Read-only by construction. The runner only
reads the interface: one
GET per scan, zero wallet or
contract writes, and it never asks for a key, password, or payment. Every
fetch is logged below so you can verify that yourself. Checks are pure
functions of the page HTML — same input, same verdicts, every time.
Fixtures:
That contract address is not a valid
0x + 40-hex address — it will be ignored.
Pick a fixture or enter a URL, then run the checks.
Scan traffic (verify: GET only)
no scan yet
What the runner checks
- Keyboard reachability — no
tabindex="-1"traps; controls keyboard-reachable. - Visible focus —
:focus-visible/:focusstyles present. - Contrast — detected text colors vs background, WCAG AA ≥ 4.5:1.
- Mobile layout —
<meta name=viewport>present; no fixed width over 480px. - Key requests — visitor-facing private-key / seed-phrase language is flagged.
- Payment requests — visitor-facing payment / card language is flagged.
- Write actions — every contract write must explain its target and arguments in nearby text.
Honest limits: this is static HTML analysis —
it cannot compute true rendered contrast or drive real keyboard focus. The
verdict schema matches the
acceptance test suite
so any browser-rendered bench can be compared 1:1. Malformed or unreachable
inputs surface as bounded error cards, never a crash.