Browse the docs

Bundles and checks

What each bundle checks, what fails a build, and which plans include it.

A bundle chooses which checks run. Set it with the bundle input on GitHub or QUALITYGATE_BUNDLE on GitLab and Bitbucket. The default is a11y.

Every check reports findings on the same four severities: critical, serious, moderate, and minor. The gate counts critical and serious findings; moderate and minor ones are reported but never fail a build. Each check decides what is serious enough to gate, as described below.

Overview

BundleChecksPlans
a11yAccessibility with axe-core’s default rulesAll plans
adaAccessibility limited to WCAG 2.0, 2.1, and 2.2 level A and AAPaid
seoOn-page SEO signalsPaid
securitySecurity response headersPaid
linksLinks on the pagePaid
fulla11y, seo, security, and links in one page loadPaid
perfLighthouse performance, median of three mobile loadsPaid
geoAI search readinessPaid
seo-deepA crawl of up to 25 pages of the sitePaid
secrets-exposureServer-side credentials exposed to the browserPaid

Requesting a bundle your plan does not include is refused with bundle_not_allowed.

Bundle groups

Groups help you choose checks; they are not extra executable bundles or paid add-ons.

  • Accessibility: a11y, ada.
  • Release quality: seo, security, links, full, secrets-exposure.
  • Performance and search visibility: perf, geo, seo-deep.

Developer, Team and Agency all include every bundle. Free includes a11y. See Pricing and packages for scan and project limits.

a11y and ada

Runs axe-core in the loaded page. Findings keep axe’s own impact levels, so a missing image alt is critical and insufficient color contrast is serious. Each finding names the rule, the CSS selector of the element, and a link explaining the fix.

ada runs the same engine with only the WCAG 2.x A and AA rules, which is the set most accessibility requirements refer to. Neither bundle is a legal or conformance assessment.

seo

Reads what the scanned page declares: title, meta description, canonical link, h1, viewport, robots directives, and Open Graph tags.

  • Gates on: serious problems such as a missing title, h1, or viewport.
  • Reported only: a noindex directive, because previews often set it on purpose.

security

Reads the response headers of the final page after redirects: Content-Security-Policy, framing protection, X-Content-Type-Options, Strict-Transport-Security, Referrer-Policy, and Permissions-Policy.

  • Gates on: a page served over plain HTTP, a missing X-Content-Type-Options: nosniff, and missing framing protection. Each is a one-line fix in most frameworks.
  • Reported only: a missing Content-Security-Policy or HSTS header. A CSP is real work to adopt, and HSTS is usually set at the edge, where a preview differs from production.

Run this bundle against a real deployment, since a local server does not carry your host’s headers.

Requests every <a href> on the scanned page, at most 100 distinct links, 8 at a time. It does not follow links further, so it never turns into a crawler.

  • Gates on: links to your own site that return an error status or cannot be requested.
  • Reported only: broken external links, which no pull request can fix, and links whose server answers automated clients with 401, 403, 405, or 429, marked as unverified.

full

Runs a11y, seo, security, and links against one page load, so it costs one run and one navigation rather than four. The report adds a findings-by-check table and labels each finding with its check. Severity counts are summed across checks, so the run still has one verdict.

full does not include perf, geo, seo-deep or secrets-exposure. Each separate URL/bundle scan is another run.

perf

Runs Lighthouse against the page three times with simulated mobile throttling, the profile PageSpeed Insights uses, and keeps the median run. The comment and run history show Lighthouse’s performance score.

  • Gates on: a core metric in Lighthouse’s poor range (First Contentful Paint, Largest Contentful Paint, Total Blocking Time, Cumulative Layout Shift, or Speed Index).
  • Reported only: metrics that need improvement, and failing Lighthouse insights as advice.

perf adds roughly 15 to 30 seconds and is not part of full. On GitHub, the first perf run in a job installs Lighthouse with npm, which every GitHub-hosted runner has.

geo

Checks how ready the page is for AI search and answer engines:

  • a missing or malformed /llms.txt;
  • whether robots.txt blocks GPTBot, OAI-SearchBot, ClaudeBot, Claude-SearchBot, PerplexityBot, or Google-Extended from the page (reported, never gating, since some sites block them on purpose);
  • JSON-LD structured data completeness;
  • a citability score: the share of substantial passages an AI answer could quote as they stand.

Gates on: JSON-LD that is not valid JSON.

These are deterministic readiness checks, not guaranteed AI citations or rankings.

seo-deep

Crawls your site from the scanned page through the scanning browser, so links rendered by JavaScript count. It stays on the same origin, goes up to 3 clicks deep and 25 pages, and reads the sitemap to find orphan pages. It checks broken internal links, canonical and hreflang correctness, JSON-LD, duplicate titles, orphan pages, and pages buried too deep.

Gates on: internal links to error pages, broken canonicals, and invalid JSON-LD.

The crawl ignores robots.txt disallow rules, because it inspects your own deployment at your request and previews usually disallow everything. A crawl that reaches a limit says so in the report.

For geo and seo-deep, the runner collects page text and structured data and uploads them. QualityGate analyses them in memory and stores only the findings.

secrets-exposure

Looks for credentials that must never reach a browser, such as Stripe secret keys, AWS access keys, private keys, and GitHub, Slack, OpenAI, or Anthropic tokens, using rules derived from gitleaks. It reads inline scripts and the same-origin scripts and JSON the page loaded, up to 40 files of at most 2 MB each and 8 MB in total, and never reads third-party scripts.

  • Gates on: any live server-side credential.
  • Not reported: keys that are public by design, such as Stripe publishable keys or Google browser API keys.

A finding shows only the first four characters and the length of the value. Rotate any exposed key: once it has been served, removing it from the bundle does not make it safe.

To catch secrets before they are ever deployed, also add the merge readiness suite, which scans your commits with gitleaks inside your CI.