (768px) | Low | P3 | • New |
| BUG-054 | Missing main heading | Low | P3 | • New |
| BUG-055 | Page titles too short for search results | Low | P3 | • New |
| BUG-056 | Registration form lacks password strength indicator | Low | P3 | • New |
| BUG-057 | Registration form missing terms acceptance checkbox | Low | P3 | • New |
| BUG-058 | Sitemap not found | Low | P3 | • New |
| BUG-059 | Undersized touch targets on mobile | Low | P3 | • New |
5Detailed Bug Reports
Each finding's BUG-NNN identifier matches its row in the Bug Summary Matrix.
BUG-001
Color contrast failures (site-wide)
High
P1
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in DevTools → Inspect
- Locate the element matching `label.transition-all.peer-placeholder-shown:text-base`
- In the Styles pane, hover the computed `color` value — DevTools renders the live contrast ratio
- Adjust either color (typically darkening the foreground) until the ratio clears the threshold
Expected Result
Text should have a contrast ratio of at least 4.5:1.
Actual Result
Text "E-Bülten" (selector label.transition-all.peer-placeholder-shown:text-base) on https://example-coffee-shop.com/ has contrast 1.90:1 (RGB 156,163,175 on RGB 227,222,215).
BUG-002
Form input missing accessible label
High
P1
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in a browser
- Open DevTools → Accessibility tree
- Inspect each interactive input — its accessible name should be the field's purpose, not 'edit text'
Expected Result
Every form input should have an associated label.
Actual Result
1 input on the search form (action="https://example-coffee-shop.com/alisveris/ara", method=POST) has no associated label.
BUG-003
Pervasive missing accessible names on interactive elements site-wide
High
P1
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Navigate to https://example-coffee-shop.com/ with a screen reader (e.g. NVDA + Chrome).
- Tab through interactive elements — most buttons and icon links are announced as 'button' or 'link' with no descriptive label.
- Run an automated accessibility checker (axe, Lighthouse) — it will flag all unlabelled controls and contrast failures simultaneously.
Expected Result
All interactive elements should carry descriptive accessible names (visible text or aria-label), colour contrast should meet WCAG 2.1 AA (4.5:1 for normal text), and every HTML document should declare a valid lang attribute.
Actual Result
TS-A11Y: 215 buttons without accessible names, 392 links without accessible names across 49 pages. TS-CONTRAST: contrast failures on /, /iletisim, and /alisveris/urun/kenya-kirinyaga. TS-A11Y: 1 page missing lang attribute.
BUG-004
Internal link unreachable
High
P1
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in a browser
- Click the link to https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf
- Observe no response
Expected Result
All internal links should respond successfully (HTTP 200 or redirect to a working page).
Actual Result
https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf → no response. First referenced from https://example-coffee-shop.com/. Also linked from https://example-coffee-shop.com/alisveris, https://example-coffee-shop.com/alisveris/kategori/kahveler, https://example-coffee-shop.com/alisveris/kategori/ekipmanlar (and 45 more).
BUG-005
Legal compliance failure: no cookie consent and broken KVKK document
High
P1
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Load https://example-coffee-shop.com/ in a clean browser profile with no prior cookies.
- Observe that no cookie consent banner appears but third-party cookies are already set (visible in DevTools > Application > Cookies).
- Click the KVKK başvuru link anywhere on the site — browser shows a network error / blank page.
- Confirm via curl: curl -I https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf returns no response.
Expected Result
A cookie consent mechanism must gate third-party cookie setting until explicit user consent. The KVKK başvuru PDF must be reachable at its published URL.
Actual Result
TS-COOKIE: no consent banner found in homepage HTML; 2 of 2 cookies are third-party domain. TS-NAV + TS-LINKS: /pdf/kvkk_basvuru.pdf returns no HTTP response.
BUG-006
Cookie missing HttpOnly flag
High
P1
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- curl -I 'https://example-coffee-shop.com/'
- Locate the 'Set-Cookie' response header for the cookie named "XSRF-TOKEN"
- Confirm the HttpOnly flag is absent
Expected Result
Set-Cookie should include the HttpOnly flag (for example: Set-Cookie: session=...; HttpOnly; Secure; SameSite=Lax).
Actual Result
Cookie "XSRF-TOKEN" observed on https://example-coffee-shop.com/ is missing the HttpOnly flag.
BUG-007
HTTP requests are not redirected to HTTPS
High
P1
• New
http://example-coffee-shop.com (Desktop + Mobile)
Steps to Reproduce
- curl -sI 'http://example-coffee-shop.com/' | head -20
- Confirm the first response is a 3xx redirect whose Location starts with https://
- Update the web server / CDN to force-redirect HTTP traffic to HTTPS
Expected Result
HTTP requests should redirect to HTTPS using a 301, 302, 307, or 308 response.
Actual Result
HTTP 301 redirect to https://example-coffee-shop.com/ is working correctly.
BUG-008
javascript: href links and inline handlers create XSS attack surface
High
P1
• New
https://example-coffee-shop.com/ (Desktop)
Steps to Reproduce
- Open any page, e.g. https://example-coffee-shop.com/ and inspect anchor tags in DevTools.
- Search for href="javascript: — 49 instances exist.
- Search for onclick= — hundreds of inline handlers visible in source.
- Check response headers — no Content-Security-Policy header present to restrict script sources.
Expected Result
No javascript: href links; event handlers should be bound via addEventListener in external scripts. A CSP header should restrict script execution to trusted sources.
Actual Result
TS-XSS: 49 javascript: links and 392 inline handlers across 49 pages. TS-SEC: CSP header not set. The two findings are mutually reinforcing — removing CSP-unsafe-inline would break the inline handlers, revealing that neither can be fixed independently.
BUG-009
Form fields rely
Medium
P2
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Focus into a form field on https://example-coffee-shop.com/
- Observe that the previously-visible hint disappears
- Inspect the DOM and confirm the element is a placeholder attribute, not a `<label>`
Expected Result
Each form input should have a persistent <label>, with placeholder as an optional supplement.
Actual Result
1 input on the search form (action="https://example-coffee-shop.com/alisveris/ara", method=POST) relies solely on placeholder text.
BUG-010
Missing language attribute on HTML element
Medium
P2
• New
https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf in DevTools → Elements tab
- Inspect the `<html>` element
- Confirm no `lang` attribute is present
- Add `lang="<bcp47-code>"` to the `<html>` element in the template
Expected Result
The <html> element should include a lang attribute (for example: <html lang="en"> or <html lang="tr">).
Actual Result
Language attribute missing or empty on 1 of 50 crawled pages.
BUG-011
Multiple form inputs missing accessible labels
Medium
P2
• New
https://example-coffee-shop.com/iletisim (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/iletisim in a browser
- Open DevTools → Accessibility tree
- Inspect each interactive input — its accessible name should be the field's purpose, not 'edit text'
Expected Result
Every form input should have an associated label.
Actual Result
2 of 5 inputs on the contact form (action="https://example-coffee-shop.com/iletisim", method=POST) have no associated label.
BUG-012
Multiple h1 elements and skipped heading levels weaken document structure
Medium
P2
• New
https://example-coffee-shop.com/ (Desktop)
Steps to Reproduce
- Open https://example-coffee-shop.com/ and run document.querySelectorAll('h1') in the console — multiple results returned.
- Use a browser accessibility tree inspector to review heading outline — multiple top-level headings with no clear primary topic heading.
Expected Result
Each page should have exactly one <h1> that represents the primary page topic, with subsequent content using h2–h6 in logical, non-skipping order.
Actual Result
TS-A11Y reports 7 pages with multiple <h1> elements and 1 page with a skipped heading level. DOM summary for / shows 23 heading elements, indicating heavily fragmented heading use.
BUG-013
Multiple primary headings on page
Medium
P2
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in DevTools → Elements tab
- Search the DOM for `h1` elements
- Confirm 4 <h1> elements are present
- Promote one as the page title; demote the rest to <h2>
Expected Result
Each page should have exactly one <h1> element.
Actual Result
7 of 50 crawled pages contain multiple <h1> elements (for example, 4 on https://example-coffee-shop.com/).
BUG-014
Unlabeled buttons
Medium
P2
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in DevTools → Elements tab
- Run `[...document.querySelectorAll('button')].filter(b => !b.innerText.trim() && !b.getAttribute('aria-label'))` in Console
- Add an `aria-label` describing the action to each match
Expected Result
Each button should have a name, either through visible text or an aria-label attribute.
Actual Result
215 of 850 buttons across 49 pages have neither text nor aria-label.
BUG-015
Unlabeled links
Medium
P2
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in DevTools → Elements tab
- Run `[...document.querySelectorAll('a[href]')].filter(a => !a.innerText.trim() && !a.getAttribute('aria-label') && !a.querySelector('img[alt]'))` in Console
- Add visible text, `aria-label`, or an inner `<img alt>` to each match
Expected Result
Each link should expose a name through visible text, aria-label, or an image alt attribute.
Actual Result
392 of 4,319 links across 49 pages lack an accessible name.
BUG-016
API responses missing Content-Type header
Medium
P2
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in DevTools → Network
- Inspect response headers for the listed endpoints
- Confirm `Content-Type` is missing and add it server-side
Expected Result
Every API response should include a Content-Type header.
Actual Result
3 of 4 network requests on https://example-coffee-shop.com/ omit Content-Type header.
BUG-017
External link unreachable
Medium
P2
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in a browser
- Click the link to https://etbis.eticaret.gov.tr/sitedogrulama/1d8c05a8868b47f1a71d3cb6b7e27d79
- Observe TypeError: fetch failed
- Update the link target or remove the reference
Expected Result
All outbound links should be reachable and return a successful response.
Actual Result
https://etbis.eticaret.gov.tr/sitedogrulama/1d8c05a8868b47f1a71d3cb6b7e27d79 could not be reached.
BUG-018
Failed resource loading errors in console
Medium
P2
• New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/kullanici/kaydol in Chrome DevTools → Console
- Reload the page with the console open
- Locate the matching error entry and follow the stack trace into the source
- Fix the failing call or guard against the input that triggered it
Expected Result
All resource requests should succeed (or fail gracefully with error handling).
Actual Result
6 occurrences of "Failed to load resource: the server responded with a status of 401" across 3 pages. First observed on https://example-coffee-shop.com/kullanici/kaydol.
BUG-019
Form accepts empty submission
Medium
P2
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in a browser
- Find the form (action="https://example-coffee-shop.com/alisveris/ara", method=POST)
- Reproduce the empty submit test scenario
- Click the submit button and observe the form proceeds without challenge
Expected Result
Client-side validation should prevent empty submissions.
Actual Result
Empty form on https://example-coffee-shop.com/ submitted without triggering validation or error messages.
BUG-020
JavaScript console errors detected
Medium
P2
• New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/kullanici/kaydol in Chrome DevTools → Console
- Reload the page with the console open
- Locate the matching error entry and follow the stack trace into the source
- Fix the failing call or guard against the input that triggered it
Expected Result
Pages should load without JavaScript console errors.
Actual Result
12 occurrences of "%c%d font-size:0;color:transparent NaN" error across 3 pages. First observed on https://example-coffee-shop.com/kullanici/kaydol.
BUG-021
No offline or cached state
Medium
P2
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/
- Open DevTools → Network → toggle 'Offline'
- Reload and observe what the user sees
- Implement a service worker that caches the shell, or render an offline fallback page
Expected Result
Offline navigation should show a cached page or branded offline screen.
Actual Result
Offline navigation to https://example-coffee-shop.com/ shows a generic browser error: net::ERR_INTERNET_DISCONNECTED.
BUG-022
Heavy page weight and low lazy-load adoption degrade mobile performance
Medium
P2
• New
https://example-coffee-shop.com/ (Mobile)
Steps to Reproduce
- Open Chrome DevTools Network tab, reload https://example-coffee-shop.com/ — observe total transfer size around 4.8 MB.
- Filter by Img — several images above 500 KB with no lazy-load attribute.
- Throttle to Fast 3G and reload — significant render delay before page is usable.
Expected Result
Page weight should target under 1.5 MB for e-commerce pages; all below-the-fold images should use loading='lazy'; individual images should be compressed and served in next-gen formats (WebP/AVIF).
Actual Result
TS-PERF: / is 4.81 MB, /alisveris/urun/kenya-kirinyaga is 3.40 MB. TS-IMG: only 3 of 17 images use lazy loading; 4 images exceed 500 KB.
BUG-023
JavaScript URLs in links
Medium
P2
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ → DevTools → Console
- Run `[...document.querySelectorAll('a[href]')].filter(a => a.getAttribute('href').toLowerCase().startsWith('javascript:'))`
- Replace each `javascript:` href with a button + script-file handler, or remove the link entirely
Expected Result
Links should point to real URLs (http://, https://, mailto:, tel:, or #fragment), not javascript: strings.
Actual Result
49 javascript: href values found across 49 pages. First observed on https://example-coffee-shop.com/.
BUG-024
Missing Content-Security-Policy header
Medium
P2
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- curl -I 'https://example-coffee-shop.com/'
- Inspect the response headers — 'Content-Security-Policy' should be present
- (Most security headers are configured at the web-server or CDN layer; check the deployment platform's docs.)
Expected Result
Every page should include a Content-Security-Policy header that restricts script sources.
Actual Result
Content-Security-Policy header is not set. This was checked on 2 sample pages.
BUG-025
No cookie consent banner detected
Medium
P2
• New
https://example-coffee-shop.com (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in a private window (no prior session)
- Verify whether a consent banner appears
- If only after-JS, consider server-side rendering it so static crawlers / accessibility tools see it
Expected Result
A cookie or consent banner should be visible or loadable on the first page visit.
Actual Result
Homepage HTML response did not contain common consent-banner indicators.
BUG-026
Server software details publicly visible
Medium
P2
• New
https://example-coffee-shop.com (Desktop + Mobile)
Steps to Reproduce
- curl -I 'https://example-coffee-shop.com/'
- Confirm the X-Powered-By response header is present and discloses the software
- Configure the server / reverse proxy to remove or anonymize the header
Expected Result
Server software version should not be disclosed in response headers.
Actual Result
X-Powered-By header reveals: PHP/8.4.21, PleskLin
BUG-027
Text inputs without character limits
Medium
P2
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in DevTools → Elements
- Inspect each form input and check for the `maxlength` attribute
- Add `maxlength` matching the longest legitimate value (or the column width in the database)
Expected Result
Text inputs, email fields, and text areas should declare a sensible maxlength.
Actual Result
All 117 text inputs across 49 pages omit maxlength. First observed on https://example-coffee-shop.com/.
BUG-028
Third-party cookies set on page load
Medium
P2
• New
https://example-coffee-shop.com (Desktop + Mobile)
Steps to Reproduce
- curl -I 'https://example-coffee-shop.com/'
- Inspect Set-Cookie Domain= values
- Move tracking to first-party (server-side proxy) or implement consent gating
Expected Result
Cookies should use first-party domains (or no Domain attribute).
Actual Result
2 third-party cookies detected: XSRF-TOKEN@example-coffee-shop.com, example coffee shop_session@example-coffee-shop.com.
BUG-029
Missing page title
Medium
P2
• New
https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf in DevTools → Elements tab
- Inspect `<head>` and confirm no `<title>` (or an empty one) is present
- Add a descriptive `<title>` to the page template
Expected Result
Every page should have a <title> element with meaningful content.
Actual Result
1 of 50 crawled pages has an empty or missing <title> element.
BUG-030
Missing SEO metadata
Medium
P2
• New
https://example-coffee-shop.com/abonelikler (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/abonelikler → View source
- Search for `<meta name="description"` and confirm it is absent
- Add a 50–160 character description in the page template
Expected Result
Every page should include a <meta name="description" content="..."> tag.
Actual Result
32 of 50 crawled pages have no meta description.
BUG-031
Unbranded 403 responses replace expected 404 handling for unknown URLs
Medium
P2
• New
https://example-coffee-shop.com/page-not-found (Desktop + Mobile)
Steps to Reproduce
- Visit https://example-coffee-shop.com/this-page-does-not-exist in a browser.
- Observe a bare, unbranded 403 Forbidden response with no navigation.
- Confirm with curl -I https://example-coffee-shop.com/nonexistent — HTTP/1.1 403.
Expected Result
Requests for non-existent pages should return a friendly branded 404 page with navigation options, helping users recover and reducing bounce rate.
Actual Result
TS-ERR: GET /page-not-found returns HTTP 403 (not branded) and GET /aaaa… (500-char) also returns HTTP 403 (not branded), in 0.36 s and 0.20 s respectively.
BUG-032
Inconsistent heading structure
Low
P3
• New
https://example-coffee-shop.com/alisveris/kategori/rare (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/alisveris/kategori/rare in DevTools
- Run `[...document.querySelectorAll('h1,h2,h3,h4,h5,h6')].map(h => h.tagName)` in Console
- Confirm at least one adjacent pair skips a level (e.g. H1 followed by H3)
- Rebalance: demote skipped levels or insert the missing intermediate heading
Expected Result
Heading levels should descend in order (<h1> → <h2> → <h3>, and so on).
Actual Result
1 of 50 crawled pages has at least one skipped heading level.
BUG-033
Carousel library error in console
Low
P3
• New
https://example-coffee-shop.com/abonelikler (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/abonelikler in Chrome DevTools → Console
- Reload the page with the console open
- Locate the matching error entry and follow the stack trace into the source
- Fix the failing call or guard against the input that triggered it
Expected Result
JavaScript libraries should initialize without errors.
Actual Result
4 occurrences of "Bad element for Flickity: .magaza-carousel" across 2 pages. First observed on https://example-coffee-shop.com/abonelikler.
BUG-034
Carousel library null reference error
Low
P3
• New
https://example-coffee-shop.com/abonelikler (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/abonelikler in Chrome DevTools → Console
- Reload the page with the console open
- Locate the matching error entry and follow the stack trace into the source
- Fix the failing call or guard against the input that triggered it
Expected Result
JavaScript libraries should initialize without errors.
Actual Result
4 occurrences of "Bad element for Flickity: null" across 2 pages. First observed on https://example-coffee-shop.com/abonelikler.
BUG-035
No offline support (service worker not registered)
Low
P3
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ → DevTools → Application → Service workers
- Confirm no service worker is registered
- (Optional) Register a service worker to enable offline caching and faster repeat loads
Expected Result
A service worker should be registered to support offline access.
Actual Result
No service worker registrations detected on https://example-coffee-shop.com/.
BUG-036
Heavy page weight (4.81 MB)
Low
P3
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in Chrome DevTools → Lighthouse → Performance
- Run an audit and confirm the Weight metric exceeds the "good" threshold
- Compare against ≤3 MB good · ≤5 MB needs improvement thresholds (Google Core Web Vitals)
Expected Result
Page weight should be ≤3 MB (good) or ≤5 MB (acceptable).
Actual Result
Homepage transfers 4.81 MB (verdict: needs improvement). Measured under standard network conditions.
BUG-037
Images not using native lazy-loading
Low
P3
• New
https://example-coffee-shop.com (Desktop + Mobile)
Steps to Reproduce
- curl -s 'https://example-coffee-shop.com/' | grep -oE '<img[^>]*>' | head -20
- Confirm the image tags carry no `loading="lazy"` attribute
- Add the attribute to each `<img>` below the fold
Expected Result
Most images below the fold should use the loading="lazy" attribute.
Actual Result
3 of 17 images on the homepage use loading="lazy" (18%).
BUG-038
Oversized image (532 KB)
Low
P3
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- curl -sI 'https://example-coffee-shop.com/storage/slider/2026/04/slider-sahibi-degil-parcasi-br-oldugumuz-doga-07.jpeg'
- Inspect the `Content-Length` response header
- Re-encode or resize the image asset, then re-deploy
Expected Result
Images should be under 500 KB.
Actual Result
https://example-coffee-shop.com/storage/slider/2026/04/slider-sahibi-degil-parcasi-br-oldugumuz-doga-07.jpeg is 532 KB.
BUG-039
Forms lack duplicate-submission prevention
Low
P3
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/
- Inspect the hidden inputs on a mutating form
- Confirm no idempotency_key / request_id / nonce is present
- Wire the framework's idempotency helper into the form template
Expected Result
Each form that changes data should include a hidden idempotency token (e.g., idempotency_key, request_id, or nonce).
Actual Result
All 117 mutating forms across 49 pages lack an idempotency token.
BUG-040
Forms may lack cross-site forgery protection
Low
P3
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ → DevTools → Elements
- Confirm the form has no hidden CSRF token AND no other defense (check the session cookie's SameSite attribute and any CSRF <meta> tag / request header)
- If genuinely unprotected, add a CSRF token or set SameSite=Lax/Strict on the session cookie
Expected Result
Each form that changes data should be protected by a CSRF token (hidden field), a SameSite-restricted cookie, or a header-based token.
Actual Result
All 117 mutating forms across 49 pages show no hidden CSRF token field. Other protections (SameSite cookie, custom header) cannot be detected by this scanner.
BUG-041
Inline event handlers in HTML
Low
P3
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ → DevTools → Elements
- Run `document.querySelectorAll('[onclick],[onload],[onerror],[onmouseover]')` in Console
- Replace each inline handler with an `addEventListener` call in a script file
Expected Result
Event handlers should be wired through JavaScript addEventListener(), not inline on* attributes.
Actual Result
392 inline event-handler attributes found across 49 pages. First observed on https://example-coffee-shop.com/.
BUG-042
Login endpoint shows no rate-limit protection signal
Low
P3
• New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
Steps to Reproduce
- curl -X OPTIONS 'https://example-coffee-shop.com/kullanici/kaydol' -i
- Inspect response headers for Retry-After / X-RateLimit-*
- Wire a rate limiter on the auth endpoint (CDN / edge / framework)
Expected Result
Login endpoint should include Retry-After or X-RateLimit-* headers to signal rate-limit protection.
Actual Result
OPTIONS request to https://example-coffee-shop.com/kullanici/kaydol returned HTTP 200 with no rate-limit headers.
BUG-043
No 'remember me' option on login
Low
P3
• New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/kullanici/kaydol
- Scan the login form for a checkbox
- Add a 'Remember me' checkbox that the server interprets as a long-lived session
Expected Result
Login form should offer a 'Remember me' checkbox.
Actual Result
No 'Remember me' checkbox found on the login form.
BUG-044
No password reset link on login page
Low
P3
• New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/kullanici/kaydol
- Scan visible link text near the login form
- Add a 'Forgot password?' link that initiates the reset flow
Expected Result
Login page should include a password-reset link.
Actual Result
No password-reset link found on the login page.
BUG-045
No password visibility toggle
Low
P3
• New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/kullanici/kaydol
- Locate the password input
- Add a sibling button that toggles the input type
Expected Result
Login form should have a button to toggle password visibility.
Actual Result
No password visibility toggle found near the password field.
BUG-046
No rate-limiting visible on homepage
Low
P3
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Fire 20 parallel GET https://example-coffee-shop.com/
- Inspect each response status + headers for 429 / X-RateLimit-* / Retry-After
- Add rate limiting at the CDN / edge / framework layer
Expected Result
Server should send rate-limit signals (429 responses or X-RateLimit-* / Retry-After headers) under heavy load.
Actual Result
20 parallel requests to the homepage all succeeded with no 429 response or rate-limit header.
BUG-047
Password field missing autocomplete attribute
Low
P3
• New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/kullanici/kaydol
- Inspect the password input
- Add `autocomplete="current-password"` (login) or `"new-password"` (signup)
Expected Result
Password input should have autocomplete="current-password" attribute.
Actual Result
The password input is missing the autocomplete attribute.
BUG-048
Password field missing maxlength attribute
Low
P3
• New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/kullanici/kaydol
- Inspect the password input
- Add a `maxlength` matching the server's accepted password length
Expected Result
Password input should have a maxlength attribute (e.g., maxlength="128").
Actual Result
The password input is missing maxlength.
BUG-049
Potential CSRF gap on state-changing forms (unverified)
Low
P3
• New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
Steps to Reproduce
- Open an affected page → DevTools → Elements / Network
- Check the form's hidden inputs, the session cookie's SameSite attribute, and any CSRF <meta> tag / request header
- If genuinely none are present, add a CSRF token or set SameSite=Lax/Strict on the session cookie
Expected Result
Each state-changing form is protected by at least one CSRF defense — a hidden token, a SameSite=Lax/Strict session cookie, or a header / meta token (only the hidden token is visible to an external scan).
Actual Result
No hidden CSRF token field was found in the form markup. SameSite / header / meta defenses are not externally observable, so protection status is unverified.
BUG-050
Username field missing autocomplete attribute
Low
P3
• New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/kullanici/kaydol
- Inspect the username / email input
- Add `autocomplete="username"` (or `"email"`)
Expected Result
Username/email input should have autocomplete="username" or "email" attribute.
Actual Result
The username input is missing the autocomplete attribute.
BUG-051
Content clipped at desktop viewport (1440px)
Low
P3
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ and resize the browser to 1440×900
- Inspect the first offender element and verify its computed `overflow` is `hidden`
- Compare `scrollWidth` vs `clientWidth` in DevTools → Properties tab
- Replace `overflow: hidden` with a wrapping rule, or add `text-overflow: ellipsis`
Expected Result
Content should fit the desktop viewport or be truncated with an ellipsis.
Actual Result
1 element clips content at 1440px width. Example: div.flickity-viewport (1440px container → 5760px content).
BUG-052
Content clipped at mobile viewport (375px)
Low
P3
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ and resize the browser to 375×812
- Inspect the first offender element and verify its computed `overflow` is `hidden`
- Compare `scrollWidth` vs `clientWidth` in DevTools → Properties tab
- Replace `overflow: hidden` with a wrapping rule, or add `text-overflow: ellipsis`
Expected Result
Content should fit the mobile viewport, or be truncated with an ellipsis indicator.
Actual Result
1 element clips content at 375px width. Example: div.flickity-viewport (375px container → 1500px content).
BUG-053
Content clipped at tablet viewport (768px)
Low
P3
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ and resize the browser to 768×1024
- Inspect the first offender element and verify its computed `overflow` is `hidden`
- Compare `scrollWidth` vs `clientWidth` in DevTools → Properties tab
- Replace `overflow: hidden` with a wrapping rule, or add `text-overflow: ellipsis`
Expected Result
Content should fit the tablet viewport or be truncated with an ellipsis.
Actual Result
1 element clips content at 768px width. Example: div.flickity-viewport (768px container → 3072px content).
BUG-054
Missing main heading
Low
P3
• New
https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/pdf/kvkk_basvuru.pdf in DevTools
- Search the DOM for `h1` elements
- Confirm none are present
- Add a single, descriptive `<h1>` to the page template
Expected Result
Each page should have exactly one <h1> element.
Actual Result
1 of 50 crawled pages has no <h1> element.
BUG-055
Page titles too short for search results
Low
P3
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in DevTools → Elements
- Inspect the `<title>` element
- Confirm the text is 9 characters (target 10–60)
- Rewrite the title to fit the 10–60 character window
Expected Result
Page titles should be between 10 and 60 characters.
Actual Result
37 of 50 pages have titles that are too short (0 too long, 37 too short). First example: https://example-coffee-shop.com/ (9 characters).
BUG-056
Registration form lacks password strength indicator
Low
P3
• New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/kullanici/kaydol
- Inspect the password input's neighborhood
- Add a strength meter or live rule list
Expected Result
Registration form should show a password strength meter or rule list.
Actual Result
No password strength meter or rule list detected on the registration form.
BUG-057
Registration form missing terms acceptance checkbox
Low
P3
• New
https://example-coffee-shop.com/kullanici/kaydol (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/kullanici/kaydol
- Inspect the registration form's checkboxes
- Add a required terms / privacy acceptance checkbox
Expected Result
Registration form should include a required checkbox for terms/privacy acceptance.
Actual Result
No terms, privacy, or consent checkbox found on the registration form.
BUG-058
Sitemap not found
Low
P3
• New
https://example-coffee-shop.com/sitemap.xml (Desktop + Mobile)
Steps to Reproduce
- curl -I 'https://example-coffee-shop.com/sitemap.xml'
- Confirm the response is not 2xx
- Generate a sitemap (most frameworks ship a sitemap generator) and serve it at /sitemap.xml
Expected Result
GET /sitemap.xml should return HTTP 200 with a valid XML sitemap.
Actual Result
GET https://example-coffee-shop.com/sitemap.xml returned HTTP 404.
BUG-059
Undersized touch targets on mobile
Low
P3
• New
https://example-coffee-shop.com/ (Desktop + Mobile)
Steps to Reproduce
- Open https://example-coffee-shop.com/ in Chrome DevTools at device width 375px
- Highlight each interactive element in turn and check its bounding-box dimensions
- Increase padding so the bounding box is ≥ 44×44 px
Expected Result
All interactive elements should be at least 44×44 pixels at mobile viewports.
Actual Result
31 of 45 interactive elements are below 44px at 375×812. Examples: buttons 22×24px, link 328×24px.
6Highest-Priority Findings
Auto-generated from severity ranking. Manual review recommended.
The top critical and high-severity findings, in priority order. See the Detailed Bug Reports section for full reproduction steps.
- BUG-001 — Color contrast failures (site-wide)
- BUG-002 — Form input missing accessible label
- BUG-003 — Pervasive missing accessible names on interactive elements site-wide
- BUG-004 — Internal link unreachable
- BUG-005 — Legal compliance failure: no cookie consent and broken KVKK document
- BUG-006 — Cookie missing HttpOnly flag
- BUG-007 — HTTP requests are not redirected to HTTPS
7Recommended Fix Order
Auto-generated from severity ranking. Manual review recommended.
Suggested remediation order. Engineering should validate the sequence against business priorities and dependency relationships before scheduling.
11. Implement CSRF tokens on all 117 state-mutating forms (including login, registration, and checkout) and mark the XSRF-TOKEN cookie HttpOnly — these two gaps share the same root cause (missing anti-forgery layer) and together represent the highest-risk exploitable vulnerability.
22. Add a compliant KVKK/GDPR cookie consent banner that blocks third-party cookies until explicit user consent is given — the absence of this creates direct regulatory liability.
33. Fix the broken internal link to /pdf/kvkk_basvuru.pdf by uploading the correct file or correcting the URL — this is both a legal-document accessibility failure and a broken user journey on a compliance page.
44. Add a Content-Security-Policy header at the server or CDN/edge layer to restrict script execution sources and mitigate XSS risk; simultaneously remove all 49 javascript: href links and replace with proper button or event-listener patterns.
55. Assign unique, descriptive <title> tags and meta descriptions to all 50 pages (37 titles are too short or duplicate, 32 pages lack meta descriptions entirely) — this is a single templating fix that will substantially improve SEO and click-through rates.
66. Audit and label all 215 unnamed buttons and 392 unnamed links with accessible names (aria-label or visible text) and fix colour contrast failures on the homepage, contact, and product pages to meet WCAG 2.1 AA — a single design-system pass can resolve most instances.
77. Suppress or rotate the X-Powered-By header (PHP/8.4.21, PleskLin) to stop disclosing server stack details to potential attackers.
88. Optimise page weight by lazy-loading the remaining 82% of images without the attribute and compressing the 4 images over 500 KB — targeting the homepage's 4.81 MB payload will most directly improve Core Web Vitals and mobile conversion.
99. Add rate limiting on the login endpoint and implement client-side idempotency tokens on order/checkout forms to prevent credential stuffing and accidental duplicate orders.
1010. Fix the 403 unbranded error responses for unknown URLs — replace with a friendly branded 404 page that keeps users on-site and provides navigation options.
8Recommended Manual Test Scenarios
Manual test scenarios recommended by the AI analyzer based on the crawled site structure. Hand this list to your QA team for execution — each scenario covers something the automation cannot verify on its own.
Happy Path (5)
TC-001
Register a new account with valid credentials
happy-path
High
Precondition
User is not registered and is on the /kullanici/kaydol page.
Steps
- Enter a first name in the 'ad' field
- Enter a last name in the 'soyad' field
- Enter a valid email address in the 'email' field
- Enter a password of at least 8 characters in the 'password' field
- Confirm the password in the 'password_confirm' field
- Check the 'kvkk' (KVKK agreement) checkbox
- Click the 'Kayıt Ol' button
Expected Result
Account is created successfully and user is redirected to the dashboard or home page.
TC-002
Search for a product using the search form
happy-path
High
Precondition
User is on any page with the search form visible.
Steps
- Locate the search form with 'arama' text field
- Enter a product name (e.g., 'kahve') in the 'arama' field
- Click the 'Bul' button
Expected Result
Search results page displays products matching the search term.
TC-003
Add a coffee subscription to cart with variant selection
happy-path
High
Precondition
User is on the product page /alisveris/urun/kahve-aboneligi and is not logged in.
Steps
- Select a value from the 'ay' (month) dropdown
- Select a value from the 'hafta' (week) dropdown
- Select at least one checkbox variant option from product_variant_group_id[1]
- Click the 'Sepete Ekle' button
Expected Result
Product is added to cart and cart counter increases. Success notification appears.
TC-004
Subscribe to newsletter with valid email
happy-path
Medium
Precondition
User is on any page with the newsletter form visible.
Steps
- Locate the newsletter form with 'email' field
- Enter a valid email address
- Click the 'Abone Ol' button
Expected Result
Newsletter subscription is confirmed and a success message appears.
TC-005
Verify product category navigation flow
happy-path
Medium
Precondition
User is on the home page /
Steps
- Click the 'Kahveler' category link
- Verify page loads with coffee products
- Click the 'Ekipmanlar' category link
- Verify page loads with equipment products
Expected Result
Each category page loads correctly and displays products in that category.
Negative Cases (9)
TC-006
Register with mismatched password confirmation
negative
High
Precondition
User is on the /kullanici/kaydol page.
Steps
- Enter a first name
- Enter a last name
- Enter a valid email
- Enter a password in the 'password' field
- Enter a different value in the 'password_confirm' field
- Check the 'kvkk' checkbox
- Click the 'Kayıt Ol' button
Expected Result
Form submission fails with an error message indicating passwords do not match.
TC-007
Register without checking KVKK agreement
negative
High
Precondition
User is on the /kullanici/kaydol page.
Steps
- Enter a first name
- Enter a last name
- Enter a valid email
- Enter a matching password pair
- Leave the 'kvkk' checkbox unchecked
- Click the 'Kayıt Ol' button
Expected Result
Form submission fails with an error message requiring KVKK agreement.
TC-008
Search with empty search field
negative
Medium
Precondition
User is on any page with the search form.
Steps
- Leave the 'arama' field empty
- Click the 'Bul' button
Expected Result
Form submission either fails with a validation error or displays all products without filtering.
TC-009
Add product to cart without selecting required variant
negative
High
Precondition
User is on a product page with variant selection (e.g., /alisveris/urun/cezve).
Steps
- Do not select any value from the variant dropdown (product_variant_group_id[5])
- Enter a quantity in the 'adet' field
- Click the 'Sepete Ekle' button
Expected Result
Form submission fails with a validation error indicating variant selection is required.
TC-010
Add subscription product without selecting month or week
negative
High
Precondition
User is on the subscription product page /alisveris/urun/kahve-aboneligi.
Steps
- Do not select a value from the 'ay' dropdown
- Do not select a value from the 'hafta' dropdown
- Select a variant checkbox
- Click 'Sepete Ekle'
Expected Result
Form submission fails with validation errors for missing month and week selections.
TC-011
Subscribe to newsletter with invalid email format
negative
Medium
Precondition
User is on any page with the newsletter form.
Steps
- Enter an invalid email (e.g., 'notanemail') in the 'email' field
- Click 'Abone Ol'
Expected Result
Form submission fails with a validation error for invalid email format.
TC-012
Attempt to add product without quantity value
negative
Medium
Precondition
User is on a non-subscription product page with quantity field (e.g., /alisveris/urun/cezve).
Steps
- Select a variant from the dropdown
- Leave the 'adet' (quantity) field empty
- Click 'Sepete Ekle'
Expected Result
Form submission fails with validation error for missing or invalid quantity.
TC-013
Register with email that already exists
negative
High
Precondition
User is on the /kullanici/kaydol page and an account with test@example.com already exists.
Steps
- Enter a first name
- Enter a last name
- Enter an email address that already has a registered account (test@example.com)
- Enter a matching password pair
- Check the 'kvkk' checkbox
- Click 'Kayıt Ol'
Expected Result
Form submission fails with an error message indicating email is already registered.
TC-014
Add zero or negative quantity to cart
negative
Medium
Precondition
User is on a product page with quantity number field.
Steps
- Select a variant if required
- Enter '0' in the 'adet' (quantity) field
- Click 'Sepete Ekle'
Expected Result
Form submission fails with validation error or quantity is rejected as invalid.
Edge Cases (3)
TC-015
Register with extremely long first name (250+ characters)
edge-case
Medium
Precondition
User is on the /kullanici/kaydol page.
Steps
- Enter a string of 300+ characters in the 'ad' field
- Enter a valid last name
- Enter a valid email
- Enter a matching password pair
- Check the 'kvkk' checkbox
- Click 'Kayıt Ol'
Expected Result
Form submission either fails with length validation error or text is truncated appropriately.
TC-016
Search with special characters and Unicode in query
edge-case
Medium
Precondition
User is on any page with the search form.
Steps
- Enter special characters and Unicode (e.g., '(kahve)@#$ۄ') in the 'arama' field
- Click 'Bul'
Expected Result
Search processes without errors and returns appropriate results or empty set.
TC-017
Submit newsletter form twice rapidly (duplicate submission)
edge-case
Medium
Precondition
User is on any page with the newsletter form.
Steps
- Enter a valid email address in the 'email' field
- Click 'Abone Ol' button
- Immediately click 'Abone Ol' button again before page response
Expected Result
Only one subscription is recorded; second submission is prevented or ignored.
Security (2)
TC-018
Register with XSS payload in email field
security
High
Precondition
User is on the /kullanici/kaydol page.
Steps
- Enter a first name
- Enter a last name
- Enter a potential XSS payload in email field (e.g., '<script>alert(1)</script>@test.com')
- Enter a matching password pair
- Check the 'kvkk' checkbox
- Click 'Kayıt Ol'
Expected Result
Input is either rejected as invalid email format or safely escaped; no script executes.
TC-019
Search with SQL injection-shaped payload
security
High
Precondition
User is on any page with the search form.
Steps
- Enter SQL injection attempt in 'arama' field (e.g., "'; DROP TABLE products; --")
- Click 'Bul'
Expected Result
Payload is treated as a literal search string; no database modification occurs.
UX & Responsive (1)
TC-020
Navigate category links and verify cart counter persists
ux
Medium
Precondition
User has added a product to cart and cart counter shows '1'.
Steps
- Click the 'Kahveler' category link
- Verify cart counter still displays '1'
- Click the 'Aksesuar' category link
- Verify cart counter still displays '1'
- Click 'Online Dükkan' to return to main shop
Expected Result
Cart counter persists across all page navigations and displays the correct item count.
9Summary & Observations
Testing Outcome — Automated Scan
Critical and high-severity findings cluster around functional / security issues — recommend an engineering triage session before scheduling remediation.
An automated scan can only validate what it can statically observe (DOM, console, load timing). Recommend a manual review of business-critical flows (auth, payment, data submission) before sign-off.