All notable changes to Web Accessibility Scanner.
The format follows Keep a Changelog, and this project uses Semantic Versioning.
[1.0.2] — 2026-09-29
Added
- Contrast findings that need a human check now show their colours. A needs-review
contrast finding had a Colour section containing nothing at all — no text colour, no background, no ratio — which is the one thing somebody opens that finding to see.
Checked against axe 4.13 in a real browser rather than assumed: an incomplete colour-contrast result carries no fgColor and no bgColor whatsoever, only a ratio of 0 and a messageKey. There was nothing of axe's to reuse, so the scanner now reads the element itself.
It reports the text colour, which is always knowable; the nearest ancestor background that actually paints one; and why axe would not measure it — a gradient, a background image, an overlapping element — which is what tells you how to check it by hand.
- Where a solid background was found, the ratio against it is shown as indicative,
never "measured", and says so: whatever made axe give up is the same thing that makes one flat colour the wrong answer. Where no solid background exists, it says unknown and shows a hatched swatch rather than a grey one, which would read as "the background is grey".
- A translucent text colour is composited over its background before being named, so the
hex shown is the grey you can see rather than the black in the stylesheet.
demo/contrast-unmeasured.htmlcovers the three cases end to end.
[1.0.1] — 2026-09-29
Fixed
- "Scan failed — the page reloaded or navigated away", on a page that did neither.
The content script Chrome registers is a loader: it starts a dynamic import() of the real module and returns. executeScript resolves at that point, so injection reported success while the module was still loading and no message listener existed yet. The very next message came back "Receiving end does not exist", which was reported as the page having navigated — a scan that failed, with an explanation pointing at the wrong thing entirely.
It is a race, which is why it appeared only sometimes: lost on a cold cache, a slow machine or a heavy page, won on a warm one. The transport now waits for the frame to actually answer a ping before sending, backing off from 25ms up to a 3s ceiling.
Measured on the installed extension with the page CPU throttled 20x, which is what a slow machine looks like: 1 of 10 cold scans succeeded before, 10 of 10 after. Unthrottled, this machine won the race every time either way — which is exactly why the bug reads as intermittent.
- The message itself was wrong even when the send genuinely fails. It now says the
page stopped responding and may have reloaded, rather than asserting that it did.
[1.0.0] — 2026-09-25
First public release. The build log from before this point is in CHANGELOG-dev.md; none of it reached a user, so none of it is listed here.
Testing the page
- Automated findings. The full axe-core rule set plus additional checks, run against
the rendered page — inside iframes and inside shadow DOM, merged into one report rather than skipped. Each finding carries the element, a selector, the opening tag and a fix you can paste.
- Framework-aware suggestions. Angular, React, Vue, Svelte and Ember are recognised,
and the fix is additionally written in that framework's idiom. Detection changes the suggestions, never the findings.
- Guided manual checks. Eighteen checks covering what a rule engine cannot decide.
Each says why it could not be automated, what a failure looks like, and gathers the page's own content as evidence. Verdicts and notes are saved per page and travel with the exported report.
- Conformance targets. WCAG 2.0, 2.1 and 2.2 — Level A and AA throughout, AAA for 2.1
and 2.2 — plus Section 508 (Revised), EN 301 549, Trusted Tester v5 and RGAA 4. Choosing one changes which rules run rather than filtering results afterwards.
Seeing the page as it is used
- Screen reader transcript. What would be announced, in reading order, with rows that
announce as nothing or as a file name flagged in place.
- Tab order overlay. The keyboard path drawn and numbered over the page, flagging
positive tabindex, backward jumps, off-screen stops, focusable content hidden from screen readers and controls with no visible focus style. On-screen stops only by default, renumbered so the badges start at 1.
- Document outline. Headings and landmarks drawn in place, flagging skipped levels,
unnamed landmarks and content outside any landmark.
- Styles off. Read the page in the order the content is really in, returning to the
same scroll position afterwards.
- Colour contrast tuner. The measured ratio, the threshold it was measured against,
and a slider that walks the colour until it passes — returning the nearest passing hex.
Working at scale
- Group by component. Eighty contrast failures collapse into one button used eighty
times, with the evidence for why two elements were treated as the same component.
- Whole-site scan. Up to 25 same-origin pages in one run, discovered from links on the
page you were already on. Nothing opens until you approve the list, links that look like they act rather than display are off by default, and the tab is returned where it started.
- User flows. Record a journey once, replay it, and have every state scanned and
merged — so dialogs and menus are checked while they are open.
- Find in source. On an Angular development build, traces a finding back to the
component template. Other frameworks strip the data this needs, and it says so rather than guessing.
Getting results out
- Export as JSON, CSV, HTML or Markdown, each carrying the manual review alongside the
automated findings.
- Needs review findings kept separate and never counted against the score.
- History — the last 10 scans kept on the device, switchable off and clearable.
- CI bundle. The same engine as a single file with no browser APIs, so Playwright or
any other runner can inject it and assert on the same report.
Privacy
- No accounts, no backend, no telemetry, no analytics, no third-party SDKs. Licence keys
are verified locally.
- The only network request the extension makes is Find in source reading a file from
the development server already serving the page, on the same origin, and only when asked.
- Settings, scan history, recorded flows and review notes are stored on the device, and
each can be deleted.
Known limits
- Automated rules find a meaningful subset of WCAG failures — commonly cited as between a
third and a half. No scanner establishes conformance on its own, which is what the guided manual checks are for.
- The screen reader transcript models what would be announced from the accessibility tree.
It is not a substitute for testing with a real screen reader.
- Text over an image or gradient has no single background colour; those contrast cases are
reported for review rather than given a ratio.
- Every feature is free in this release. Controls marked PRO are a statement of intent —
the licensing machinery is built, and nothing is currently withheld.