Bundles and checks
What each bundle checks, what fails a build, and which plans include it.
A bundle chooses which checks run. Set it with the bundle input on GitHub or
QUALITYGATE_BUNDLE on GitLab and Bitbucket. The default is a11y.
Every check reports findings on the same four severities: critical, serious, moderate, and minor. The gate counts critical and serious findings; moderate and minor ones are reported but never fail a build. Each check decides what is serious enough to gate, as described below.
Overview
| Bundle | Checks | Plans |
|---|---|---|
a11y | Accessibility with axe-core’s default rules | All plans |
ada | Accessibility limited to WCAG 2.0, 2.1, and 2.2 level A and AA | Paid |
seo | On-page SEO signals | Paid |
security | Security response headers | Paid |
links | Links on the page | Paid |
full | a11y, seo, security, and links in one page load | Paid |
perf | Lighthouse performance, median of three mobile loads | Paid |
geo | AI search readiness | Paid |
seo-deep | A crawl of up to 25 pages of the site | Paid |
secrets-exposure | Server-side credentials exposed to the browser | Paid |
Requesting a bundle your plan does not include is refused with
bundle_not_allowed.
Bundle groups
Groups help you choose checks; they are not extra executable bundles or paid add-ons.
- Accessibility:
a11y,ada. - Release quality:
seo,security,links,full,secrets-exposure. - Performance and search visibility:
perf,geo,seo-deep.
Developer, Team and Agency all include every bundle. Free includes a11y.
See Pricing and packages for scan and project limits.
a11y and ada
Runs axe-core in the loaded page.
Findings keep axe’s own impact levels, so a missing image alt is critical and
insufficient color contrast is serious. Each finding names the rule, the CSS
selector of the element, and a link explaining the fix.
ada runs the same engine with only the WCAG 2.x A and AA rules, which is the
set most accessibility requirements refer to. Neither bundle is a legal or
conformance assessment.
seo
Reads what the scanned page declares: title, meta description, canonical link,
h1, viewport, robots directives, and Open Graph tags.
- Gates on: serious problems such as a missing title,
h1, or viewport. - Reported only: a
noindexdirective, because previews often set it on purpose.
security
Reads the response headers of the final page after redirects:
Content-Security-Policy, framing protection, X-Content-Type-Options,
Strict-Transport-Security, Referrer-Policy, and Permissions-Policy.
- Gates on: a page served over plain HTTP, a missing
X-Content-Type-Options: nosniff, and missing framing protection. Each is a one-line fix in most frameworks. - Reported only: a missing Content-Security-Policy or HSTS header. A CSP is real work to adopt, and HSTS is usually set at the edge, where a preview differs from production.
Run this bundle against a real deployment, since a local server does not carry your host’s headers.
links
Requests every <a href> on the scanned page, at most 100 distinct links, 8 at
a time. It does not follow links further, so it never turns into a crawler.
- Gates on: links to your own site that return an error status or cannot be requested.
- Reported only: broken external links, which no pull request can fix, and
links whose server answers automated clients with
401,403,405, or429, marked as unverified.
full
Runs a11y, seo, security, and links against one page load, so it costs
one run and one navigation rather than four. The report adds a findings-by-check
table and labels each finding with its check. Severity counts are summed across
checks, so the run still has one verdict.
full does not include perf, geo, seo-deep or secrets-exposure.
Each separate URL/bundle scan is another run.
perf
Runs Lighthouse against the page three times with simulated mobile throttling, the profile PageSpeed Insights uses, and keeps the median run. The comment and run history show Lighthouse’s performance score.
- Gates on: a core metric in Lighthouse’s poor range (First Contentful Paint, Largest Contentful Paint, Total Blocking Time, Cumulative Layout Shift, or Speed Index).
- Reported only: metrics that need improvement, and failing Lighthouse insights as advice.
perf adds roughly 15 to 30 seconds and is not part of full. On GitHub, the
first perf run in a job installs Lighthouse with npm, which every
GitHub-hosted runner has.
geo
Checks how ready the page is for AI search and answer engines:
- a missing or malformed
/llms.txt; - whether
robots.txtblocks GPTBot, OAI-SearchBot, ClaudeBot, Claude-SearchBot, PerplexityBot, or Google-Extended from the page (reported, never gating, since some sites block them on purpose); - JSON-LD structured data completeness;
- a citability score: the share of substantial passages an AI answer could quote as they stand.
Gates on: JSON-LD that is not valid JSON.
These are deterministic readiness checks, not guaranteed AI citations or rankings.
seo-deep
Crawls your site from the scanned page through the scanning browser, so links rendered by JavaScript count. It stays on the same origin, goes up to 3 clicks deep and 25 pages, and reads the sitemap to find orphan pages. It checks broken internal links, canonical and hreflang correctness, JSON-LD, duplicate titles, orphan pages, and pages buried too deep.
Gates on: internal links to error pages, broken canonicals, and invalid JSON-LD.
The crawl ignores robots.txt disallow rules, because it inspects your own
deployment at your request and previews usually disallow everything. A crawl
that reaches a limit says so in the report.
For geo and seo-deep, the runner collects page text and structured data and
uploads them. QualityGate analyses them in memory and stores only the findings.
secrets-exposure
Looks for credentials that must never reach a browser, such as Stripe secret keys, AWS access keys, private keys, and GitHub, Slack, OpenAI, or Anthropic tokens, using rules derived from gitleaks. It reads inline scripts and the same-origin scripts and JSON the page loaded, up to 40 files of at most 2 MB each and 8 MB in total, and never reads third-party scripts.
- Gates on: any live server-side credential.
- Not reported: keys that are public by design, such as Stripe publishable keys or Google browser API keys.
A finding shows only the first four characters and the length of the value. Rotate any exposed key: once it has been served, removing it from the bundle does not make it safe.
To catch secrets before they are ever deployed, also add the merge readiness suite, which scans your commits with gitleaks inside your CI.